Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
An IT outage in behavioral health is a compliance event, not a help-desk ticket
Short answer: When a behavioral health operator loses IT, the CEO is simultaneously managing a HIPAA event, a 42 CFR Part 2 event, a payer-reimbursement event, and a state licensure event. Treat that moment as a vendor ticket and the executive team loses control of the response before lunch.
The Change Healthcare ransomware attack made the stakes concrete. According to the HHS Office for Civil Rights FAQ page, on July 31, 2025, Change Healthcare notified OCR that approximately 192.7 million individuals have been impacted, and outside counsel has since characterized the incident as the largest healthcare data breach ever recorded. The root cause was mundane: a ransomware attack orchestrated by the ALPHV/BlackCat group exploited a Citrix portal lacking multi-factor authentication, and once inside, the attackers moved laterally across the network for nine days, exfiltrating sensitive data and ultimately deploying ransomware. One missing control. Nine-figure fallout.
Behavioral health carries a different risk profile than the rest of medicine. SUD and mental health records sit under 42 CFR Part 2 and state confidentiality overlays. Clinicians deliver care by telehealth as a default channel. Founders run decentralized outpatient footprints across multiple states with clinical workforce stretched thin.
When one EMR goes down at a Florida PHP at 6:30 a.m., the CEO’s questions hit fast. Are clinicians breaching timely access standards? Did the overnight group’s progress notes survive? Will the payer deny the day? Do we owe a notification to AHCA or DCF? Yet operators keep buying IT, cybersecurity, and HIPAA as three separate vendor contracts. One firm runs help-desk tickets. Another runs a quarterly scan. A third sells a binder of templated policies. When a ransomware event, a Medicaid SIU audit, or an OCR inquiry lands, the CEO discovers nobody owns the risk across systems, workflows, and regulators.
Why vendor-based IT support fails behavioral health operators at scale
General IT shops close tickets. They do not build regulatory defensibility. Most cannot articulate the 42 CFR Part 2 Final Rule that SAMHSA and OCR issued on February 8, 2024. Per the HHS fact sheet, persons subject to the regulation must comply with the applicable requirements of the final rule by February 16, 2026. The 2024 Final Rule applies the HIPAA Breach Notification Rule requirements to Part 2 records and aligns Part 2 enforcement with HIPAA by providing for both civil and criminal penalties.
Healthcare-marketed cybersecurity firms often stop at technical controls. They harden a firewall. They do not manage breach notification timelines, payer disclosures, state licensing board exposure, or the corrective action plan an operator will negotiate with OCR.
Generic HIPAA vendors hand out static policies that will not survive an investigation. Then-OCR Director Melanie Fontes Rainer said publicly at an OCR/NIST conference in October 2024 that despite several years of OCR guidance on the standard having been available to organizations, a risk analysis is flagged in four out of every five enforcement actions. A policy binder does not fix that. A documented, current, technology-asset-tied risk analysis does.
Then there is the volume problem. HHS reports that ransomware and hacking are the primary cyberthreats in health care, and since 2018, there has been a 264% increase in large breaches reported to OCR involving ransomware attacks. OCR stood up its Risk Analysis Initiative in the fall of 2024 and has since announced multiple settlements under it. Our team has walked into behavioral health operators in Florida, Texas, and Tennessee that believed they were “covered” until a ransomware incident, a whistleblower complaint, or a Medicaid SIU audit exposed the absence of governance. The failure point is rarely technology selection. Founders and CEOs are missing an MSO-level layer that ties IT, compliance, operations, and reimbursement into a single accountable structure.
The AHS MSO model: IT, cybersecurity, and breach readiness under one governance layer
Atlantic Health Strategies operates as the control plane across vendors, systems, and regulators. We do not sell software. We do not outsource accountability. We govern.
Our team standardizes IT architecture across multi-site operators, vets vendors, negotiates contract terms that actually shift liability appropriately, and enforces a security baseline (not aspirational language in a policy). We oversee access controls, device management, data segregation between Part 2 and non-Part 2 records, and telehealth security with behavioral-health-specific assumptions built in. When a clinician is terminated at 7 p.m., our team revokes access in minutes, not the next business day.
We design breach response as a business continuity function, not a legal afterthought. That includes incident command structures, forensic coordination, legal escalation pathways, payer notification protocols, and clinical operations preservation so the census does not collapse during a crisis. Our clients are not improvising between their IT firm, outside counsel, and a state regulator while a ransomware actor sits on their network. Our team pre-governs the response.
When OCR announced its first Risk Analysis Initiative settlement, Director Fontes Rainer put it plainly: “Failure to conduct a HIPAA Security Rule risk analysis leaves health care entities vulnerable to cyberattacks, such as ransomware. Knowing where your ePHI is held and the security measures in place to protect that information is essential for compliance with HIPAA”. Operators who pretend otherwise are making a leadership choice, not a technology one.
HIPAA and 42 CFR Part 2 must be embedded in clinical workflow, not bolted on
HIPAA compliance in behavioral health is inseparable from clinical workflow. Consent management, data sharing, documentation access, role-based permissions, and audit logs all intersect with privacy law. SUD programs carry additional exposure under Part 2, particularly when operators enter value-based contracts, care coordination arrangements, or HIE integrations.
The 2024 Part 2 Final Rule allows a single consent for all future uses and disclosures for treatment, payment, and health care operations, and allows HIPAA covered entities and business associates that receive records under this consent to redisclose the records in accordance with the HIPAA regulations. It also applies HIPAA’s Breach Notification Rule to Part 2 records and aligns Part 2 enforcement with HIPAA.
OCR is already positioned to act. On February 13, 2026, HHS OCR announced a new civil enforcement program for the confidentiality of SUD patient records, and beginning February 16, 2026, OCR began accepting complaints alleging violations of the regulation that protect the confidentiality of SUD patient records and notification of breaches of SUD patient records. OCR investigations conducted under the new program may be resolved through a range of civil enforcement mechanisms, including OCR entering into resolution agreements, securing monetary settlements, obtaining commitments for corrective action, or imposing civil money penalties for the failure to comply. Operators in Florida (AHCA and DCF), Texas (HHSC), and Tennessee should treat Part 2 exposure as live and enforceable.
The cybersecurity side is tightening too. On December 27, 2024, OCR issued a Notice of Proposed Rulemaking to modify the HIPAA Security Rule, and the NPRM proposes to remove the distinction between “required” and “addressable” implementation specifications and make all implementation specifications required with specific, limited exceptions. Proposed technical controls include encrypting ePHI at rest and in transit; multi-factor authentication (MFA); anti-malware protection, network segmentation; separate controls for backup and recovery of ePHI; vulnerability scanning at least every six months; penetration testing at least once every 12 months; and patch management, plus a documented technology asset inventory and network map. Our team embeds those requirements into operational design, not a policy refresh. That includes workforce training tied to job function, consent workflows that match real clinical practice (not idealized flowcharts), audit-ready documentation frameworks, and continuous monitoring tied to payer and regulator expectations. For operators preparing for a transaction, our team aligns compliance infrastructure with the diligence standards used by private equity and strategic buyers, because compliance theater collapses fast in a quality-of-earnings review.
Strategic outcomes for behavioral health CEOs, boards, and investors
Boards are catching up to what operators have known for years: IT and cybersecurity failures are leadership failures. Downtime crushes access metrics. Breaches trigger payer reviews and 60-day notification clocks. Compliance gaps delay expansion approvals and depress valuation in a sale.
The dollar figures are board-level. In the Bryan County Ambulance Authority settlement, the first case under the Risk Analysis Initiative, as documented by WilmerHale, BCAA reported that files impacted by the ransomware contained the ePHI of approximately 14,273 patients and agreed to pay $90,000 and implement a corrective action plan that the HHS OCR will monitor for three years. IBM’s 2024 Cost of a Data Breach analysis found that for the 14th year in a row, healthcare participants saw the costliest breaches across industries with average breach costs reaching $9.77 million. And regulator activity is not slowing: the HHS Office for Civil Rights submitted its annual reports to Congress on HIPAA compliance and breaches of unsecured protected health information for calendar year 2024, and across 663 large breaches, the protected health information of 242,908,056 individuals was exposed, a figure that dwarfs every previous year on record.
AHS gives behavioral health CEOs a single accountable partner across IT governance, cybersecurity risk management, breach readiness, and HIPAA and Part 2 compliance. That MSO-level control lets founders and clinical leaders concentrate on what they were hired to do: clinical quality, workforce stability, census, and expansion. As OCR escalates enforcement, payers tighten utilization management, and investors demand operational maturity in diligence, operators who cling to the fragmented vendor model will keep paying more (and taking on more risk) than they realize.
Frequently asked questions
Does OCR treat ransomware as a reportable HIPAA breach even if no data was exfiltrated?
Yes. OCR’s long-standing position is that a ransomware incident that encrypts ePHI is presumed to be a breach because PHI availability was compromised under the Security Rule. Operators should assume notification obligations under 45 CFR 164.402 until a written risk-of-compromise analysis says otherwise. The scale of exposure is not theoretical: per the HHS OCR FAQ, on July 31, 2025, Change Healthcare notified OCR that approximately 192.7 million individuals had been impacted by its ransomware event, which outside counsel has called the largest healthcare data breach ever recorded.
What did the 42 CFR Part 2 Final Rule actually change for SUD providers?
Per the HHS fact sheet, the 2024 Final Rule (effective April 16, 2024, with a February 16, 2026 compliance deadline) aligns Part 2 with HIPAA in three material ways: a single patient consent covering future uses and disclosures for treatment, payment, and healthcare operations; application of the HIPAA Breach Notification Rule to Part 2 records; and application of HIPAA civil and criminal enforcement authorities to Part 2 violations. SUD operators had to update Notices of Privacy Practices and consent forms by the February 16, 2026 deadline, and OCR announced its Part 2 Civil Enforcement Program on February 13, 2026 and began accepting complaints on February 16, 2026.
What is OCR’s Risk Analysis Initiative and why does it matter for behavioral health operators?
OCR launched the Risk Analysis Initiative in the fall of 2024. The first enforcement action, announced October 31, 2024, was a $90,000 settlement with Bryan County Ambulance Authority in Oklahoma over a ransomware incident affecting the ePHI of approximately 14,273 patients, paired with a three-year corrective action plan monitored by OCR. Then-Director Melanie Fontes Rainer publicly stated that a risk analysis is flagged in four out of every five OCR enforcement actions. For behavioral health operators with EMRs, telehealth stacks, and multi-site footprints, that means a documented, technology-asset-tied risk analysis is the single most-scrutinized artifact when OCR opens a file.
What controls does the proposed HIPAA Security Rule update require operators to plan for?
OCR’s December 27, 2024 NPRM would remove the distinction between ‘required’ and ‘addressable’ implementation specifications and make all implementation specifications required with limited exceptions. Proposed technical controls include encryption of ePHI at rest and in transit, multi-factor authentication, anti-malware protection, network segmentation, separate controls for backup and recovery, vulnerability scanning at least every six months, penetration testing at least once every 12 months, and patch management, plus a documented technology asset inventory and network map. The rule is proposed, not final, but operators building or scaling should design to it now. Retrofitting after the compliance clock starts is materially more expensive.
References
- HHS OCR. Change Healthcare Cybersecurity Incident FAQ
- HHS OCR Press Release. Bryan County Ambulance Authority $90,000 Settlement (Oct. 31, 2024)
- HHS Fact Sheet. 42 CFR Part 2 Final Rule
- HHS OCR. Civil Enforcement Program for Confidentiality of SUD Patient Records (Feb. 13, 2026)
- HHS OCR. HIPAA Security Rule NPRM Fact Sheet (Dec. 27, 2024)
- Federal Register. HIPAA Security Rule NPRM (published Jan. 6, 2025)
- IBM. 2024 Cost of a Data Breach Report (Newsroom)
- WilmerHale. OCR Risk Analysis Initiative Enforcement Recap