Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
The Short Answer: Pick an MSP That Runs Your EHR as Compliance Infrastructure
The right IT managed services provider for a behavioral health treatment center runs your EHR, telehealth platform, and access controls as HIPAA and 42 CFR Part 2 compliance infrastructure, not as hardware. Generalist MSPs do not. That gap now shows up as a measurable dollar figure in OCR settlements, IBM breach data, and payer SIU audit findings.
The federal enforcement numbers make this concrete. In its 2024 breach report to Congress, HHS OCR named the recurring failures behavioral health operators keep tripping on: OCR identified risk analysis, risk management, information system activity review, audit controls, and person or entity authentication as key areas for improvement. Across 663 large breaches, the protected health information of 242,908,056 individuals was exposed, and hacking/IT incidents accounted for 81% of all large breaches.
Layer that against IBM’s finding: the average cost of a healthcare data breach in 2024 sat at $9.77 million, and healthcare held the costliest-industry title for the 14th year in a row. One ransomware event can erase a year of margin for a 40-bed residential program in Florida or a multi-site IOP network in Texas before the survey team even arrives.
At Atlantic Health Strategies our team runs IT for behavioral health operators the way we run their licensure and accreditation files. Same standard. Same audit trail. Same person accountable.
Why Generic MSPs Fail Behavioral Health Operators
Behavioral health clinics sit under two privacy regimes at once. HIPAA governs PHI. 42 CFR Part 2, now administered by OCR after HHS Secretary delegated Part 2 authority to the OCR Director on August 25, 2025, governs substance use disorder records and was overhauled in the February 2024 final rule.
Per the HHS fact sheet and the APA summary of the rule, the rule went into effect on April 16, 2024, with a two-year implementation period, and enforcement for the updated Part 2 rules started on February 16, 2026. The amendments apply the same requirements of the HIPAA Breach Notification Rule to breaches of records under Part 2, meaning a breach of SUD data now triggers notification to affected patients, HHS OCR, and, in some cases, the media on the HIPAA schedule.
The financial exposure jumped too. Prior to the 2024 amendments, Part 2 violations were subject to criminal penalties of $500 for the first offense and $5,000 for subsequent offenses; under the amendments, HIPAA penalties now apply, ranging from $141 to $2.1 million per violation, adjusted annually for inflation.
Most generalist MSPs have never read either rule. Two operational truths your IT provider has to internalize:
- A help-desk ticket about a frozen workstation in your PHP (an outpatient ASAM Level 2.5 setting) is also a documentation-integrity event when clinicians cannot close notes inside the timely-filing window.
- An after-hours login from a former employee is a HIPAA Security Rule audit-control issue and, when the record involved SUD treatment, a Part 2 issue too.
When a payer SIU audit pulls access logs from your EHR and finds a terminated counselor still active 11 days after separation, the CEO owns that finding. Not the MSP.
What OCR Enforcement Tells Operators in Florida, Texas, Georgia, Tennessee, and the Carolinas
OCR is not subtle about where penalties are going. In calendar year 2024, OCR received 30,256 new complaints and carried over 2,955 complaints from previous years. OCR also resolved 12 breach investigations with resolution agreements, corrective action plans, and monetary settlements totaling $7,813,831 during 2024.
One case should focus every operator in Florida, Georgia, Tennessee, or South Carolina. OCR investigated Green Ridge Behavioral Health, a Maryland outpatient mental health group practice, after a 2019 ransomware attack. Per the resolution agreement, GRBH was subject to a ransomware attack that resulted in the acquisition of the protected health information of over 14,000 patients. Green Ridge could not provide evidence of an accurate risk analysis. The settlement: $40,000 paid to HHS with a corrective action plan, monitored by OCR for three years.
OCR Director Melanie Fontes Rainer put it plainly in the agency’s announcement: “Ransomware is growing to be one of the most common cyber-attacks and leaves patients extremely vulnerable”.
The direction of travel is clear. Over the past five years, OCR tracked a 264% increase in large breaches reported involving ransomware, and a 256 percent increase in large breaches involving hacking in the last five years. A treatment center with one IT vendor handling firewalls, a second handling the EHR, and a third handling email is exactly the org chart OCR investigators have been unwinding for years. If your MSP still sells uptime as the primary metric, your MSP is answering a question the regulators stopped asking.
What to Demand From an IT Managed Services Partner
When AHS evaluates an incoming IT environment for a behavioral health client, our team runs the same checklist whether the operator is a single-site detox in Georgia or a five-state MSO platform in Texas. Your provider should give you, in writing:
- A current HIPAA Security Rule risk analysis tied to your actual asset inventory, not a template. OCR and ASTP/ONC jointly publish a Security Risk Assessment Tool for small and medium-sized organizations.
- Documented termination procedures that pull EHR, email, VPN, and badge access on the same ticket, within minutes, with attempted-login alerting after the fact.
- Multi-factor authentication, encryption at rest and in transit, network segmentation, patch management, and a current asset inventory. These map to the proposed HIPAA Security Rule updates published December 27, 2024, which would require encryption of ePHI at rest and in transit, MFA, anti-malware, network segmentation, vulnerability scanning, penetration testing, and patch management. The rule remains proposed, not final.
- A signed Business Associate Agreement that explicitly covers Part 2 records where applicable. The 2024 final rule aligned Part 2 with HIPAA, and enforcement started on February 16, 2026.
- Real coordination with your compliance officer, clinical leadership, and revenue cycle team. Not a quarterly status email.
If your current vendor cannot produce these on request, you do not have an IT problem. You have a governance problem.
How Atlantic Health Strategies Runs IT for Behavioral Health Operators
AHS does not sell IT as a stand-alone box. Our team runs it inside the same operational backbone that handles licensure, accreditation prep, mock surveys, payer readiness, and utilization management for clients across Florida, Texas, Georgia, Tennessee, and the Carolinas. (We do not work in California or New York, and we do not provide ABA or autism services.)
What that integration looks like in practice:
- When clinical leadership terminates a counselor at 3pm, our team pulls EHR access in minutes, deactivates the badge, and preserves the audit trail for the next SIU audit.
- When a payer requests records during a UM dispute, our team has already documented the IT side of records production to the standards your accreditor expects on an EOC tour.
- When OCR’s risk-analysis enforcement initiative pulls your file, your risk analysis is current, the asset inventory matches, and the remediation log lines up with what the surveyor is reading.
That is the relevance test. Not vendor scale. Not generic healthcare experience. Not a glossy SOC 2 report sitting on a shelf. Whether the next surveyor focus, or the next ransomware actor, finds your team ready.
Frequently asked questions
What is the single most common HIPAA finding from OCR investigations, and how does it apply to behavioral health IT?
OCR’s 2024 Annual Report to Congress on breaches identifies risk analysis, risk management, information system activity review, audit controls, and person or entity authentication as the recurring areas for improvement. In calendar year 2024, OCR resolved 12 breach investigations with monetary settlements totaling $7,813,831, and hacking/IT incidents drove 81% of large breaches. Your MSP must produce a current, organization-specific HIPAA Security Rule risk analysis tied to your real asset inventory, EHR, telehealth platform, and BAAs, not a template.
How does the 2024 update to 42 CFR Part 2 change what my IT provider has to do?
The SAMHSA and OCR final rule became effective April 16, 2024, and enforcement for the updated Part 2 rules started on February 16, 2026. It applies the HIPAA Breach Notification Rule to Part 2 records and brings Part 2 violations under the HIPAA enforcement framework, including civil money penalties that range from $141 to $2.1 million per violation, adjusted annually for inflation. If your clinic provides SUD treatment, a breach of unsecured Part 2 records triggers patient notification, HHS notification, and, in some cases, media notification. Your MSP has to detect, scope, and document that incident on those timelines.
How fast should terminated employee access be removed from our EHR?
Within minutes, not the next business day. Behavioral health treatment centers operate 24/7, and OCR investigations routinely cite failures in risk analysis, audit controls, and person or entity authentication as recurring problems. Your MSP should remove EHR, email, VPN, and badge access on a single termination ticket, log the action, and produce attempted-login alerts on demand for the next SIU audit or state survey.
What did the Green Ridge Behavioral Health settlement actually penalize?
OCR’s investigation of Green Ridge, a Maryland outpatient mental health group practice, followed a 2019 ransomware attack that resulted in the acquisition of PHI of more than 14,000 patients. OCR found the provider failed to conduct an accurate and thorough risk analysis, failed to implement sufficient security measures, and failed to sufficiently monitor its information systems’ activity. Green Ridge agreed to pay $40,000 and to a three-year corrective action plan monitored by OCR. For behavioral health operators, this is the enforcement blueprint: no current risk analysis, no defensible position.
References
- HHS OCR, Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2024
- HHS OCR, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2024
- HHS OCR, Green Ridge Behavioral Health, LLC Resolution Agreement and Corrective Action Plan
- HHS, Fact Sheet: 42 CFR Part 2 Final Rule
- HHS, Understanding Confidentiality of Substance Use Disorder (SUD) Patient Records or “Part 2”
- IBM, 2024 Cost of a Data Breach Report Announcement
- HIPAA Journal, Ransomware Attack on Maryland Psychotherapy Provider Results in HIPAA Penalty
- Woods Rogers, Compliance Deadline Approaches for 42 CFR Part 2 Amendments: Enhanced Penalties and Enforcement Process