Company Details
florida-behavioral-health-association
23
1,458
62133
floridabha.org
0
FLO_1141717
In-progress


Florida Behavioral Health Association Company CyberSecurity Posture
floridabha.orgThe Florida Behavioral Health Association (FBHA) is a statewide trade association that represents over 70 community mental health and substance use treatment providers throughout the entire state. FBHA’s members span from Pensacola to Key West, serve over 604,000+ individuals each year, and provide services in every county in Florida. These community providers primarily serve the uninsured, underinsured, and the Medicaid populations.
Company Details
florida-behavioral-health-association
23
1,458
62133
floridabha.org
0
FLO_1141717
In-progress
Between 550 and 599

FBHA Global Score (TPRM)XXXX

Description: Spindletop Center Hit by Rhysida Ransomware Attack in September 2025 In September 2025, Spindletop Center, a Texas-based behavioral health clinic, disclosed a data breach affecting an undisclosed number of patients. The incident, first detected on September 29, 2025, involved unauthorized access to sensitive information, including names, Social Security numbers, government-issued IDs, diagnoses, and case numbers. The ransomware group Rhysida claimed responsibility for the attack, asserting it stole records of 100,000 individuals and demanding a 15 bitcoin ransom (approximately $1.65 million). Rhysida provided sample documents as proof of the breach, though Spindletop has not verified the group’s claims. The clinic’s investigation, concluded on December 3, 2025, determined that unauthorized access may have occurred as early as September 23, 2025. Spindletop’s breach notification did not mention credit monitoring or identity theft protection for affected individuals. Rhysida, a ransomware-as-a-service (RaaS) operation active since May 2023, has been linked to 100 confirmed attacks (and 156 unconfirmed) since its emergence, compromising nearly 5.5 million records. The group’s average ransom demand is $1.17 million, with healthcare providers being frequent targets. In 2025 alone, Rhysida claimed 17 breaches, including four in the healthcare sector: - Florida Lung, Asthma & Sleep Specialists (May 2025, 10,000 affected, $639,000 ransom) - Cookeville Regional Medical Center (July 2025, 500+ affected, $1.15 million ransom) - MedStar Health (September 2025, $3.1 million ransom) The Spindletop breach is part of a broader surge in ransomware attacks on U.S. healthcare providers. In 2025, 104 confirmed incidents compromised over 8.8 million records, with an average ransom demand of $697,000. Other recent attacks include: - Pulse Urgent Care Center (March 2025, 4,035 affected, $120,000 ransom by Medusa) - Medical Center, LLP (Georgia) (October 2025, claimed by PEAR) - University of Hawaii Cancer Center (August 2025) Ransomware attacks on healthcare facilities disrupt critical systems, forcing providers to cancel appointments, divert patients, or revert to manual record-keeping. The fallout can jeopardize patient safety, privacy, and operational stability. Spindletop Center, headquartered in Beaumont, Texas, operates five locations and serves over 16,000 patients annually, employing more than 500 staff. The clinic offers mental health services, substance use treatment, and support for intellectual and developmental disabilities.


No incidents recorded for Florida Behavioral Health Association in 2026.
No incidents recorded for Florida Behavioral Health Association in 2026.
No incidents recorded for Florida Behavioral Health Association in 2026.
FBHA cyber incidents detection timeline including parent company and subsidiaries

The Florida Behavioral Health Association (FBHA) is a statewide trade association that represents over 70 community mental health and substance use treatment providers throughout the entire state. FBHA’s members span from Pensacola to Key West, serve over 604,000+ individuals each year, and provide services in every county in Florida. These community providers primarily serve the uninsured, underinsured, and the Medicaid populations.


Dementia Care Devon is a public Information website to promote best practice in dementia care in Devon, published by Rose Lodge in Exmouth. It publishes general information about dementia and dementia care services in Devon, and provides guides that help people find and select a suitable residential

Heartland Mental Health (formerly CHARG Resource Center), transforms lives by providing supportive member-centered, culturally responsive mental health, wellness, and recovery services. We envision a community of wellness where members flourish and live their best, self–directed lives. Through outpa

Taylor Life Center is a not-for-profit organization headquartered in Mason, Michigan that offers mental health support to individuals and families who experience mental illness, developmental disabilities, struggle with substance use, or have other emotional issues. Our mission is to empower peopl

Trusty Behavioral Services helps individuals with developmental disabilities access treatment that leads to a life of independence and happiness. We help people achieve independence and happiness through the use of applied behavior analysis. We strive to maintain a team approach by hiring and reta
Rocky Mountain Crisis Partners, a legal trade name of Metro Crisis Services, Inc., is a statewide, 24/7, year-round, community-based system of crisis intervention services from which people experiencing mental health and/or substance abuse crises can be assessed, safely and effectively stabilized, a

Family Service & Guidance Center (FSGC) is dedicated to meeting the unique mental health needs of children and families and providing training opportunities for behavioral health professionals. FSGC was established in 1904 to help Topeka flood victims. As the needs in our community have changed, so

Hello, we’re Neami. We’re big believers in everyone having the opportunity to live a full life. We support people to achieve the wellbeing and mental health outcomes that matter to them. We provide services across Australia for mental health and wellbeing, housing and homelessness, and suicide pr

Capital Crescent Collective (formerly Emily Cook Therapy) is a private practice located in downtown Bethesda, MD that specializes in helping you repair and enrich your relationships-- especially the one you have with yourself. Our diverse and experienced therapists and coaches offer daytime and even

The Spirit of Gheel, Inc. is a private, non-profit residential psychiatric therapeutic community located in Kimberton, Pennsylvania approximately 30 miles west of Philadelphia. Our two residential facilities, Gheel House and Buttonwood Farm, are within walking distance of each other and are located
.png)
In 2023, 725 data breaches were reported to OCR and across those breaches, more than 133 million records were exposed or impermissibly disclosed.
HIPAA updates and changes happen more frequently than many people are aware of because of the nature of the update or their minor impact on...
What are the new HIPAA regulations in 2026? What additional HIPAA compliance requirements will be introduced this year?
Local nonprofit Embarc Collective nurtures 141 member companies that have created over 1200 jobs and $100 million in economic benefits.
Updates from the NGA Membership Team. For more about the programs below and a list of upcoming events please email us at:...
The National Cybersecurity Alliance welcomes you to join peers who are tackling human risk from every angle. Join us and connect, share and Convene.
U.S. healthcare data breaches are down 34.1% month-over-month, and 44.5% fewer individuals had their healthcare data exposed.
Hacking-related data breaches have been announced by Mid Florida Primary Care, Northwest Denture Center in Washington, Forward, The National...
Two mental healthcare providers have recently announced cybersecurity incidents that exposed patient data: Eleos Wellness in Florida and...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Florida Behavioral Health Association is http://www.floridabha.org.
According to Rankiteo, Florida Behavioral Health Association’s AI-generated cybersecurity score is 592, reflecting their Very Poor security posture.
According to Rankiteo, Florida Behavioral Health Association currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Florida Behavioral Health Association has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Florida Behavioral Health Association is not certified under SOC 2 Type 1.
According to Rankiteo, Florida Behavioral Health Association does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Florida Behavioral Health Association is not listed as GDPR compliant.
According to Rankiteo, Florida Behavioral Health Association does not currently maintain PCI DSS compliance.
According to Rankiteo, Florida Behavioral Health Association is not compliant with HIPAA regulations.
According to Rankiteo,Florida Behavioral Health Association is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Florida Behavioral Health Association operates primarily in the Mental Health Care industry.
Florida Behavioral Health Association employs approximately 23 people worldwide.
Florida Behavioral Health Association presently has no subsidiaries across any sectors.
Florida Behavioral Health Association’s official LinkedIn profile has approximately 1,458 followers.
Florida Behavioral Health Association is classified under the NAICS code 62133, which corresponds to Offices of Mental Health Practitioners (except Physicians).
No, Florida Behavioral Health Association does not have a profile on Crunchbase.
Yes, Florida Behavioral Health Association maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/florida-behavioral-health-association.
As of January 22, 2026, Rankiteo reports that Florida Behavioral Health Association has experienced 1 cybersecurity incidents.
Florida Behavioral Health Association has an estimated 5,283 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notice to victims (pdf) submitted to texas attorney general..
Title: Spindletop Center Ransomware and Data Breach
Description: Spindletop Center, a behavioral health clinic in Texas, experienced a ransomware attack in September 2025, resulting in a data breach that compromised sensitive personal information. The ransomware group Rhysida claimed responsibility and demanded a ransom of 15 bitcoin ($1.65 million).
Date Detected: 2025-09-29
Date Resolved: 2025-12-03
Type: Ransomware, Data Breach
Threat Actor: Rhysida
Motivation: Financial gain
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Data Compromised: Names, Social Security numbers, Government-issued ID numbers, Diagnoses, Case numbers
Systems Affected: Systems and servers were inoperable for a limited time
Downtime: Limited time
Operational Impact: System outage, potential disruption to healthcare services
Brand Reputation Impact: Potential negative impact on brand reputation
Identity Theft Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal and health information.

Entity Name: Spindletop Center
Entity Type: Behavioral health clinic
Industry: Healthcare
Location: Beaumont, Texas, USA
Size: 500+ full-time staff, serves 16,000+ patients per year
Customers Affected: 100,000 (claimed by Rhysida, unverified by Spindletop)

Communication Strategy: Notice to victims (PDF) submitted to Texas Attorney General

Type of Data Compromised: Personal and health information
Number of Records Exposed: 100,000 (claimed by Rhysida, unverified)
Sensitivity of Data: High (PII, PHI)
Data Exfiltration: Yes (claimed by Rhysida)
Data Encryption: Yes (ransomware encrypted systems)
Personally Identifiable Information: Names, Social Security numbers, Government-issued ID numbers

Ransom Demanded: 15 bitcoin ($1.65 million)
Ransomware Strain: Rhysida
Data Encryption: Yes
Data Exfiltration: Yes (claimed by Rhysida)

Regulatory Notifications: Submitted to Texas Attorney General

Source: Comparitech

Source: Spindletop Center Notice to Victims (PDF)
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Comparitech, and Source: Spindletop Center Notice to Victims (PDF).

Investigation Status: Concluded
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notice to victims (PDF) submitted to Texas Attorney General.

Customer Advisories: Notice to victims (PDF) submitted to Texas Attorney General
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Notice to victims (PDF) submitted to Texas Attorney General.
Last Ransom Demanded: The amount of the last ransom demanded was 15 bitcoin ($1.65 million).
Last Attacking Group: The attacking group in the last incident was an Rhysida.
Most Recent Incident Detected: The most recent incident detected was on 2025-09-29.
Most Recent Incident Resolved: The most recent incident resolved was on 2025-12-03.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, Government-issued ID numbers, Diagnoses and Case numbers.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Names, Social Security numbers, Government-issued ID numbers, Diagnoses and Case numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 100.0K.
Highest Ransom Demanded: The highest ransom demanded in a ransomware incident was 15 bitcoin ($1.65 million).
Most Recent Source: The most recent source of information about an incident are Spindletop Center Notice to Victims (PDF) and Comparitech.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Concluded.
Most Recent Customer Advisory: The most recent customer advisory issued was an Notice to victims (PDF) submitted to Texas Attorney General.
.png)
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler. Root causeThe commitHash variable, derived from user input via the --commit-hash CLI argument, is interpolated directly into a shell command using template literals (e.g., execSync(`git show -s --format=%B ${commitHash}`)). Shell metacharacters are interpreted by the shell, enabling command execution. ImpactThis vulnerability is generally hard to exploit, as it requires --commit-hash to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the --commit-hash parameter is populated from external, potentially untrusted sources. An attacker could exploit this to: * Run any shell command. * Exfiltrate environment variables. * Compromise the CI runner to install backdoors or modify build artifacts. Credits Disclosed responsibly by kny4hacker. Mitigation * Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. * Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. * Users on Wrangler v2 (EOL) should upgrade to a supported major version.
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.