Texas took HIPAA and turned the dial up: House Bill 300 rewrote the Texas Medical Records Privacy Act to cover far more organisations, mandate training on a statutory clock, and back it all with state penalties enforced by the Texas Attorney General.
HB 300 in one paragraph
Passed in 2011 and effective September 2012, HB 300 amended Chapter 181 of the Texas Health and Safety Code — the Texas Medical Records Privacy Act (TMRPA). Its design philosophy is simple: where HIPAA left gaps or generalities, Texas filled them with specifics. The result is a state regime that borrows HIPAA’s definition of protected health information but applies it to a much wider set of organisations, with faster deadlines and its own penalty schedule. If you handle PHI about Texas residents, assume the TMRPA applies to you until you have confirmed otherwise.
The broader “covered entity” definition
This is the headline difference and the one most often missed. Under HIPAA, a covered entity is a healthcare provider that transmits standard transactions, a health plan, or a clearinghouse; everyone else touching PHI is at most a business associate with a narrower set of direct obligations.
Texas defines covered entity to include, in essence, any person who engages in the practice of assembling, collecting, analysing, using, evaluating, storing, or transmitting protected health information — or who comes into possession of it. Read that again: comes into possession of it. Under Texas law, a software vendor, a billing company, a records-storage firm, a lawyer holding medical files, or an accountant with claims data can all be covered entities in their own right, with direct statutory obligations rather than obligations flowing only through a business associate agreement.
The practical upshot: if you are a business associate under federal law and you touch Texas residents’ PHI, you should run your programme as though you were a covered entity, because under state law you are one.
Training: fixed deadlines, kept records
HIPAA requires workforce training but leaves timing to the organisation’s judgement. Texas does not. Under the TMRPA, covered entities must train employees on state and federal law concerning protected health information as it relates to the employee’s role, and the statute fixes the schedule: initial training within roughly 90 days of hire, and refresher training at least once every two years — sooner if material changes in law affect the employee’s duties. Employees must sign a record of completion, and the organisation must retain those records.
This turns training from a policy commitment into a statutory compliance item with dates attached. The operational requirements are the ones any training programme should already have: a roster reconciled against HR records including contractors, role-appropriate content covering both HIPAA and Texas law, signed attestations, and a tickler for the two-year refresh. If your training records cannot show a hire date next to a completion date, you cannot demonstrate the 90-day requirement was met.
The 15-business-day electronic records clock
HIPAA gives you 30 days to fulfil a patient’s access request, with a possible extension. Texas cuts that in half for electronic records: a healthcare provider using an electronic health records system must provide a requested electronic copy of the patient’s record within 15 business days of a written request. There is no doubling up — the shorter clock governs. If your access-request workflow is built to the federal 30-day standard, it needs a Texas lane.
No sale of PHI, and notice requirements
The TMRPA prohibits the sale of protected health information without authorisation, subject to narrow exceptions for treatment, payment, insurance, and certain permitted functions. It also requires notice to individuals when their PHI is subject to electronic disclosure, which most organisations satisfy through posted notices and their Notice of Privacy Practices. Neither requirement is exotic, but both need to appear in your written policies to be demonstrable.
Breach notification in Texas
Breach notification for Texas residents runs under the Texas Identity Theft Enforcement and Protection Act, which requires notice to affected individuals within 60 days of determining a breach occurred. Where a breach affects 250 or more Texas residents, the organisation must also notify the Texas Attorney General — and the AG’s office publishes reported breaches on a public website, so Texas breaches, like California ones, come with publicity attached. Sensitive personal information under the statute expressly includes information about health condition and treatment, so health-data breaches trigger the state regime alongside HIPAA’s.
Your incident response plan should carry both clocks: HIPAA’s individual and HHS deadlines, and the Texas AG notification threshold and deadline.
Penalties and enforcement
The TMRPA carries its own civil penalty schedule, enforced by the Texas Attorney General: as a general matter, up to $5,000 per violation committed negligently, up to $25,000 for knowing or intentional violations, and up to $250,000 per violation where PHI is knowingly used for financial gain — with annual exposure up to $1.5 million where a pattern or practice is found. Licensed professionals face an additional lever: state licensing boards can discipline licence holders for privacy violations, up to and including revocation. The statute directs that in assessing penalties, factors such as the seriousness of the violation, compliance history, and — notably — whether the organisation was trained and acting in good faith are considered, which makes your documented training programme part of your penalty defence.
Running one programme for both regimes
The efficient path is a single programme built on HIPAA’s structure with the Texas deltas made explicit:
- Confirm your entity status under both definitions; if you are Texas-covered but only a federal business associate, upgrade your programme scope accordingly.
- Put the 90-day and two-year training clocks into your HR onboarding workflow, with signed completion records retained.
- Add a 15-business-day lane to your records-access workflow for electronic requests from Texas patients.
- Write the no-sale rule and electronic disclosure notice into your privacy policies.
- Carry the Texas AG breach notification threshold in your incident response runbook.
All of this rides on the same foundation HIPAA already demands — a current risk analysis, written policies, and evidence you can produce on request.
Where SuperHIPAA fits
The platform tracks training completions against hire dates, keeps your policy set versioned and acknowledged, and holds your incident response deadlines in one place — which is exactly the evidence Texas enforcement asks for. Our team helps you map the Texas deltas onto your existing HIPAA programme rather than building a second one.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying the gaps in your HIPAA foundation, which is the same foundation Texas law builds on. If you are further along than you thought, we will tell you that too.