

If you run a small behavioral health practice, a therapy group, or a psychiatric clinic, you may assume that cybercriminals are focused on hospitals and health systems. The reality is the opposite. Ransomware groups specifically seek out small behavioral health practices because of what you hold: psychiatric diagnoses, therapy session notes, substance use history, medication records, and the kind of deeply personal patient data that people will pay anything to keep private.
That leverage is exactly what makes you a target. And in most cases, the practices that get hit had no incident response plan, no written security policies, and no one responsible for security at all.
This post breaks down why behavioral health practices are disproportionately targeted, what OCR enforcement actually looks like for small clinics, and what you should do first if you have no IT staff and limited time.
Ransomware operators are businesspeople. They go where the data is most sensitive and where the defenses are weakest. Behavioral health practices check both boxes.
The data is uniquely sensitive. A patient's therapy notes, psychiatric diagnosis, or history of substance use treatment carries a level of sensitivity that goes far beyond a routine medical record. Patients have lost jobs, custody of children, and professional licenses when this information was exposed without their consent. That sensitivity means patients are more likely to pay a ransom to prevent exposure, and that attorneys are more likely to file class actions when a breach occurs.
The defenses are minimal. Most behavioral health practices operate with one to ten clinicians, no dedicated IT staff, and an EHR system that may or may not be configured correctly. Security is typically handled by whoever has the most patience for technology, which is often no one. There are no written security policies, no documented incident response plan, and frequently no signed Business Associate Agreements with billing vendors or telehealth platforms.
OCR knows this. The Office for Civil Rights has been actively targeting small behavioral health practices in its enforcement actions, and the penalties are real.
These are not hypothetical scenarios. These are real practices with real consequences from recent years.
A few things stand out across these cases. First, the practices were small. Second, where OCR cited a Security Rule failure, it was the risk analysis. Third, OCR is not the only exposure. One of these was a class action, and it cost more than any of the fines. Fourth, the financial consequences extend well beyond the number in the headline. Corrective action plans run for years, not months, and the legal fees and reputational damage are nearly impossible to quantify.
Understanding how attacks start is the first step toward preventing them. The most common entry points for small behavioral health practices are:
Once a ransomware group gets in, the goal is twofold: encrypt your files so you cannot operate, and exfiltrate sensitive data so they can threaten to publish it if you do not pay. For behavioral health practices, that second threat is often the more terrifying one.
The proposed overhaul of the HIPAA Security Rule is the most significant regulatory shift in over a decade, and most small practices have not heard about it.
It is still a proposal. It was published on January 6, 2025, the comment period closed that March, and the final rule is currently projected for July 2027. That projection has moved before.
What has not moved is the Security Rule that has been in force since 2005, and OCR is enforcing that one now. Here is what the proposal would add:
| What the proposal would require | What It Means for Your Practice |
|---|---|
| Encryption of ePHI at rest and in transit | You could not store or transmit patient records without encryption. The "addressable" category, which lets you document why a safeguard does not apply, would be eliminated. |
| MFA for all ePHI access | Every system that touches patient data would require multi-factor authentication, with limited exceptions. |
| Annual compliance audit and annual risk analysis | A documented Security Rule compliance audit at least once every 12 months, plus a risk analysis built on a current technology asset inventory and network map. |
| Annual penetration testing, vulnerability scanning every six months | Penetration testing at least once every 12 months, and vulnerability scanning at least every six months. |
| 72-hour restoration of critical systems | Written procedures to restore certain critical systems and data within 72 hours of a loss. This is a recovery requirement, not a reporting deadline. |
One clarification, because the 72-hour figure gets misread constantly. Breach notification has not changed, and the proposal does not change it. You must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery, and notify HHS contemporaneously with that notice when 500 or more individuals are affected. Breaches affecting fewer than 500 are reported to HHS annually, within 60 days after the end of the calendar year. The clock runs from discovery, not from the incident and not from the day you confirm it.
At the same time, cyber insurance carriers have tightened their underwriting requirements to mirror these new standards. If you cannot demonstrate MFA, endpoint detection and response (EDR), encrypted backups, and a documented incident response plan, you may face denial of coverage or significant premium increases at your next renewal.
Yes. Full stop.
This is the most common question small practices ask, and the most dangerous misconception in the market. A HIPAA risk assessment is not optional for covered entities, regardless of size.
It is also the document OCR asks for first. The agency runs a dedicated Risk Analysis Initiative, and every settlement announced under it turns on the same failure: the organization could not produce an accurate and thorough risk analysis. Not a missing firewall. Not an unpurchased monitoring tool. The assessment.
A HIPAA risk assessment does not need to be a 200-page enterprise document. For a one-to-five clinician practice, a thorough risk assessment should:
How often? The current Security Rule does not set a fixed schedule. HHS guidance says the risk analysis process should be ongoing and updated as needed. My recommendation is a documented review at least once a year, plus a reassessment whenever something significant changes. The proposed rule described above would make an annual risk analysis a requirement, but it is not final.
The Cybersecurity Advisory Group HIPAA Readiness Assessment for behavioral health practices is designed specifically for small, owner-operated clinics. It is not a checkbox exercise. It results in a documented security program you can show to OCR, your cyber insurer, and your malpractice carrier.
If your practice has no IT staff and no security program, here is where to start. These are not the only steps, but they are the ones that reduce the most risk in the shortest time.
Step 1: Know where your patient data lives.
List every system that stores or transmits patient data: your EHR, your billing platform, your telehealth tool, your email, your scheduling software. If it touches a patient record, it is in scope for HIPAA.
Step 2: Check your Business Associate Agreements.
Every vendor on that list needs a signed BAA. Many small practices discover they have been sending patient data through billing companies, telehealth platforms, and even email providers for years without a BAA in place. That is an OCR finding waiting to happen.
Step 3: Turn on multi-factor authentication everywhere.
MFA would be required under the proposed Security Rule. It is already one of the ten Essential HHS Cybersecurity Performance Goals, your cyber insurance carrier is almost certainly asking about it now, and it is one of the single most effective controls against credential theft. Turn it on for your EHR, your email, your billing platform, and anything else on your vendor list.
Step 4: Create a basic incident response plan.
You do not need a 50-page document. You need a written plan that answers three questions: Who do we call when something goes wrong? What do we do to contain it? Who do we notify and by when? Having this documented before an incident is the difference between a manageable situation and a crisis.
Step 5: Conduct a HIPAA risk assessment.
Everything else flows from this. You cannot build a security program without knowing what your risks actually are. If you are not sure where to start, this is the first conversation worth having with a vCISO who specializes in behavioral health practices.
Most small practices do not need a full-time Chief Information Security Officer. A full-time CISO costs $200,000 or more per year in base salary, and materially more in total compensation. That is not a realistic option for a practice with five therapists and a part-time office manager.
A virtual CISO provides the strategic security leadership your practice needs at a fraction of that cost. For behavioral health practices specifically, that means:
Healthcare is a core focus for Cybersecurity Advisory Group. Behavioral health practices get a vCISO who understands the sensitivity of your patient population, the specific vulnerabilities of your EHR and billing software, and the requirements of the HIPAA Security Rule.
Behavioral health practices hold the most sensitive patient data in healthcare. That is not a reason to panic. It is a reason to take security seriously before a ransomware group, an OCR investigator, or a plaintiff's attorney makes the decision for you.
If you are not sure where your practice stands, start with a conversation. In a free 30-minute session, we will look at your biggest exposure points and what it would take to close them.
Book Your Free 30-Minute Security Clarity Session →
Melissa Thornton, CISSP, C|CISO, is the founder of Cybersecurity Advisory Group and a former CEO who now works as a fractional CISO. She has led security at a healthcare startup and helps small and mid-sized practices build security programs that fit how they operate. Cybersecurity Advisory Group serves mental health clinics, dental offices, home health agencies, and specialty practices nationwide.
Connect with Melissa Thornton on LinkedIn
Updated September 2026 to correct the status of the proposed HIPAA Security Rule, the breach notification timeline, the details of the enforcement actions cited, and the guidance on how often to review a risk assessment.



