Operation PAR took a full year from detecting the intrusion to confirming that the files taken contained patient information.
What happened
Operation PAR, Inc., a Pinellas Park, Florida nonprofit that has provided addiction treatment and mental health services since 1970, is notifying 145,714 current and former clients that their personal and health information was exposed. The organization detected unauthorized access to its network on June 10, 2025, and investigators determined that files were accessed or removed between June 6 and June 10. The following June, it was determined that the files held personal and protected health information. Notification letters went out beginning June 25, 2026. Operation PAR filed the required notice with state regulators, where the letter is logged as breach number 2026-1031.
Going deeper
The exposed information covers nearly every category that matters for fraud. Affected files contained first and last names, dates of birth, Social Security numbers, driver's license numbers, financial account information, medical information, and health insurance details. What sets this data breach apart from a hospital or clinic incident is the nature of the underlying service, since a record confirming someone received treatment for a substance use disorder is often deeply personal and individuals may avoid sharing to prevent stigma or discrimination. Disclosure can affect employment, custody proceedings, professional licensing, and insurance, which is why Congress built a separate confidentiality regime for these records decades before HIPAA existed. Operation PAR has not publicly identified who was responsible or described how the intruder got in.
What was said
Federal enforcement of that separate regime is new. "Beginning on February 16, 2026, anyone can file a Part 2 complaint," the HHS Office for Civil Rights states in its guidance on the confidentiality of substance use disorder patient records, the rules known as 42 CFR Part 2. OCR gained authority to administer and enforce Part 2 through a delegation from the HHS Secretary on August 25, 2025, and it now investigates complaints, conducts compliance reviews, and can impose civil money penalties using the same enforcement provisions that apply to HIPAA.
In the know
The year-long gap between detection and confirmation raises a question compliance teams face regularly, which is when the 60-day notification clock actually starts. Under the HIPAA Breach Notification Rule, a breach is treated as discovered on the first day it is known, or reasonably should have been known, to the covered entity, not on the day a forensic review finishes identifying whose records were involved. Regulators have accepted lengthy review periods where the entity can show the work was necessary and diligent, and the OCR has also cited notification delays as violations in its own settlements. Part 2 programs now sit under the same rule, since the 2024 final rule extended HIPAA breach notification requirements to substance use disorder records and required compliance by February 16, 2026. An organization operating under both frameworks answers to one notification standard and two sets of confidentiality obligations.
Ultimately, the 60-day notification can be challenging for many organizations who have to sit through countless files while also ensuring operations can return to normal. There are many cases when extensions have been granted for these reasons, but it is difficult to know if a notice is late because of that or for another, unknown reason.
The big picture
Providers in behavioral health and addiction treatment often run leaner IT operations than hospital systems while holding data that causes more harm when exposed. The population served here includes people whose treatment history could cost them a job or a custody arrangement, and no credit freeze addresses that category of damage. Federal attention to the sector has shifted, with Part 2 moving from a regime that saw almost no enforcement to one where OCR takes complaints and levies penalties. Paubox's report on what healthcare gets wrong about HIPAA and email security describes organizations treating a completed risk assessment as a finished obligation rather than a recurring one, a pattern that leaves gaps of exactly the kind an intruder needed here. Organizations handling Part 2 records should confirm their breach response procedures and name both frameworks, since a plan written only against HIPAA now covers half the exposure.
FAQs
What makes 42 CFR Part 2 stricter than HIPAA?
Part 2 restricts the use of substance use disorder records in civil, criminal, administrative, and legislative proceedings against a patient, a protection HIPAA does not provide. It also historically required specific patient consent for disclosures that HIPAA permits routinely, though the 2024 final rule allows a single consent covering treatment, payment, and healthcare operations.
Which organizations count as Part 2 programs?
Federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral for treatment, which covers most addiction treatment providers, opioid treatment programs, and some general medical facilities with identified SUD units or staff. General practitioners who occasionally treat SUD patients without holding themselves out as specialists usually fall outside the definition.
Do Part 2 records lose their protection once shared with a hospital?
Not entirely. The 2024 rule permits HIPAA covered entities and business associates to redisclose Part 2 records as HIPAA allows, though limits remain, including the restrictions on use in legal proceedings against the patient. Receiving organizations should confirm what obligations travel with the records.
What penalties apply to a Part 2 violation now?
The final rule replaced the previous criminal-only penalty structure with civil money penalties aligned to HIPAA's tiers under Sections 1176 and 1177 of the Social Security Act, alongside retained criminal penalties. Enforcement runs through the HIPAA Enforcement Rule at 45 CFR part 160.
Should a breach involving SUD records be reported differently?
The notification mechanics match HIPAA, including the 60-day deadline and the HHS breach portal. The practical difference sits in the risk assessment, since the reputational and legal harm to individuals is higher, which affects whether an entity can conclude there is a low probability of compromise.
