HIPAA Compliance in Texas: HB 300 & State Privacy Laws
Texas healthcare organizations must comply with federal HIPAA plus state-specific privacy laws that extend protections for medical records. This guide covers the Texas Medical Records Privacy Act (HB 300), identity theft enforcement, and other state requirements beyond HIPAA.
Texas imposes healthcare privacy requirements through the Medical Records Privacy Act (HB 300), identity theft statutes, and the Texas Health & Safety Code. Texas law generally aligns with HIPAA but adds specific procedural requirements: patients have a statutory right to access records within 30 days, providers must comply with stricter breach notification timelines, and the Texas Attorney General can enforce healthcare privacy violations. Additionally, Texas has aggressive identity theft laws (Texas Identity Theft Enforcement Act) that apply to healthcare data breaches involving social security numbers or financial information.
How Texas Law Extends Beyond HIPAA
While Texas law often parallels HIPAA requirements, several areas impose stricter standards or add procedural requirements:
1. Texas Medical Records Privacy Act (HB 300)
Texas Health & Safety Code Chapter 241 (Medical Records Privacy Act) provides:
- Right to access: Patients have statutory right to access medical records within 30 days (faster than HIPAA's 60 days)
- Reasonable fees: Providers may charge reasonable copying/mailing fees but cannot charge unreasonable amounts
- Disclosure restrictions: Written authorization required for most disclosures; limitations on direct marketing and use of records
- Psychotherapy notes: Similar to HIPAA but with specific Texas procedural requirements
2. Texas Identity Theft Enforcement Act (Texas Business & Commerce Code §59.001)
Healthcare data breaches involving identity risk trigger this statute:
- Scope: Applies to disclosure of social security numbers, driver's license numbers, financial account information, and biometric data in healthcare records
- Notification requirement: Without unreasonable delay (stricter than HIPAA's 60 days)
- Law enforcement notification: Must notify law enforcement if breach involves 250+ Texas residents
- Penalties: Civil penalties up to $100,000 plus restitution
3. Texas Health & Safety Code Privacy Provisions
Additional state requirements:
- Genetic testing: Specific protections for genetic information under Texas Health & Safety Code §103.001
- Mental health records: Enhanced protections under Texas Mental Health Code §571
- Substance abuse treatment: Additional confidentiality requirements for federal grantees and 42 CFR Part 2 covered entities
4. Texas Data Breach Notification Law
Texas Business & Commerce Code §59.001 requires notification:
- Notification without unreasonable delay (interpreted as within days)
- Applies to any unencrypted or unsecured personal information disclosure
- Content requirements similar to HIPAA but with stricter timing
Key Texas State Statutes & References
Texas Attorney General Enforcement
Texas actively enforces healthcare privacy laws through the Attorney General's office:
- HIPAA enforcement: Texas Attorney General enforces HIPAA violations in Texas
- Data breach enforcement: Investigates violations of data breach notification law; can pursue civil penalties
- Consumer protection authority: Under Texas Deceptive Trade Practices Act, AG can pursue healthcare organizations for unfair privacy practices
- Recent activity: Texas AG has pursued healthcare providers and health insurers for data breaches, inadequate security, and delayed notifications
Penalty structure: Texas allows civil penalties under the identity theft law (up to $100,000 per violation) plus consumer restitution for actual damages.
Comparison: HIPAA vs. Texas State Requirements
| Area | HIPAA | Texas Law | More Stringent |
|---|---|---|---|
| Patient Access Timeline | 60 days to provide records | 30 days (Medical Records Privacy Act) | Texas |
| Breach Notification | 60 days of discovery | Without unreasonable delay (interpreted as days) | Texas |
| Authorization Requirements | Permissive; allows routine use authorizations | Specific written authorization required | Texas (for some uses) |
| Copying Fees | Reasonable costs of copying/mailing | Reasonable fees explicitly permitted; cannot be excessive | Similar |
| Law Enforcement Notification | Not explicitly required | Required if breach affects 250+ Texas residents | Texas |
| Genetic Information | Covered under PHI | Additional specific protections and consent requirements | Texas |
| Identity Theft Data | PHI protection | Additional identity theft act provisions; separate penalties structure | Texas (higher penalties) |
| Mental Health Records | Covered under HIPAA/psychotherapy notes protections | Enhanced Texas-specific protections and access restrictions | Similar (Texas more specific) |
Texas-Specific Breach Notification Requirements
Notification Timeline
- HIPAA requirement: Within 60 days of discovery
- Texas requirement: "Without unreasonable delay"—interpreted as requiring notification within days of discovery
- Practical impact: Organizations must have rapid incident response procedures to meet Texas's stricter interpretation
Notification Content
Texas law requires notification to include:
- Description of the breach and date of occurrence
- Types of personal information involved
- Actions the company is taking to protect individuals
- Resources available to address potential harm
- Contact information for inquiries
Law Enforcement Notification
- If breach affects 250+ Texas residents, must notify law enforcement
- Notification to Texas Attorney General may also be required in certain circumstances
Identity Theft Specific
If breach involves SSN, driver's license, financial account numbers, or biometric data:
- Must offer credit monitoring services if feasible
- May be subject to higher penalties under identity theft law
- Potential criminal liability if breach results in actual identity theft
Frequently Asked Questions
Yes. Texas's Medical Records Privacy Act and data breach notification law apply to any entity handling medical information of Texas residents, regardless of where the provider is located. If your organization processes health information of Texas residents (whether you're based in Texas or not), you must comply with Texas's 30-day access requirement, breach notification timelines, and other requirements.
If your breach involves social security numbers, driver's licenses, financial account information, or biometric data, the Texas Identity Theft Enforcement Act applies. You must notify without unreasonable delay. Additionally, if 250+ Texas residents are affected, law enforcement notification is required. More importantly, if the breach results in actual identity theft of any Texas resident, you may face criminal liability (Texas Penal Code §39.02) in addition to civil penalties and restitution.
Yes, but the fee must be "reasonable." Texas law explicitly permits copying and mailing fees but requires them to be reasonable and not excessive. Unlike HIPAA, which allows costs-based fees, Texas focuses on the reasonableness standard. Charging $10 per page for copying, for example, would likely be considered unreasonable. Patients can request records within 30 days, and while you can charge a reasonable fee, you cannot deny access due to inability to pay.
Yes. Mental health treatment records are covered under Texas Mental Health Code §571 with specific confidentiality protections. Substance abuse treatment information is governed by federal 42 CFR Part 2 (which Texas incorporates) plus Texas Health & Safety Code §481.131. These statutes require more specific authorization forms than general HIPAA language. For example, blanket authorizations do not comply with 42 CFR Part 2; you must use the specific form required by that regulation. Violations can result in private lawsuits beyond HIPAA penalties.
Ensure Your Texas Healthcare Organization Stays Compliant
Texas's stricter timelines and identity theft laws require robust compliance programs. Get a professional security assessment to identify gaps in HIPAA and Texas-specific compliance.
Get Your Security Assessment