Skip to content
Compliance

Beyond HIPAA: Texas Laws and the HIPAA Security Rule Update Every Practice Should Know

August 23, 2026

Most practice administrators in Texas think of compliance as one thing: HIPAA. That is understandable. HIPAA is the law that shows up in vendor contracts, insurance questionnaires and OCR enforcement headlines.

It is also incomplete. A Texas practice answers to at least three state statutes that overlap with HIPAA and, in places, reach further or move faster. And HIPAA itself is in the middle of its first significant Security Rule overhaul in roughly two decades.

This article maps the pieces in plain language. One caveat up front: this is an IT provider's summary, not legal advice. Statutes get amended, thresholds change and how a rule applies to your particular entity depends on facts we do not have. Every section below should end with "confirm with counsel," and we will say so where it matters most.

The Texas Medical Records Privacy Act (Chapter 181)

The Texas Medical Records Privacy Act lives in Health and Safety Code Chapter 181. Two things about it matter to a practice.

It covers more entities than HIPAA. HIPAA applies to covered entities and their business associates. Chapter 181 uses a broader definition of "covered entity" that reaches essentially anyone who assembles, collects, stores, uses or transmits protected health information in Texas. Vendors and businesses that would fall outside HIPAA can fall inside Chapter 181.

It has a training requirement. Chapter 181 requires covered entities to train workforce members on state and federal law concerning PHI, with training tailored to the employee's role, provided within a set period after hire and repeated on a schedule, with records kept. HIPAA has a training requirement too, but Texas is more specific about timing and documentation.

The Act also addresses areas such as the sale of PHI, electronic disclosure and marketing use, and it gives the Texas Attorney General enforcement authority separate from OCR.

What this means for IT: your training records need to exist, be dated and be retrievable. Your vendor list needs to include everyone touching PHI, not just those you have a HIPAA BAA with. Confirm the current training intervals and your entity's status under Chapter 181 with counsel.

Texas breach notification (Chapter 521)

Texas breach notification lives in the Identity Theft Enforcement and Protection Act, Business and Commerce Code Chapter 521. It applies to businesses generally, not just healthcare, and it sits on top of the HIPAA Breach Notification Rule.

Key differences from HIPAA in general terms:

  • Shorter timelines. HIPAA gives up to 60 days from discovery to notify affected individuals. Texas sets a shorter clock, and it has been shortened by amendment. Do not assume the HIPAA window is your deadline.
  • Attorney General notice. When a breach affects more than a threshold number of Texas residents, the practice must notify the Texas Attorney General within a specified period, and the AG publishes a list of reported breaches.
  • Broader definition of protected data. Chapter 521 covers "sensitive personal information," which includes identifiers beyond health information, such as Social Security numbers, driver's license numbers and financial account data. A payroll or billing breach can trigger it even where PHI is not involved.

What this means for IT: your incident response plan needs the Texas deadlines written into it, next to the HIPAA ones. It needs the AG's reporting process documented. And your logging and backup need to be good enough to determine what was accessed and how many Texans were affected within days, not weeks. Get the current thresholds and timelines from counsel and update the plan when the statute changes.

The Texas safe-harbor style provision (Chapter 542)

Texas has enacted a safe-harbor style provision, found in Business and Commerce Code Chapter 542, for businesses that maintain a written cybersecurity program aligned to a recognized framework. The general idea: if a business has implemented and maintains a program that reasonably conforms to a recognized standard such as the NIST Cybersecurity Framework, HITRUST, or the HIPAA Security Rule, it may have a defense against certain data breach claims in Texas courts.

The provision has conditions, size-based scaling and limits on what it protects against. Whether it applies to your practice, and what "reasonably conforms" requires in your case, is squarely a question for counsel.

What this means for IT: the direction is clear even if the details are legal. A written, framework-aligned security program is no longer only a HIPAA obligation. It is potentially a litigation defense in Texas. That means the program needs to be documented, not just practiced. Policies, risk analysis, control mapping and evidence of ongoing operation.

The Texas Data Privacy and Security Act

The Texas Data Privacy and Security Act (TDPSA) is a general consumer privacy law. It generally excludes protected health information governed by HIPAA and entities covered by HIPAA, so most clinical operations fall outside it.

Where it can still reach a practice is marketing. Website analytics, advertising pixels, patient acquisition lists, email marketing platforms and appointment-request forms on a marketing site may process personal data that is not PHI. Depending on the practice's size and data volume, TDPSA obligations around notice, consent for sensitive data and consumer rights may apply.

What this means for IT: know what your website and marketing stack collect and where it goes. Tracking technologies on healthcare websites have also drawn attention from OCR and the FTC. Whether TDPSA applies to your marketing is a question for counsel; knowing what data you collect is a question you can answer today.

The proposed HIPAA Security Rule update

HHS published a Notice of Proposed Rulemaking in early 2025 to update the HIPAA Security Rule for the first time since it took effect. The final status is something to check rather than assume, but the direction of the proposal is clear and worth understanding now.

The proposal would make explicit many controls that the current rule leaves to interpretation:

AreaCurrent rule (general)Proposed direction
Multifactor authenticationNot named; access control is requiredMFA required for access to ePHI systems, with limited exceptions
Encryption"Addressable" at rest and in transitRequired at rest and in transit, with limited exceptions
Asset inventoryImplied by risk analysisWritten technology asset inventory, updated regularly
Network mapNot namedWritten map of how ePHI moves through systems
Technical testingEvaluation required, method openAnnual penetration testing and regular vulnerability scanning
RestorationContingency plan requiredAbility to restore critical systems within 72 hours
Risk analysisRequiredMore specific content and frequency requirements
"Addressable" specificationsFlexibility to document alternativesRemoved; specifications become required

The removal of "addressable" is the biggest structural change. Under the current rule, a practice can decide an addressable specification is not reasonable and document an alternative. Under the proposal, that flexibility largely goes away.

For a fuller picture of what the current rule already expects in practice, see our article on what HIPAA-compliant IT actually means.

What to do now, regardless of final rule status

Nothing in the proposed rule is exotic. Every item is already what OCR treats as expected under the current risk analysis standard, what cyber insurers require on their questionnaires, and what a competent IT program does anyway. Waiting for the final text is not a strategy.

  1. Turn on MFA everywhere. Email, EHR, remote access, VPN, admin accounts, cloud file storage. No exceptions for physicians.
  2. Encrypt at rest and in transit. Laptops, workstations, servers, backups, mobile devices, and every connection carrying ePHI.
  3. Build the asset inventory. Every workstation, server, network device, medical device, cloud service and mobile device. Owner, location, OS, ePHI status.
  4. Draw the network map. Where ePHI enters, where it lives, where it flows, and where it leaves. One page is fine. Update it when the network changes.
  5. Test the backups. Restore something real on a schedule and time it. If you cannot show a 72-hour restoration is realistic, fix that. Our backup and disaster recovery page describes what a tested plan looks like.
  6. Schedule annual technical testing. Vulnerability scanning on a regular cadence and a penetration test at least yearly.
  7. Refresh the risk analysis. Make it current, make it specific, and make it cover the devices and vendors you found in step 3. Our guide to the HIPAA security risk assessment explains what a real one contains.
  8. Update the incident response plan. Add Texas deadlines and the AG reporting step next to the HIPAA ones.
  9. Fix training records. Role-based, dated, retained, on the Texas schedule.
  10. Write it down. Policies, procedures, evidence. The Texas safe-harbor provision and OCR both reward documentation.

If you want a structured starting point, our HIPAA IT compliance checklist covers the technical layer.

Where to check status

  • Federal Register for the HIPAA Security Rule NPRM and any final rule.
  • HHS Office for Civil Rights (hhs.gov/ocr) for guidance, enforcement announcements and the rule text.
  • Texas Legislature Online (statutes.capitol.texas.gov) for the current text of Health and Safety Code Chapter 181 and Business and Commerce Code Chapters 521 and 542.
  • Texas Attorney General for breach reporting procedures and the published breach list.
  • Your healthcare counsel for how each of these applies to your entity, your thresholds and your deadlines.

Set a calendar reminder to review all five twice a year. Statutes and rules move; your compliance program should move with them.

Frequently asked questions

Yes. The Texas Medical Records Privacy Act, Health and Safety Code Chapter 181, applies to a broader set of entities than HIPAA and adds requirements such as workforce privacy training. Practices in Texas must comply with both HIPAA and Chapter 181. Confirm how it applies to your entity with counsel.

Texas Business and Commerce Code Chapter 521 sets a shorter clock than HIPAA's 60 days for notifying affected individuals, and requires notice to the Texas Attorney General when the number of affected Texans exceeds a threshold. Get the current deadlines from counsel, since the statute has been amended.

In early 2025 HHS published a proposed rule that would make controls like MFA, encryption, asset inventories, network maps, annual technical testing and 72-hour restoration expectations explicit, and remove the "addressable" flexibility. Check the Federal Register or HHS OCR for its current status.

It generally excludes protected health information governed by HIPAA and entities covered by HIPAA, but data outside that scope, such as website analytics, marketing lists and ad tracking, may be affected. Whether your marketing activity falls in scope is a question for counsel.

Implement the controls the proposed rule describes. MFA, encryption, an asset inventory, a network map, tested backups and annual testing are already what OCR expects under the current rule and what insurers require. Waiting for the final text does not change the direction.

Our regulatory compliance services translate the requirements above into a working technical program: MFA, encryption, inventory, network map, tested backups and the documentation to prove it. We build the IT side; your counsel handles the legal reading, and we are used to working alongside them.

Ready for a straight answer about your IT? Call (972) 776-6366 or contact us.

Get Started

Ready for a straight answer about your IT?

Schedule a 20-minute discovery call. We will tell you what is working, what is not, and what the gaps would cost.