Guide

HIPAA Compliance in Texas

How Texas HB 300 and the Texas Medical Records Privacy Act extend HIPAA — broader covered entities, faster records access, mandatory training.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Texas took HIPAA and turned the dial up: House Bill 300 rewrote the Texas Medical Records Privacy Act to cover far more organisations, mandate training on a statutory clock, and back it all with state penalties enforced by the Texas Attorney General.

HB 300 in one paragraph

Passed in 2011 and effective September 2012, HB 300 amended Chapter 181 of the Texas Health and Safety Code — the Texas Medical Records Privacy Act (TMRPA). Its design philosophy is simple: where HIPAA left gaps or generalities, Texas filled them with specifics. The result is a state regime that borrows HIPAA’s definition of protected health information but applies it to a much wider set of organisations, with faster deadlines and its own penalty schedule. If you handle PHI about Texas residents, assume the TMRPA applies to you until you have confirmed otherwise.

The broader “covered entity” definition

This is the headline difference and the one most often missed. Under HIPAA, a covered entity is a healthcare provider that transmits standard transactions, a health plan, or a clearinghouse; everyone else touching PHI is at most a business associate with a narrower set of direct obligations.

Texas defines covered entity to include, in essence, any person who engages in the practice of assembling, collecting, analysing, using, evaluating, storing, or transmitting protected health information — or who comes into possession of it. Read that again: comes into possession of it. Under Texas law, a software vendor, a billing company, a records-storage firm, a lawyer holding medical files, or an accountant with claims data can all be covered entities in their own right, with direct statutory obligations rather than obligations flowing only through a business associate agreement.

The practical upshot: if you are a business associate under federal law and you touch Texas residents’ PHI, you should run your programme as though you were a covered entity, because under state law you are one.

Training: fixed deadlines, kept records

HIPAA requires workforce training but leaves timing to the organisation’s judgement. Texas does not. Under the TMRPA, covered entities must train employees on state and federal law concerning protected health information as it relates to the employee’s role, and the statute fixes the schedule: initial training within roughly 90 days of hire, and refresher training at least once every two years — sooner if material changes in law affect the employee’s duties. Employees must sign a record of completion, and the organisation must retain those records.

This turns training from a policy commitment into a statutory compliance item with dates attached. The operational requirements are the ones any training programme should already have: a roster reconciled against HR records including contractors, role-appropriate content covering both HIPAA and Texas law, signed attestations, and a tickler for the two-year refresh. If your training records cannot show a hire date next to a completion date, you cannot demonstrate the 90-day requirement was met.

The 15-business-day electronic records clock

HIPAA gives you 30 days to fulfil a patient’s access request, with a possible extension. Texas cuts that in half for electronic records: a healthcare provider using an electronic health records system must provide a requested electronic copy of the patient’s record within 15 business days of a written request. There is no doubling up — the shorter clock governs. If your access-request workflow is built to the federal 30-day standard, it needs a Texas lane.

No sale of PHI, and notice requirements

The TMRPA prohibits the sale of protected health information without authorisation, subject to narrow exceptions for treatment, payment, insurance, and certain permitted functions. It also requires notice to individuals when their PHI is subject to electronic disclosure, which most organisations satisfy through posted notices and their Notice of Privacy Practices. Neither requirement is exotic, but both need to appear in your written policies to be demonstrable.

Breach notification in Texas

Breach notification for Texas residents runs under the Texas Identity Theft Enforcement and Protection Act, which requires notice to affected individuals within 60 days of determining a breach occurred. Where a breach affects 250 or more Texas residents, the organisation must also notify the Texas Attorney General — and the AG’s office publishes reported breaches on a public website, so Texas breaches, like California ones, come with publicity attached. Sensitive personal information under the statute expressly includes information about health condition and treatment, so health-data breaches trigger the state regime alongside HIPAA’s.

Your incident response plan should carry both clocks: HIPAA’s individual and HHS deadlines, and the Texas AG notification threshold and deadline.

Penalties and enforcement

The TMRPA carries its own civil penalty schedule, enforced by the Texas Attorney General: as a general matter, up to $5,000 per violation committed negligently, up to $25,000 for knowing or intentional violations, and up to $250,000 per violation where PHI is knowingly used for financial gain — with annual exposure up to $1.5 million where a pattern or practice is found. Licensed professionals face an additional lever: state licensing boards can discipline licence holders for privacy violations, up to and including revocation. The statute directs that in assessing penalties, factors such as the seriousness of the violation, compliance history, and — notably — whether the organisation was trained and acting in good faith are considered, which makes your documented training programme part of your penalty defence.

Running one programme for both regimes

The efficient path is a single programme built on HIPAA’s structure with the Texas deltas made explicit:

  • Confirm your entity status under both definitions; if you are Texas-covered but only a federal business associate, upgrade your programme scope accordingly.
  • Put the 90-day and two-year training clocks into your HR onboarding workflow, with signed completion records retained.
  • Add a 15-business-day lane to your records-access workflow for electronic requests from Texas patients.
  • Write the no-sale rule and electronic disclosure notice into your privacy policies.
  • Carry the Texas AG breach notification threshold in your incident response runbook.

All of this rides on the same foundation HIPAA already demands — a current risk analysis, written policies, and evidence you can produce on request.

Where SuperHIPAA fits

The platform tracks training completions against hire dates, keeps your policy set versioned and acknowledged, and holds your incident response deadlines in one place — which is exactly the evidence Texas enforcement asks for. Our team helps you map the Texas deltas onto your existing HIPAA programme rather than building a second one.

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying the gaps in your HIPAA foundation, which is the same foundation Texas law builds on. If you are further along than you thought, we will tell you that too.

Questions

What is Texas HB 300?

A 2011 Texas law, effective 2012, that amended the Texas Medical Records Privacy Act to go beyond HIPAA — expanding who counts as a covered entity, mandating privacy training, tightening electronic records access timelines, and adding state penalties up to $250,000 per violation.

Who is a covered entity under Texas law?

Almost anyone who handles PHI. The Texas definition includes any person or organisation that comes into possession of protected health information, including those who obtain or store it — far broader than HIPAA's providers, plans, and clearinghouses. Many businesses that are merely business associates federally are full covered entities in Texas.

What are the HB 300 training requirements?

Texas covered entities must train employees on state and federal medical privacy law as it relates to their role, within roughly 90 days of hire, with refresher training at least every two years, and keep signed records of completion. HIPAA requires training too, but Texas fixes the deadlines in statute.

How fast must electronic records be provided in Texas?

Healthcare providers using electronic health records must provide a requested electronic copy within 15 business days — half of HIPAA's 30-day standard. Your access-request workflow needs to run to the Texas clock.

What are the penalties for violating the Texas Medical Records Privacy Act?

Civil penalties enforced by the Texas Attorney General can reach $5,000 to $250,000 per violation depending on culpability, and up to $1.5 million annually for a pattern of violations. Licence-holding professionals also face disciplinary action from their licensing boards.

Does HIPAA compliance satisfy HB 300?

It gets you most of the way but not all of it. The Texas-specific deltas — broader entity scope, statutory training deadlines, the 15-business-day records clock, and the ban on selling PHI without authorisation — need explicit coverage in your programme.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo