Your Therapy Notes Are a Ransomware Target. Here's What Small Behavioral Health Practices Need to Know.

August 11, 2026
August 11, 2026
By Melissa Thornton, CISSP | Cybersecurity Advisory Group | cyberadvisor.tech

If you run a small behavioral health practice, a therapy group, or a psychiatric clinic, you may assume that cybercriminals are focused on hospitals and health systems. The reality is the opposite. Ransomware groups specifically seek out small behavioral health practices because of what you hold: psychiatric diagnoses, therapy session notes, substance use history, medication records, and the kind of deeply personal patient data that people will pay anything to keep private.

That leverage is exactly what makes you a target. And in most cases, the practices that get hit had no incident response plan, no written security policies, and no one responsible for security at all.

This post breaks down why behavioral health practices are disproportionately targeted, what OCR enforcement actually looks like for small clinics, and what you should do first if you have no IT staff and limited time.

‍

Why Are Behavioral Health Practices Such High-Value Ransomware Targets?

Ransomware operators are businesspeople. They go where the data is most sensitive and where the defenses are weakest. Behavioral health practices check both boxes.

The data is uniquely sensitive. A patient's therapy notes, psychiatric diagnosis, or history of substance use treatment carries a level of sensitivity that goes far beyond a routine medical record. Patients have lost jobs, custody of children, and professional licenses when this information was exposed without their consent. That sensitivity means patients are more likely to pay a ransom to prevent exposure, and that attorneys are more likely to file class actions when a breach occurs.

The defenses are minimal. Most behavioral health practices operate with one to ten clinicians, no dedicated IT staff, and an EHR system that may or may not be configured correctly. Security is typically handled by whoever has the most patience for technology, which is often no one. There are no written security policies, no documented incident response plan, and frequently no signed Business Associate Agreements with billing vendors or telehealth platforms.

OCR knows this. The Office for Civil Rights has been actively targeting small behavioral health practices in its enforcement actions, and the penalties are real.

What Does OCR Enforcement Actually Look Like for a Small Behavioral Health Clinic?

These are not hypothetical scenarios. These are real practices with real consequences from recent years.

  • Green Ridge Behavioral Health (small Maryland clinic) paid $40,000 and took on a three-year corrective action plan after a ransomware attack, reported in February 2019, exposed the records of more than 14,000 patients. OCR cited its failure to conduct an accurate and thorough risk analysis. Announced February 2024.
  • Rio Hondo Community Mental Health Center, operated by the County of Los Angeles Department of Mental Health, received a $100,000 civil monetary penalty in August 2024. That one was a Right of Access case, not a Security Rule case.
  • Behavioral Health Resources settled a $1.1 million class action in August 2025 after a breach affecting 50,083 patients. Note that this was private litigation, not an OCR action. The regulator is not your only exposure, and in this case the settlement was larger than any of the fines above.
  • Mid-Ohio Psychological Services reported a breach to OCR in November 2024 affecting 40,345 individuals.

A few things stand out across these cases. First, the practices were small. Second, where OCR cited a Security Rule failure, it was the risk analysis. Third, OCR is not the only exposure. One of these was a class action, and it cost more than any of the fines. Fourth, the financial consequences extend well beyond the number in the headline. Corrective action plans run for years, not months, and the legal fees and reputational damage are nearly impossible to quantify.

What Triggers Ransomware Attacks on Behavioral Health Practices?

Understanding how attacks start is the first step toward preventing them. The most common entry points for small behavioral health practices are:

  • Phishing emails sent to staff, often disguised as EHR notifications, insurance messages, or scheduling system alerts
  • Unpatched software, particularly outdated versions of common EHR systems or billing platforms
  • Stolen credentials from staff who reuse passwords across personal and professional accounts
  • Misconfigured remote access, including unsecured Remote Desktop Protocol (RDP) connections set up by an outside IT vendor and never locked down

Once a ransomware group gets in, the goal is twofold: encrypt your files so you cannot operate, and exfiltrate sensitive data so they can threaten to publish it if you do not pay. For behavioral health practices, that second threat is often the more terrifying one.

What Would the Proposed HIPAA Security Rule Mean for Your Practice?

The proposed overhaul of the HIPAA Security Rule is the most significant regulatory shift in over a decade, and most small practices have not heard about it.

It is still a proposal. It was published on January 6, 2025, the comment period closed that March, and the final rule is currently projected for July 2027. That projection has moved before.

What has not moved is the Security Rule that has been in force since 2005, and OCR is enforcing that one now. Here is what the proposal would add:

What the proposal would require What It Means for Your Practice
Encryption of ePHI at rest and in transit You could not store or transmit patient records without encryption. The "addressable" category, which lets you document why a safeguard does not apply, would be eliminated.
MFA for all ePHI access Every system that touches patient data would require multi-factor authentication, with limited exceptions.
Annual compliance audit and annual risk analysis A documented Security Rule compliance audit at least once every 12 months, plus a risk analysis built on a current technology asset inventory and network map.
Annual penetration testing, vulnerability scanning every six months Penetration testing at least once every 12 months, and vulnerability scanning at least every six months.
72-hour restoration of critical systems Written procedures to restore certain critical systems and data within 72 hours of a loss. This is a recovery requirement, not a reporting deadline.

One clarification, because the 72-hour figure gets misread constantly. Breach notification has not changed, and the proposal does not change it. You must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery, and notify HHS contemporaneously with that notice when 500 or more individuals are affected. Breaches affecting fewer than 500 are reported to HHS annually, within 60 days after the end of the calendar year. The clock runs from discovery, not from the incident and not from the day you confirm it.

At the same time, cyber insurance carriers have tightened their underwriting requirements to mirror these new standards. If you cannot demonstrate MFA, endpoint detection and response (EDR), encrypted backups, and a documented incident response plan, you may face denial of coverage or significant premium increases at your next renewal.

Does a Small Therapy Practice Really Need a HIPAA Risk Assessment?

Yes. Full stop.

This is the most common question small practices ask, and the most dangerous misconception in the market. A HIPAA risk assessment is not optional for covered entities, regardless of size.

It is also the document OCR asks for first. The agency runs a dedicated Risk Analysis Initiative, and every settlement announced under it turns on the same failure: the organization could not produce an accurate and thorough risk analysis. Not a missing firewall. Not an unpurchased monitoring tool. The assessment.

A HIPAA risk assessment does not need to be a 200-page enterprise document. For a one-to-five clinician practice, a thorough risk assessment should:

  1. Identify where all electronic protected health information (ePHI) lives: EHR, billing software, email, telehealth platform, and any cloud storage
  2. Assess the likelihood and impact of potential threats to that data
  3. Document what controls are currently in place and where the gaps are
  4. Produce a prioritized remediation plan
  5. Be reviewed on a regular schedule and updated after significant changes, such as a new EHR, a new location, staff turnover, or a security incident

How often? The current Security Rule does not set a fixed schedule. HHS guidance says the risk analysis process should be ongoing and updated as needed. My recommendation is a documented review at least once a year, plus a reassessment whenever something significant changes. The proposed rule described above would make an annual risk analysis a requirement, but it is not final.

The Cybersecurity Advisory Group HIPAA Readiness Assessment for behavioral health practices is designed specifically for small, owner-operated clinics. It is not a checkbox exercise. It results in a documented security program you can show to OCR, your cyber insurer, and your malpractice carrier.

What Should a Behavioral Health Practice Do First? (The No-IT-Staff Starting Point)

If your practice has no IT staff and no security program, here is where to start. These are not the only steps, but they are the ones that reduce the most risk in the shortest time.

Step 1: Know where your patient data lives.
List every system that stores or transmits patient data: your EHR, your billing platform, your telehealth tool, your email, your scheduling software. If it touches a patient record, it is in scope for HIPAA.

Step 2: Check your Business Associate Agreements.
Every vendor on that list needs a signed BAA. Many small practices discover they have been sending patient data through billing companies, telehealth platforms, and even email providers for years without a BAA in place. That is an OCR finding waiting to happen.

Step 3: Turn on multi-factor authentication everywhere.
MFA would be required under the proposed Security Rule. It is already one of the ten Essential HHS Cybersecurity Performance Goals, your cyber insurance carrier is almost certainly asking about it now, and it is one of the single most effective controls against credential theft. Turn it on for your EHR, your email, your billing platform, and anything else on your vendor list.

Step 4: Create a basic incident response plan.
You do not need a 50-page document. You need a written plan that answers three questions: Who do we call when something goes wrong? What do we do to contain it? Who do we notify and by when? Having this documented before an incident is the difference between a manageable situation and a crisis.

Step 5: Conduct a HIPAA risk assessment.
Everything else flows from this. You cannot build a security program without knowing what your risks actually are. If you are not sure where to start, this is the first conversation worth having with a vCISO who specializes in behavioral health practices.

How Does a vCISO Help a Small Behavioral Health Practice?

Most small practices do not need a full-time Chief Information Security Officer. A full-time CISO costs $200,000 or more per year in base salary, and materially more in total compensation. That is not a realistic option for a practice with five therapists and a part-time office manager.

A virtual CISO provides the strategic security leadership your practice needs at a fraction of that cost. For behavioral health practices specifically, that means:

  • Completing and documenting your HIPAA risk assessment, and keeping it current
  • Building your written security policies and procedures from scratch
  • Reviewing and managing your Business Associate Agreements
  • Creating an incident response plan you can actually execute
  • Preparing you for a cyber insurance renewal with documentation your carrier will accept
  • Being the person who picks up the phone when something goes wrong

Healthcare is a core focus for Cybersecurity Advisory Group. Behavioral health practices get a vCISO who understands the sensitivity of your patient population, the specific vulnerabilities of your EHR and billing software, and the requirements of the HIPAA Security Rule.

Frequently Asked Questions

  • Does a 3-person therapy practice need to worry about cybersecurity?
    Yes. Practice size does not reduce regulatory exposure, and the enforcement record shows it. Star Group's breach affected 9,316 people and still resulted in a $245,000 settlement. Top of the World Ranch, an Illinois substance use disorder treatment provider, settled for $103,000 over a breach affecting 1,980 individuals. Green Ridge Behavioral Health, a small Maryland clinic, paid $40,000 and took on a three-year corrective action plan. Smaller practices often carry more exposure, not less, because they have fewer controls in place.
  • What happens if we get hit by ransomware and do not have a security program?
    Beyond the operational impact of losing access to patient records, OCR will investigate. If a risk assessment was never completed, that finding alone can result in significant fines and a corrective action plan. Class action lawsuits from affected patients are increasingly common.
  • How long does it take to get HIPAA-compliant?
    A basic, documented security program for a small behavioral health practice can be built in 30 to 60 days. The goal is not perfection. It is a defensible program that demonstrates you took reasonable steps to protect patient data.
  • What does Cybersecurity Advisory Group charge for behavioral health practices?
    The vCISO retainer is $5,000 per month. For a practice that has never had security leadership, the first 90 days typically include a full HIPAA risk assessment, written policies, BAA review, incident response plan, and cyber insurance readiness documentation.

The Bottom Line

Behavioral health practices hold the most sensitive patient data in healthcare. That is not a reason to panic. It is a reason to take security seriously before a ransomware group, an OCR investigator, or a plaintiff's attorney makes the decision for you.

If you are not sure where your practice stands, start with a conversation. In a free 30-minute session, we will look at your biggest exposure points and what it would take to close them.

Book Your Free 30-Minute Security Clarity Session →

Melissa Thornton, CISSP, C|CISO, is the founder of Cybersecurity Advisory Group and a former CEO who now works as a fractional CISO. She has led security at a healthcare startup and helps small and mid-sized practices build security programs that fit how they operate. Cybersecurity Advisory Group serves mental health clinics, dental offices, home health agencies, and specialty practices nationwide.

Connect with Melissa Thornton on LinkedIn

Updated September 2026 to correct the status of the proposed HIPAA Security Rule, the breach notification timeline, the details of the enforcement actions cited, and the guidance on how often to review a risk assessment.

__wf_reserved_inherit

Related Blogs

September 28, 2026
September 28, 2026

Your Healthcare Practice Has Never Had a HIPAA Risk Assessment. Here Is Where to Start.

Read More
Device inventory graphic illustrating the connected medical device landscape discussed in this article
September 26, 2026
September 26, 2026

When Security Meets Patient Care: How Health Tech Startups, Rural Hospitals, and PE Investors Can Secure Connected Medical Devices

Read More
September 2, 2026
September 2, 2026

$11.5 Million Is the Average. You're Not Average — And That's the Problem.

Read More