Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
The 60-Day Clock Starts at Discovery, Not at Cleanup
A behavioral health provider that discovers a PHI breach has 60 calendar days from the date of discovery to notify affected individuals, and, for breaches of 500 or more people, to also notify HHS and prominent media in the affected state. That is not aspirational. It is the outer limit written into 45 CFR 164.404, which requires notification without unreasonable delay and no later than 60 calendar days after discovery.
The volume behind that rule is not theoretical. OCR’s 2024 Report to Congress documented 663 notifications of breaches of unsecured PHI affecting 500 or more individuals that occurred during 2024, affecting a total of approximately 242,908,056 individuals, plus another 74,299 reports of data breaches affecting fewer than 500 individuals. Behavioral health operators sit inside that statistic, now with the added weight of 42 CFR Part 2.
On February 13, 2026, OCR announced a civil enforcement program for the confidentiality of SUD patient records, effective February 16, 2026. Operators who survive the OCR follow-up a year later are the ones who treated hour one like a regulator was already watching. Because, effectively, one is. OCR investigates all breaches of protected health information (PHI) and Part 2 records that affect 500 or more individuals, and its portal has separate submission paths for PHI and Part 2 records.
Hour One Through Day Three: Facts First, Notifications Later
The first questions are not about notification. They are about facts. What systems were accessed. Whether PHI was viewed, exported, or modified. How far the compromise reached.
AHS opens every engagement the same way: evidence preservation, log review, network activity analysis, and isolation of compromised endpoints. Guesswork at this stage is what blows up the OCR submission later.
While forensics runs, a second team maps the data elements affected. Names. Addresses. Clinical notes. SUD records. Diagnoses. Treatment details. Financial information. That mapping determines the reporting path. OCR’s portal has one submission path for PHI and, since February 16, 2026, a separate path for breaches of SUD patient records under Part 2, which means a single incident can generate two federal reports. Entities are now able to file breach reports under Part 2 using a new form on OCR’s existing breach portal, and OCR will accept complaints of alleged violations.
This is the failure point for operators without dedicated support. Their leaders try to manage IT remediation, patient notifications, OCR reporting, insurer communication, and legal review at the same time, with limited documentation and unclear sequencing. AHS coordinators stage the work so attorneys receive precise timelines, access details, and confirmation of exposed elements in a format they can actually use to advise the board.
The timing pressure is not abstract. IBM’s 2025 Cost of a Data Breach Report puts healthcare at USD 7.42 million average breach cost, the highest among industries for the 14th consecutive year, down from USD 9.77 million the prior year. Healthcare breaches took the longest to identify and contain at 279 days, more than five weeks longer than the global average.
Part 2 Changed the Math for SUD Programs in February 2026
Behavioral health operators who treat substance use disorders should understand what changed this year. In February 2024, HHS published a final rule modifying the regulation at 42 CFR part 2 to implement the confidentiality provisions of section 3221 of the CARES Act. Enforcement previously lived with SAMHSA and DOJ and was almost never used in practice. That regime is over.
Beginning February 16, 2026, OCR began accepting complaints alleging violations of the regulation that protect the confidentiality of SUD patient records, and notifications of breaches of SUD patient records. OCR investigations conducted under the new program may be resolved through a range of civil enforcement mechanisms, including OCR entering into resolution agreements, securing monetary settlements, obtaining commitments for corrective action, or imposing civil money penalties for the failure to comply.
The penalty exposure now mirrors HIPAA. The penalties for noncompliance align with the penalties available under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. For a residential SUD program in Florida or an opioid treatment program in Ohio, the breach response plan has to explicitly address Part 2 records.
Every AHS client we have walked through Part 2 readiness in the last twelve months has needed three things rebuilt: EHR audit logging, breach risk-assessment template, and notification letter templates. Old HIPAA-only playbooks miss the Part 2 reporting path entirely.
OCR Director Paula M. Stannard framed the point directly in the enforcement announcement: “OCR is uniquely positioned to enforce patient rights and the regulated community’s obligations given our extensive experience administering compliance and enforcement programs for health information privacy, security, and breach notification under HIPAA.”
What Counsel and OCR Actually Want to See
Once the facts are clear, the work shifts to containment, remediation, and operational recovery. AHS coordinates the standard remediation set: securing compromised accounts and devices, resetting authentication, repairing vulnerabilities, restoring clean backups, activating encrypted internal communication channels, and verifying system integrity before returning to normal operations.
Notification documents are the next pressure point. Many covered entities notify HHS, state attorneys general, and affected patients but skip the media notice. Covered entities that experience a breach affecting more than 500 residents of a state or jurisdiction are required to provide notice to prominent media outlets serving that state under 45 CFR 164.406, and the media notice is itself a Breach Notification Rule requirement.
The penalties for getting the rest wrong are not abstract. In January 2025, Solara Medical Supplies paid $3,000,000 to OCR to resolve alleged HIPAA Security Rule and Breach Notification Rule violations tied to a 2019 phishing incident. OCR received a breach report concerning a phishing attack in which an unauthorized third party gained access to the email accounts of eight Solara employees between April and June 2019, resulting in the breach of the ePHI of 114,007 individuals. Solara Medical Supplies failed to issue timely notifications to the HHS for both breaches, did not provide timely notifications to the individuals affected by the phishing breach, and did not issue a timely notification to prominent media outlets about the phishing breach, in violation of 45 C.F.R. § 164.404 and 45 C.F.R. § 164.406 of the HIPAA Breach Notification Rule. That third failure, the media notice, is the one operators most consistently miss.
Months after the immediate work ends, the regulatory follow-up arrives: audits, corrective action plans, documentation requests, and inquiries about security practices before the breach. AHS prepares clients for that second wave by building integrated corrective action plans that pair technical fixes with policy updates, workforce training, and governance reinforcement.
Preparation Is the Only Real Defense
The strongest breach response starts long before the breach. In its 2024 Report to Congress, OCR identified the Security Rule standards and implementation specifications of risk analysis, risk management, information system activity review, audit controls, and person or entity authentication as key areas for improvement in 2024 breach investigations. Those are the same items OCR keeps writing into resolution agreements.
For behavioral health operators specifically, AHS recommends five concrete pre-breach actions:
- A documented breach response plan that explicitly addresses Part 2 records
- An annual risk analysis, dated and signed
- Tabletop exercises with IT and clinical leadership
- Business associate agreement audits with every EHR and billing vendor
- Workforce training tracked at the individual level
HHS requires entities to retain breach documentation for at least six years. None of this is about avoiding scrutiny. Operators need to be able to show, on the day an OCR investigator or a Florida AHCA surveyor or an Ohio Department of Mental Health and Addiction Services reviewer asks, that they understood the risk, mitigated it, and acted within the timelines the regulation requires.
That is the work AHS does as the operational anchor when a breach happens, and the planning work AHS does before it does.
Frequently asked questions
How quickly does a behavioral health provider have to report a PHI breach to OCR?
For breaches affecting 500 or more individuals, providers must notify affected individuals, HHS OCR, and prominent media in the affected state without unreasonable delay and no later than 60 calendar days from the date of discovery, per 45 CFR 164.404 and 45 CFR 164.406. For breaches affecting fewer than 500 individuals, providers log the incident and submit to OCR no later than 60 days after the end of the calendar year in which the breach was discovered. The clock starts on the discovery date, not the date the investigation concludes.
Do SUD records require a separate breach report under 42 CFR Part 2?
Yes. Beginning February 16, 2026, OCR began accepting complaints and breach notifications involving SUD patient records under Part 2 alongside its existing PHI breach reporting. A single incident at a Part 2 program that exposes both PHI and SUD records can generate two federal reports, and OCR now has authority to impose resolution agreements, monetary settlements, corrective action plans, and civil money penalties for Part 2 violations.
What are OCR’s most common findings in breach-related enforcement actions?
OCR’s 2024 Report to Congress identified risk analysis, risk management, information system activity review, audit controls, and person or entity authentication as the Security Rule standards most consistently cited as areas for improvement in 2024 breach investigations. The January 2025 Solara Medical Supplies settlement, in which Solara paid $3,000,000 to OCR after a phishing incident affecting 114,007 individuals, cited the same pattern: failure to conduct a compliant risk analysis, failure to implement sufficient security measures, and failure to provide timely breach notification to individuals, HHS, and the media.
How much does a healthcare data breach actually cost?
IBM’s 2025 Cost of a Data Breach Report puts the average healthcare incident at $7.42 million, the highest of any industry for the 14th consecutive year, with a mean 279 days to identify and contain, roughly five weeks longer than the global average. For behavioral health operators, the cost stack also includes OCR civil monetary penalties, state attorney general fines, class action exposure, and business associate remediation obligations.
References
- HHS OCR, 2024 Annual Report to Congress on Breaches of Unsecured Protected Health Information
- HHS, Office for Civil Rights Announces Civil Enforcement Program for Confidentiality of Substance Use Disorder Patient Records (Feb. 13, 2026)
- 45 CFR 164.404. Notification to individuals
- 45 CFR 164.406. Notification to the media
- IBM, Cost of a Data Breach Report 2025
- HIPAA Journal, Solara Medical Supplies Pays $3M to Settle Alleged HIPAA Security and Breach Notification Rule Violations (Jan. 2025)
- HHS OCR Breach Reporting Portal
- TechTarget Healthtech Security, OCR Launches Part 2 Civil Enforcement Program, New Breach Portal Features