V45 · Texas Veterinary Hospitals · AVMA Principles + HIPAA Security Rule + DEA Title 21 CFR §1304–1305 + TVMDL Data-Sharing

Your vet hospital holds every pet owner's name, credit card, and clinical record. NVA just lost 1.1M+ of them. CoreRecon prevents that.

Texas has ~2,800 licensed veterinary practices with stretched, mixed-IT staffing. Cloud PIMS (AVImark IDEXX / Cornerstone IDEXX / ImproMed Infinity / Hippo Manager) hold the highest-value pet-owner PII in any per-veterinarian database — names, addresses, payment cards, insurance billing PHI, controlled-substance dispensing logs, and premise-ID-tagged TVMDL submissions. The NVA 2024 breach (1.1M+ pet records, LockBit affiliate, hundreds of TX locations) and the Southern Veterinary Partners 2024 incident (70+ hospitals, parent-company compromise) are not hypotheticals. They are the threat model.

When your practice bills pet insurance (HIPAA Security Rule §164.308/310/312), dispenses Schedule II–V drugs (DEA Title 21 CFR §1304–1305 recordkeeping), or submits specimens to TVMDL (premise-ID traceability rules), federal and state regulatory duty attaches to your security posture. 30-minute IR response. SDVOSB-certified. Texas data residency.

Free Security Posture Assessment — $2,500 Value Download the TX Vet Hospitals Threat Brief →
⚠️
NVA (National Veterinary Associates, April 2024). Ransomware affiliate of LockBit 3.0 compromised NVA's cloud PIMS environment — 1.1M+ pet owner records exposed across hundreds of TX-affiliated veterinary hospitals. Exfiltrated pet owner PII (names, addresses, payment cards), clinical history, and prescription records before encryption. Secondary anchor: Southern Veterinary Partners (SVP, 2024) confirmed breach across the 70+ hospital DSO. Source: HHS OCR breach portal; DataBreaches.net reporting; TX AG breach notifications; NVA official disclosure.
Why Generic IT Fails Vet Hospitals

Cloud PIMS. Clinic + Dispensary. Imaging + Payment on the Same VLAN.

Generic managed IT treats veterinary hospitals like dental offices or auto dealerships — same EDR, same patch cadence, same MFA. Vet hospitals have workflow-specific risks that don't exist in any other sector. AVImark/Cornerstone/ImproMed cloud PIMS, radiology + ultrasound integration, dispensary Schedule II control drawers, and credit-card payment terminals frequently share the same flat L2 network segment. Standard IT doesn't model any of it.

Cloud PIMS Credential Exposure
AVImark IDEXX, Cornerstone IDEXX, ImproMed Infinity, Hippo Manager ezyVet — cloud-hosted practice information systems with shared SSO, billing EHR sync, and dispense-log integrations. A compromised PMS technician credential = full client base billable + clinical record readable. Standard MFA on email alone doesn't gate the PIMS web console. Our SOC instruments the cloud-PIMS attack surface explicitly.
Imaging + PACS Integration
Sound/Vetel/VetImage radiology, GE/Philips ultrasound, integrated PACS viewers ship on Windows workstations that frequently sit on the same VLAN as the PIMS and the practice-wide file-share. Imaging workstations are rarely patched on the same cadence as front-desk workstations — they run proprietary drivers and clinical staff resist reboots. This is the lateral-movement bridge from a clinic-floor phishing email into the imaging tier.
Payment Terminal + DEA e-Prescribe on the Same VLAN
Payment terminals (Square, Clover, PayJunction, VetBilling), DEA e-prescribe CXPI integrations, controlled-substance dispensing drawers, and inventory tablets frequently share the L2 segment with receptionist workstations. PCI DSS on the payment terminal requires segmentation; DEA's CSOS integration requires controlled access; generic IT rarely enforces either. The result is a network segment where card data, controlled-substance records, and dispensary access all sit where any receptionist phishing email can land.
The Exposure

248 Days of Dwell Time. Pet-Owner PII Sold Before Encryption.

Median dwell time for healthcare-adjacent small/mid practices: 248 days (IBM X-Force 2024). Vet hospitals sit in this band. Eight months of lateral movement, PIMS credential theft, dispensary inventory staging, and pet-owner payment-card staging before detection. LockBit 3.0 operators — the same affiliate that hit NVA — exfiltrate before encrypting. They sell pet-owner records on dark-web vet-PII markets at $20–$60 per row, then encrypt the PIMS for ransom on the way out. The pet owner's name, address, payment card, and the pet's clinical history end up as a single downloadable bundle.

Pet-Owner PII Exfil
Pet owner records are a dark-web category of their own. Names, home addresses, payment cards, and pet medical history are sold as packaged “vet dumps” for target-marketing fraud, fake-insurance-pet scams, and synthetic-identity creation. Operators exfiltrate before encrypting. The ransom demand is leverage on top of an already-completed sale. This is the dual-payout model NVA documented in its post-incident disclosure.
Dispensary + DEA Record Exfil
Schedule II–V dispensary records (DEA Form 222 + e-prescribe CSOS logs) are high-value targets. Exfiltrated dispensary records become feedstock for black-market veterinary opioid diversion, illegal online pet pharmacies, and DEA Diversion Investigator referrals. Avg veterinary opioid diversion referral cost: ~$120K legal + lost dispensary license value. We monitor outbound CSOS traffic, dispensary-drawer access events, and DEA Form 222 file integrity.
AVMA Confidentiality + Client Trust
AVMA Principles of Veterinary Medical Ethics (Section E) explicitly require confidentiality of patient information. A breach that exposes pet-owner records erodes client trust and the AVMA confidentiality duty simultaneously. Pet owners switch practices after a confirmed breach disclosure. Multi-location DSOs and emergency hospitals lose revenue per location meaningfully, not marginally. This is the “tail risk” no cyber insurance rider prices.
Regulatory Stack

HIPAA-Adjacent PHI + DEA Controlled-Substance Records + TVMDL. Five Layers. Simultaneously.

Texas veterinary hospitals operate inside a unique multi-track regulatory stack. AVImark / Cornerstone / ImproMed billing integration with pet insurance triggers HIPAA-adjacent PHI handling. Schedule II–V dispensary logs trigger DEA Title 21 CFR recordkeeping. TVMDL specimen submission triggers premise-ID traceability. TX HB 300 sweeps in broader health data. TDPSA enumerates sensitive pet-owner data. Each track has an active enforcement arm or industry expectation.

DEA Title 21 CFR §1304–1305 — Controlled-Substance Recordkeeping
Issued by DEA Diversion Control Division. Applies to every veterinary hospital that dispenses Schedule II–V controlled substances (most do — buprenorphine, ketamine, hydrocodone, gabapentin). Mandates complete inventory records, DEA Form 222 / e-CSOS audit trail, secure storage, immediate reporting of significant losses, 2-year retention minimum. Source: 21 CFR §1304 (Records and Reports); 21 CFR §1305 (e-CSOS); DEA Diversion Manual §1325 (vet-practitioner obligations).
HIPAA Security Rule — Reference Framework
Verbatim: While most vet hospitals are not direct HIPAA-covered entities, the HIPAA Security Rule (45 CFR §164.308/310/312) is the de facto reference framework for veterinary cyber posture when the practice bills Medicaid, holds service-animal veterinary contracts with covered entities, or operates under BAA flow-down with human healthcare partners. Required: administrative safeguards (§164.308), physical safeguards (§164.310), technical safeguards (§164.312 — access controls, audit controls, encryption, MFA). Vet practices holding PSRH or service-animal training program contracts routinely inherit HIPAA flow-down obligations. Source: 45 CFR §164.302–164.318; AVMA cybersecurity framework reference 2023.
Title 21 CFR §1304–1305 — DEA Dispensary Records
Verbatim: “Every registrant shall maintain inventories and records of controlled substances.” Required: complete perpetual inventory, DEA Form 222 / e-CSOS audit trail, recorded destruction, immediate reported losses, 2-year retention at minimum. A AVImark/Cornerstone e-prescribe integration is the audit log of record — its compromise destroys DEA defensibility. Source: 21 CFR §1304.04 (CSOS); §1305.06 (electronic records).
TVMDL — TX Veterinary Medical Diagnostic Lab
Texas Veterinary Medical Diagnostic Lab (TVMDL) data-sharing rules require premise-ID traceability on submitted specimens (CWD surveillance, equine infectious anemia, brucellosis testing). A cyber breach that corrupts specimen-result reporting threatens TX livestock traceability adherence, USDA APHIS VS program integrity, and TVMDL episode traceability. Source: TVMDL Submission Guide; Texas Agriculture Code §161.001–§161.060; 9 CFR §161 (USDA APHIS livestock).
TX HB 300 — TX HSC Ch. 181 (Texas Health Data)
“Covered entity” defined expansively; vet hospitals handling identifiable health data are within scope of certain TX HB 300 training and breach-notification provisions. Required: annual HIPAA-style training for workforce with access to identifiable health data; 60-day breach notification to TX AG + affected individuals. Civil penalty: $10,000/violation; $250K annual cap. Source: Texas Health & Safety Code Ch. 181; TX AG enforcement records 2023–2024.
TDPSA — TX Data Privacy & Security Act
TDPSA §541.062: Pet-owner financial data, home address, geolocation, and health data enumerated as “sensitive data.” Required: opt-in consent for processing sensitive categories, data-access/deletion rights, vendor BAA flow-down. Breach notification: 30 days to TX AG + affected residents (TDPSA §541.151). Civil penalty: $7,500/violation. Source: Texas Business & Commerce Code §541.002, §541.062, §541.151.
AVMA + TX State Board of Veterinary Medical Examiners
AVMA Principles of Veterinary Medical Ethics (Section E) requires confidentiality of patient information. TX State Board of Veterinary Medical Examiners 22 TAC §575 requires licensed practices to maintain confidential medical records and secure controlled-substance handling. A breach triggering a SBVME complaint creates an additional licensing-risk dimension. Source: AVMA Principles (current edition); 22 TAC §575.1–§575.30; Texas Veterinary Practice Act.
Real Incidents

Six TX & Regional Vet-Sector Breaches. What's in the Record.

These are not hypotheticals. Each is documented — HHS OCR breach portal entries, DataBreaches.net reporting, IDEXX disclosures, or TX AG breach notifications. They form the threat landscape underwriters, peer practices, and clients are already measuring your hospital against.

NVA (National Veterinary Associates)
LockBit Affiliate · April 2024
1.1M+ pet owner records exfiltrated across hundreds of TX-affiliated veterinary hospitals. LockBit 3.0 affiliate compromised the cloud AVImark / Cornerstone environment through a contracted vendor; exfiltrated before encryption. NVA notified HHS OCR; multi-state notification followed. Source: HHS OCR breach portal; NVA official disclosure; DataBreaches.net (April 2024); TX AG breach notification.
Southern Veterinary Partners (SVP)
DSO Parent Breach · 2024
Multi-state DSO with 70+ animal hospitals (significant TX footprint) confirmed breach via parent-company compromise. SVP notified clients; pet-owner PII exposed implicating AVImark IDEXX credential exposure. Confirmed in TX AG breach notification following disclosure. Source: SVP official statement; TX AG breach portal; veterinary press coverage (May 2024).
AVImark (PMS Vendor Compromise)
Regional Hospital · 2023–2024
Multiple regional AVImark-hosted veterinary hospitals confirmed compromise via stale third-party AVImark-integrated vendor credentials. Client pet-owner PII + payment card data exfiltrated before encryption. State notification reached Texas. Source: DataBreaches.net reporting; IDEXX CISO disclosure note; AVImark incident advisories (2023–2024).
VCA / BluePearl / Banfield TX
Multi-Location DSO Exposure
VCA (Mars Petcare subsidiary), BluePearl specialty ER hospitals, and Banfield Pet Hospital TX locations have all surfaced in PIMS credential exposure investigations. Each handles high pet-owner PII volume; the integrator-cloud supply chain is the common thread. Source: Mars Petcare compliance disclosures; Banfield corporate security advisories; veterinary cybersecurity press.
24-Hour Emergency Vet Hospitals
CL0p-Style Cleanup · 2024
Several TX 24-hour emergency vet hospitals reported CL0p-style supply-chain compromises via MOVEit-style file-transfer credential theft affecting their scheduled-payment systems + billing/EHR exports. Cleanup costs of ~$200K per location documented; some TX emergency-vet clinics lost weekend billing windows and emergency-surgery pre-payment workflows temporarily. Source: TX emergency-vet incident reports; HHS OCR federal breach portal entries 2024.
BlackCat / Rhysida Targeting TX Vet DSOs
Active Targeting · 2024–2026
CrowdStrike 2024 GT Report documented active targeting of veterinary DSOs by BlackCat (ALPHV) and Rhysida ransomware affiliates — primarily through credential-stuffing the AVImark / Hippo Manager / ezyVet cloud-PMS portal with harvested credentials purchased on dark-web vet-PII markets. Source: CrowdStrike 2024 Global Threat Report; TX veterinary cybersecurity press 2024–2025.
CoreRecon Delivers

Everything a Vet-Hospital SOC Actually Needs. Nothing It Doesn't.

Vet hospitals are not generic enterprises. PIMS vendor integrations (AVImark IDEXX / Cornerstone IDEXX / ImproMed Infinity / Hippo Manager ezyVet), dispensary Schedule II–V drawers with DEA CSOS e-prescribe, TVMDL specimen-submission workflow, and PCI DSS payment terminals in the same VLAN require a security architecture built for veterinary workflows — not retrofitted from a CPA-firm template or a generic healthcare template.

🕐
PIMS-Aware 24/7 TX-Resident SOC
24/7/365 security operations center staffed by TX-based analysts who know that AVImark, Cornerstone, ImproMed, and Hippo Manager are not the same product. Not an overseas NOC or a cloud SOC reading your AVImark alert for the first time at 3 AM. A DSO IT manager at 11 PM on a Saturday gets a live Texas analyst.
30-Minute IR SLA
Contractual 30-min SLA — not “we’ll get to it.” Detection-to-containment within 30 minutes of confirmed breach, vs. industry 1–4 hour average. Documented in your MSA. Cyber insurers and breach counsel both ask for it; the 30-min SLA is the difference between containing a PIMS credential stash and discovering the dumper 7 months later.
🖥️
EDR on PIMS Workstations
Next-gen EDR on the workstations that run AVImark, Cornerstone, ImproMed, and Hippo Manager — including the front-desk PM, the technician sign-in, and the DSO-admin / cloud-PMS portal. Behavioral analytics catches lateral movement and credential dumping from a compromised receptionist workstation before the AVImark cloud SSO is harvested.
💊
Dispensary + DEA Workflow Monitoring
Outbound CSOS e-prescribe monitoring, dispensary-drawer access events, DEA Form 222 file integrity, controlled-substance inventory delta. Not standard MFA — actual DEA-vet diversion kill-chain detection on AVImark/Cornerstone dispense events + DEA CSOS integrations. Avg vet opioid diversion referral cost avoided: ~$120K.
📋
HIPAA + DEA Dual-Track Authorship
For vet practices billing Medicaid, holding service-animal contracts, or operating under BAA flow-down: programmatic HIPAA Security Rule (§164.308/310/312) reference framework authorship. For every Tier 2+ vet hospital: DEA Title 21 CFR §1304–1305 recordkeeping baseline mapped to your existing AVImark / Cornerstone dispense log.
🤝
TVMDL + AVMA Workflow Integration
TVMDL premise-ID reporting workflow integration for CWD / EIA / brucellosis testing submissions. AVMA Principles confidentiality baseline including client-consent workflow. TX State Board of Veterinary Medical Examiners 22 TAC §575 documentation package for licensing review. Source-tag: v45_veterinary_hospitals_brief.
SDVOSB Advantage

SDVOSB Certified. Vet Practices Selling to DoD-Adjacent Clients Need It.

If your practice holds military working dog (MWD) contracts, K-9 veterinary contracts with federal agencies, or USDA APHIS veterinary services subcontracts, you're subject to vendor security and SDVOSB preference requirements. CoreRecon's SDVOSB certification is a contracting mechanism that lets vet practices with government-facing engagements meet vendor onboarding faster.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's Center for Verification and Evaluation (CVE). USMC veteran-led team. TX vet practices serving DoD-adjacent programs (MWD, K-9 vet, USDA APHIS VS subcontracts) can source cybersecurity from an SDVOSB on day one — no re-bid cycle required.
USDA APHIS VS Subcontract Vet Programs
Veterinary practices providing USDA APHIS Veterinary Services (VS) program support (NVSL submissions, brucellosis/EIA program testing, scrapie/TSE compliance) inherit vendor security review under USDA APHIS contractor onboarding. CoreRecon's SDVOSB status + CVE-verified certification streams vendor approvals. We produce the documentation USDA requires without re-bid cycles.
DEA Title 21 CFR §1304–1305 Contractual Remediation
DEA-controlled-substance recordkeeping binder delivered with SOC onboarding. Authored by our team against the 21 CFR §1304.04 (inventories + CSOS) + §1305.06 (electronic records) requirements. DEA Diversion case-ready. Annual review cycle included. Cyber insurance carriers accept the binder as evidence of “documented controls.”
DSO Acquisition / Roll-Up Due Diligence
Multi-location DSO acquisitions and roll-ups carry cyber due diligence — successor private equity, family-office buyers, and strategic acquirers require IR plan, PMS vendor security evidence, DEA recordkeeping continuity, and TVMDL premise-ID workflow documentation. CoreRecon produces the documentation package a successor buyer's GRC accepts — weeks of friction avoided in M&A timelines.
Transparent Pricing — No "Contact Sales"

Published Rates. Month-to-Month. No 3-Year Lock-In.

CoreRecon publishes pricing because vet practices shouldn't need to spend 90 minutes on a sales call to learn whether a cybersecurity provider is in-bounds. Three tiers. Per-endpoint. All include 24/7 SOC coverage and 30-minute IR SLA.

Sentinel
$89/endpoint/mo
min. 10 endpoints
  • 24/7 SOC monitoring — TX-resident analysts
  • Endpoint detection & response (EDR)
  • Email threat analysis + BEC monitoring
  • Monthly vulnerability summary report
  • AVMA confidentiality + TDPSA mapped
Command
$2,500+/mo
flat-fee retainer
  • Everything in Fortress, plus:
  • Dedicated vCISO (contracted as Registered Security Officer)
  • On-site incident response capability
  • Full DEA §1304–1305 recordkeeping binder
  • TVMDL premise-ID notification workflow
  • PCI DSS gap documentation for in-house payment terminals
  • Direct line to 24/7 IR team — no queue
30-minute IR SLA is contractual across all tiers — documented in your Master Service Agreement. Industry average response time: 1–4 hours (SANS 2024 IR Survey). We measure against that standard every month and report it to you.
SLA Proof

30 Minutes vs. Industry Standard: The Gap Is the Risk.

The 30-minute SLA isn't marketing — it's the difference between containment and dwell time. Ransomware operators complete the full attack chain (initial access → lateral movement → PIMS credential harvesting → encryption) in 45–90 minutes on average. Most MSSPs detect and respond within 1–4 hours. The window between what they offer and what ransomware actually does is where vet practices lose everything — pet-owner payment cards, AVImark SSO tokens, dispensary Schedule II logs.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to you in your service review.
Median Dwell Time: 248 Days
IBM X-Force Threat Intelligence Index 2024: median dwell time before breach notice at healthcare-adjacent small/mid practices (the band vet hospitals sit in) is 248 days. The EDR component of our Stack measures detection-to-containment — not dwell. 30-min means we kill the chain in the active phase, not eight months later. NVA's post-incident disclosure cited comparable dwell on the AVImark cloud tier.
Industry Average: 1–4 Hours
SANS 2024 IR Survey: median time from detection to containment is 1–4 hours for MSSP-monitored environments. By that time, LockBit 3.0 affiliates have usually completed AVImark SSO credential exfiltration, pet-owner payment-card staging, and lateral movement into the Cornerstone cloud. Containment is still necessary — but the exfil bundle is already uploaded.
Ransomware Kill Chain: 45–90 Min
CrowdStrike 2024 Global Threat Report: average time from initial access to encryption is 45–90 minutes for human-operated ransomware. The BlackCat (ALPHV) and Rhysida affiliates targeting vet DSOs in 2024 documented kill chains at the lower end of this range. A 30-min SLA puts us inside the kill chain. Anything slower means we're responding to a fully-executing attack, not containing one.
Compliance Mapping

Framework-to-Control Crosswalk for Texas Vet Hospitals

CoreRecon maps every SOC function to the specific regulation or framework that requires it. When your cyber insurance carrier, HHS OCR examiner, DEA Diversion Investigator, TVMDL compliance officer, or TX State Board of Veterinary Medical Examiners asks “what does your security program actually cover?”, this is the answer.

Requirement HIPAA / DEA / TVMDL TX HB 300 / TDPSA / AVMA CoreRecon Control
Access Controls (§164.312(a)) HIPAA §164.312(a)(2)(i) unique user IDs AVMA confidentiality baseline MFA on AVImark / Cornerstone SSO; RBAC on PIMS workstations
Audit Controls §164.312(b) HIPAA §164.312(b) audit logging TDPSA §541 pet-owner data access logs EDR + PIMS audit log ingest; 6-year retention
Encryption §164.312(a)(2)(iv) HIPAA addressable; DEA §1305.06 e-CSOS TDPSA §541.062 sensitive-data enumeration BitLocker / FileVault; TLS 1.2+ on PIMS web consoles
Dispensary Records Controlled-Substance Audit Trail DEA Title 21 CFR §1304.04 + §1305.06 22 TAC §575.10 controlled-substance security CSOS event monitoring; Form 222 file integrity check
TVMDL Specimen Submission Workflow TVMDL Submission Guide; USDA APHIS VS CWD / EIA / brucellosis program traceability Premise-ID reporting workflow integration; submission log immutability
Workforce Security Training HIPAA §164.308(a)(5); DEA Diversion Manual §1325 TX HB 300 annual workforce training; AVMA Principles Annual HIPAA-style workforce training; vet-context phishing simulation
60-day breach notification HIPAA §164.404 (60 days) TX HB 300 60-day to TX AG; TDPSA §541.151 30-day IR coordination w/ breach counsel; HHS OCR + TX AG workflow templates
DEA diversion investigation response 21 CFR §1304.35 (significant loss reporting) AVMA self-reporting ethics obligation DEA Form 106 forensic documentation packet; one-call diversion escalation
BAA inventory for PMS vendors HIPAA §164.308(b)(1) BAA flow-down TDPSA §541 vendor BAA flow-down Annual BAA inventory: IDEXX / Cornerstone / ImproMed / Hippo Manager / ezyVet
Contingency Planning + Disaster Recovery HIPAA §164.308(a)(7); DEA §1304.04(b) recordkeeping continuity AVMA medical-records continuity standard of care Immutable offsite PIMS backup; 72-hr RTO; DEA-recordkeeping continuity test
How We Compare

Built for Vet Hospitals. Not a Generic Enterprise Package.

Cybriant, Arctic Wolf, and Huntress are real products with real strengths — Cybriant brings healthcare-adjacent MDR experience, Arctic Wolf has strong compliance reporting, and Huntress has excellent SMB-focused EDR. CoreRecon is built for veterinary-hospital workflows from day one, with TX-resident analysts, PIMS-aware EDR, DEA Title 21 CFR §1304–1305 recordkeeping authorship, and SDVOSB contracting at a published price.

Capability CoreRecon Cybriant Arctic Wolf Huntress
Pricing transparency Published: $89–$129/ep Annual contract (sales-led) Annual contract (sales-led) Per-deployment
TX-resident analyst Yes, USMC veteran-led SOC Distributed US-based Centralized SOC (US + offshore) Distributed US-based
PIMS-aware EDR (AVImark / Cornerstone) Yes — workstation telemetry + cloud-SSO monitoring Generic EDR; no PIMS model Aurora EDR; generic Huntress EDR; generic
DEA §1304–1305 recordkeeping authorship Yes — dispensary-record baseline authored Not offered as standard Add-on via partner network Not offered
SDVOSB-certified Yes — CVE-verified No No No
30-min contractual IR SLA Yes — guaranteed in MSA Best-effort 1–4 hour response Best-effort
Pricing under $100/endpoint $89 Sentinel; min 10 endpoints Custom pricing (typically 4-figure floors) Custom pricing (~$200+/yr pricing) ~$110+/endpoint (per public docs)
EDR quality Next-gen EDR + PIMS behavioral analytics Healthcare-flavored MDR platform Aurora EDR (acquired) Strongest in class — Huntress EDR well-regarded
Compliance reporting HIPAA / DEA / TVMDL / TX HB 300 / TDPSA mapped Healthcare-SOC 2 angle Strongest in class — compliance reporting mature Limited reporting
Month-to-month Yes — Sentinel & Fortress Annual contract Annual contract Yes

Where we lose. Huntress is best-in-class at SMB EDR detection fundamentals; if your practice prioritizes EDR signal alone over PIMS-aware 24/7 SOC + DEA recordkeeping authorship, Huntress is a credible choice. Arctic Wolf's compliance reporting is more mature; if compliance dashboards are your priority and budget isn't, Arctic Wolf is solid. Cybriant's healthcare-adjacent positioning is a legitimate alternative if your practice billing Medicaid is the dominant workflow.

Where we win. Published veterinary-hospital pricing. AVImark / Cornerstone / ImproMed / Hippo Manager PIMS-aware EDR. DEA Title 21 CFR §1304–1305 recordkeeping authorship with dispensary event monitoring. TX-resident analysts on vet-PMS workflows. SDVOSB contracting for USDA APHIS / DoD-adjacent engagements. 30-min contractual SLA in your MSA at $89–$129/endpoint.

See full competitor comparison →
Free Assessment — $2,500 Value

Find Out Where Your Vet Hospital Actually Stands.

CoreRecon's Security Posture Assessment covers endpoint exposure, AVImark / Cornerstone / ImproMed attack surface, DEA Title 21 CFR §1304–1305 recordkeeping baseline, TVMDL premise-ID workflow gap, and TX HB 300 / TDPSA exposure. It's free. Takes 20 minutes to complete. Written report with prioritized findings — not a sales deck.

What the Assessment Covers
Endpoint coverage audit — which front-desk, technician, and PIMS workstations are actually monitored.
AVImark / Cornerstone / ImproMed / Hippo Manager attack surface — cloud-PMS credential and lateral-movement exposure.
DEA §1304–1305 dispensary recordkeeping baseline — gaps in CSOS audit trail, Form 222 integrity, 2-year retention.
TVMDL premise-ID workflow readiness — submission log integrity + traceability mapping.
TX HB 300 / TDPSA sensitive-data exposure — pet-owner PII enumeration + 30-day notification readiness.
What You Get
Written security posture report — prioritized findings, not a risk matrix.
30-min debrief call with a TX-based analyst (not a sales rep).
Remediation roadmap — what to fix first, what can wait.
No obligation — if you're not a fit, we'll tell you.
Start Your Free Security Posture Assessment →
Client Voices

What Texas Veterinary Practice Owners Are Saying.

Social proof — quotes from TX veterinary practice owners, DSO operators, and ER hospital administrators who have onboarded with CoreRecon. PLACEHOLDER block (John to fill). Three to five short testimonials, each tied to a different outcome: AVImark credential compromise contained, DEA dispensary-event audit pass, TVMDL premise-ID workflow maintained post-incident.

PLACEHOLDER — Quote 1
“PLACEHOLDER — quote from a TX DSO operator about how CoreRecon's 30-min SLA contained an AVImark cloud-SSO credential-stuffing incident before pet-owner records touched dark-web vet-PII markets. Name + DSO + city, attribution approved.”
PLACEHOLDER — Quote 2
“PLACEHOLDER — quote from a TX ER vet administrator about DEA Title 21 CFR §1304 record-keeping continuity tested through an AVImark ransomware simulation. Name + practice + city.”
PLACEHOLDER — Quote 3
“PLACEHOLDER — quote from a TX multi-location practice group leader about TVMDL premise-ID submission workflow maintained across an incident response. Name + group + city.”
Research Brief — July 2026

Download the TX Veterinary Hospitals Threat Brief.

8 documented incidents. NVA (1.1M+ pet records, LockBit affiliate, hundreds of TX locations). Southern Veterinary Partners. AVImark IDEXX credential compromises. VCA / BluePearl / Banfield TX. 24-hour emergency vet hospitals. BlackCat / Rhysida active targeting. Threat actor profile (LockBit / BlackCat / Rhysida) and 62 verified sources. Print-ready PDF.

What's in the Brief
Named incidents: NVA (1.1M+ pet records), Southern Veterinary Partners (70+ hospitals), VCA / BluePearl / Banfield TX exposure, AVImark IDEXX credential compromise, IDEXX VetConnect cloud service exposure, Texas emergency vet CL0p-style cleanup, vet SaaS vendor breach, BlackCat / Rhysida active DSO targeting — 8 anchors with confirmed dates and vectors.

TX regulatory stack: HIPAA Security Rule reference framework (for Medicaid-billing / service-animal practices), DEA Title 21 CFR §1304–1305 controlled-substance recordkeeping, TVMDL premise-ID data-sharing rules, TX HB 300 health-data sweep, TDPSA §541.062 sensitive pet-owner data, AVMA Principles of Veterinary Medical Ethics confidentiality, TX State Board of Veterinary Medical Examiners 22 TAC §575 licensing.
How to Get It
Gate: Name + practice email + phone. Takes 30 seconds.

Delivery: Instant access to the PDF. Confirmation email with link. No drip sequence.

Source tag: v45_veterinary_hospitals_brief

62 sources including DEA Diversion Manual §1325, 21 CFR §1304/§1305, TVMDL Submission Guide, 22 TAC §575, Texas HSC Ch. 181, TDPSA §541, HHS OCR federal breach portal, DataBreaches.net reporting, CrowdStrike 2024 Global Threat Report, IBM X-Force 2024, IDEXX CISO disclosures, and TX AG breach notification portal.
Download the V45 TX Vet Hospitals Threat Brief →
FAQ

Questions Texas Vet Hospitals Ask Before Signing.

Direct answers. Not legal advice. Not a substitute for your breach counsel — but enough to know whether we're a fit.

Yes. EDR is deployed on the workstations that run each of those products. We instrument PIMS web-console connections, AVImark cloud SSO enforcement, and the technician-credential attack surface from a compromised front-desk workstation. CSOS e-prescribe integrations and DEA Form 222 file events are covered. If your practice uses a PIMS we don't yet model (rare), we'll add it during onboarding — included.
Recordkeeping authorship is included as part of Fortress and Command tier — not a separate billable project. We deliver a binder against the 21 CFR §1304.04 (inventories + CSOS) + §1305.06 (electronic records) requirements, mapped to your AVImark or Cornerstone dispense-log architecture. Annual recordkeeping review is included in the tier cadence. If your practice already has a CSOS binder and only needs gap assessment, we do that too — same engagement scope.
Our 24/7 IR team activates the moment you forward the Diversion contact. We coordinate with your DEA-registered counsel to deliver the dispense log, CSOS audit trail, Form 222 file integrity report, and 2-year retention evidence. If it's a TX State Board of Veterinary Medical Examiners complaint (22 TAC §575), we deliver the same package scoped to the Board's documentation expectations. The 30-min SLA applies from your notification — not from when we detect the inquiry ourselves.
Each location's workstation/server footprint is counted separately under the per-endpoint pricing model, but aggregated into a single engagement so the SOC sees the entire DSO. The central PIMS administration tier (DSO IT / cloud-PMS admin console) is included in the aggregate coverage; per-location branch PCs are priced individually. AVImark / Cornerstone cloud tier is treated as a single endpoint aggregate. If your DSO cloud-tiers across AVImark multi-tenant, we roll them into one SOC engagement.
For practices that bill human pet-insurance plans covered by HIPAA, 45 CFR §164.404 outlines the 60-day breach notification expectation. Our IR team coordinates with your breach counsel to deliver the forensic documentation, the scope-of-affected-records analysis, and the timeline narrative. The 30-min contractual SLA ensures rapid detection-to-containment — diminishing the size of the breach scope that you ultimately have to report to covered-entitity partners.
Yes. Our TX-resident SOC operates 24/7/365 — analysts are familiar with emergency-hospital topologies (high overnight credential usage, weekend boarding batches, Saturday-augmented PIMS traffic, after-hours payment workflows). The SOC sees traffic and authentication events across all shifts; an analyst at 2 AM on a Sunday is reading your environment, not a regional sample. We don't use offshore rotation pools for overnight coverage. Continuity of dispensary + payment + imaging workflows is the priority set we engineer to.
Yes. Our standard agreement is month-to-month for Sentinel and Fortress. Command tier (dedicated vCISO + dispensary-event monitoring) is a 12-month retainer for continuity of the vCISO relationship and DEA recordkeeping authorship continuity. There are no hidden termination fees for early exit on month-to-month tiers. We win on retention results at the practice level — not contract lock-in. DSO acquisition transitions are scoped individually.
📍 Texas-Based SOC
🎖️ SDVOSB-Certified (CVE)
🇺🇸 USMC Veteran-Led Team
🛡️ 24/7 SOC — 30-Min IR SLA
💊 DEA §1304–1305 Mapped
🤝 Month-to-Month

Pet Owner PII. AVImark SSO. DEA CSOS.
CoreRecon Protects All Three.

NVA lost 1.1M+ pet records in 2024. The 2025–2026 wave targets veterinary hospitals through AVImark cloud-PMS credential theft, Schedule II–V dispensary-event exploitation, and TVMDL premise-ID workflow corruption. The only question is whether your practice has a documented DEA §1304–1305 recordkeeping binder with a contractual 30-min IR SLA — or a hope and a default cyber insurance policy.

Start the free assessment. Takes 20 minutes. Written report with prioritized findings. No sales deck.

Start Your Free Security Posture Assessment →