If you handle PHI in Texas, HIPAA alone may not cover your risk. Texas law often goes further: it can apply to more organizations, require training within 90 days, force EHR access in 15 business days, and add notice to the Texas Attorney General for breaches affecting 250+ Texas residents.

Here’s the short version:

  • HIPAA is the federal floor. Texas can add stricter rules on top.
  • Texas scope is broader. It can reach schools, researchers, IT vendors, website owners, and other groups that handle Texas resident PHI.
  • Texas training rules are tighter. Staff training must be role-based, documented, and refreshed every 2 years.
  • Texas access deadlines are shorter. Some EHR records must be provided within 15 business days, not 30 days.
  • Texas breach response can mean two regulators. A single incident may draw both OCR and the Texas Attorney General.

If I had to sum it up in one line, it’s this: Texas turns a standard HIPAA review into a state-plus-federal review.

HIPAA vs. Texas Medical Privacy Law: Key Differences at a Glance

HIPAA vs. Texas Medical Privacy Law: Key Differences at a Glance

Each of the following are ways that Texas HB 300 expands individual privacy protections beyond HIPAA

HB 300

Quick Comparison

Area HIPAA Texas law
Who it covers Health plans, clearinghouses, providers, business associates A much broader set of people and organizations handling Texas resident PHI
Training Required under HIPAA program rules Role-based training within 90 days; records kept 6 years; refreshers every 2 years
Patient access 30 days, with one 30-day extension 15 business days for certain EHR requests
Marketing use of PHI Limited, with some exceptions Often requires written or electronic permission
Breach notice Notice to individuals and HHS within 60 days May also require notice to the Texas AG for breaches affecting 250+ Texas residents
Enforcement HHS OCR, civil money penalties Texas AG, civil actions, court orders, and possible licensing fallout

For most Texas healthcare groups, the takeaway is simple: check scope first, then build your privacy process to the stricter Texas rule where the two laws differ.

Scope: Who HIPAA Covers vs. Who Texas Law Covers

Scope is the first big line between these two laws. HIPAA applies to a defined group of entities and their vendors. Texas Chapter 181 reaches much farther and can pull in many more people and organizations that touch PHI.

HIPAA Covered Entities and Business Associates

HIPAA applies to health plans, clearinghouses, and providers that transmit health information electronically. It also applies to business associates that create, receive, maintain, or transmit PHI for those entities.

There’s also a key paperwork rule here: covered entities must have a BAA in place before sharing PHI with those vendors.

Texas Covered Entities Under Chapter 181

Texas Chapter 181 uses a much broader definition. It treats a covered entity as any person or organization that, for gain or on a nonprofit or pro bono basis, assembles, collects, analyzes, uses, evaluates, stores, or transmits PHI.

That can include:

That broad reach is exactly why scope needs to be mapped first. If you skip that step, it’s easy to miss a Texas rule that applies even when a team assumes it only needs to check HIPAA.

How Preemption Works When Texas Law Is Stricter

When Chapter 181 is stricter, Texas law controls. HIPAA still acts as the floor.[1][2]

The table below shows where the two frameworks split on scope:

Dimension HIPAA Texas Chapter 181
Entity types Health plans, clearinghouses, healthcare providers, and business associates Any person or organization that assembles, collects, analyzes, uses, evaluates, stores, or transmits PHI - including IT vendors, schools, researchers, law firms, and website owners
Geographic reach Nationwide; applies wherever the covered entity or business associate operates Applies to Texas resident PHI, even outside Texas to prevent data breaches
Nonprofit/pro bono entities Generally not covered unless they meet provider, plan, or clearinghouse definitions Explicitly covered if they handle Texas resident PHI in a structured way

In practice, geography doesn’t box in Chapter 181. If an organization systematically handles Texas resident PHI, it should map that exposure before moving on to HIPAA control checks.

That gap in scope sets up the stricter Texas rules on training, disclosures, access, and breach response.

Requirements: Where Texas Rules Are Stricter Than HIPAA

Texas sets a higher bar than HIPAA in a few key areas. The biggest gaps show up in training, disclosures, marketing, patient access, and breach response.

Training, Disclosures, and Marketing Limits

HB 300 requires role-based HIPAA and Texas PHI training within 90 days of hire. It also requires a signed acknowledgment that the training was completed, and those records must be kept for six years. Refresher training is generally required every two years.

Disclosure rules are tighter too. Under Chapter 181, certain electronic sharing without authorization is limited to treatment, payment, and health care operations (TPO), along with certain insurance- or HMO-related operations. Texas also requires a clear notice that explains how PHI is disclosed electronically.

Marketing is another area where Texas goes further. HIPAA has a few narrow exceptions, but Texas generally requires written or electronic authorization before PHI can be used for marketing. Texas also places broader limits on the sale of PHI than HIPAA.

Patient Access Timelines and Record Delivery

HIPAA gives covered entities up to 30 days to respond to a patient access request, with one 30-day extension.

Texas moves faster. For written requests involving EHRs, records must be provided within 15 business days when electronic access is available.

That shorter timeline can catch teams off guard. If your workflow is built around HIPAA's 30-day window, Texas law leaves a lot less room for delay.

Breach Notification and State-Specific Obligations

HIPAA requires notice to affected individuals and HHS within 60 days of discovery.

Texas can move on a shorter clock, depending on the type of data involved. It also adds a separate state duty: if a breach affects 250 or more Texas residents, the covered entity must notify the Texas Attorney General and include the required details in that notice.

That extra reporting step matters. It's not just about telling patients and HHS. In Texas, a larger breach can also trigger state review, which adds another layer of enforcement risk.

Enforcement: OCR Penalties vs. Texas Attorney General Action

OCR

Enforcement is where these scope and rule differences stop being academic and start becoming a day-to-day risk. In Texas, the same incident can trigger both OCR review and action from the Texas Attorney General.[10]

HIPAA Enforcement and Civil Monetary Penalties

HIPAA enforcement falls under the U.S. Department of Health and Human Services Office for Civil Rights (OCR). OCR investigates complaints, runs compliance reviews, and can issue civil monetary penalties (CMPs) based on how blameworthy the organization was. HIPAA penalties are split into tiers of culpability, starting with no knowledge and going up to uncorrected willful neglect.[17]

Current inflation-adjusted penalty ranges are:[13][14][15][16][18]

Tier Description Min. Per Violation Max. Per Violation Annual Cap
1 No knowledge ~$140–$150 ~$70,000–$73,000 ~$2.1M+
2 Reasonable cause ~$1,400–$1,500 ~$70,000–$73,000 ~$2.1M+
3 Willful neglect, corrected within 30 days ~$14,000–$14,600 ~$70,000–$73,000 ~$2.1M+
4 Willful neglect, not corrected within 30 days ~$70,000+ Varies ~$2.1M+

OCR often settles matters through resolution agreements paired with a corrective action plan, or CAP. In plain English, that usually means the organization doesn't just pay money and move on. A CAP can require enterprise-wide risk analysis, updated policies, staff training, stronger technical safeguards, and continued reporting or monitoring.[12]

In the most serious cases, such as intentional misuse or sale of PHI, OCR can refer the matter to the Department of Justice for criminal prosecution. That can lead to fines and prison time.[11][12]

Texas Penalties, Investigations, and Licensing Risk

Texas adds a second enforcement path on top of OCR. The Texas Attorney General enforces Chapter 181 on its own. The AG can bring civil actions for penalties per violation per day, seek injunctive relief, issue civil investigative demands, and subpoena records and testimony.[10]

That per day piece matters. A problem that sits unresolved for weeks or months can snowball fast, even if each single event looks small on its own.

Texas also looks at factors that can push the stakes higher, including:

  • whether the violation was knowing or intentional
  • whether it affected a large number of Texas residents
  • whether the organization ignored earlier warnings or failed to put required safeguards in place[10]

On the other hand, documented training, a privacy officer, and regular audits and on-demand cyber risk management can help reduce risk.[10]

Texas violations can also spill into licensing trouble. If the facts suggest individual misconduct or broad failures in oversight, the findings may be sent to state licensing boards such as the Texas Medical Board or the Texas Board of Nursing. Those boards have their own power to issue sanctions, from reprimands to license suspension or revocation.[10]

Facility licenses can be affected too. State health departments may weigh serious privacy failures when making renewal decisions.[10] That means privacy controls aren't just a legal checkbox. They can shape whether a person or facility keeps operating.

Those enforcement risks set up the operational priorities covered next.

Operational Impact for Texas Healthcare Organizations

For Texas healthcare organizations, compliance usually means following the stricter rule when state and federal requirements don't match.[19][3][6] In practice, that means adding Texas-specific controls on top of normal HIPAA workflows. If a team leans only on HIPAA definitions, it's easy to miss vendor gaps.

Those differences show up fast in day-to-day work.

Vendor scope review comes first. Texas can treat some nontraditional vendors and even internal units as covered entities. Chapter 181 can reach beyond vendors that sit under a BAA, so your inventory process needs to be broader than HIPAA alone.[8]

Training alignment comes next. Texas requires documented, role-based training soon after hire, plus refresher training every two years.[5][19][3] It’s worth checking that training records cover both federal law and Texas law. If policies or systems change, training should change too.

Record-access workflows also need attention. Build processes around Texas’ 15-business-day deadline for electronic access, not HIPAA’s 30-day window.[5][4]

Incident response is the other big control point. Breach playbooks should include Texas-specific actions, including notice to the Attorney General when a breach affects 250 or more Texas residents.[5][19][3][7][9] A Texas breach can bring both OCR review and Attorney General action. So a single, generic response plan may fall short. Run these steps through tabletop exercises to train incident response teams before there’s a live incident.

Censinet RiskOps™ can help manage third-party risk and keep vendor inventories up to date for Texas and HIPAA response planning. That becomes even more useful when several vendors, systems, and reporting deadlines collide.

FAQs

Does Texas law apply if my organization is not a HIPAA covered entity?

Yes. The Texas Medical Records Privacy Act reaches far beyond HIPAA and can apply to groups that are not HIPAA covered entities.

Here’s the key point: it can apply to any person or business that handles PHI for commercial, financial, or professional reasons. That sweep is much broader than many people expect.

That can include:

  • IT providers
  • Law firms
  • Accounting firms
  • Websites
  • Schools

And it doesn’t stop at the Texas state line. If an individual or organization outside Texas handles or stores Texans’ PHI, the law can still apply.

Which rule should we follow if HIPAA and Texas law conflict?

In general, follow the rule that gives more protection or sets the stricter requirement.

For record retention, if Texas and federal rules don’t match, the usual approach is to keep records for the longer period that applies. HIPAA sets the baseline, but Texas law can add extra duties. That may include things like shorter breach notification deadlines or employee training requirements that you also need to meet.

What should we update first to meet Texas privacy requirements?

First, confirm whether your organization is a covered entity under the Texas Medical Records Privacy Act.

Then review and update policies for consent, patient access to records, data protection, and breach response. At the same time, inventory every system that stores PHI so you can apply whichever rule is stricter under state or federal law.

Related Blog Posts