HIPAA Law Texas: The SB 1188 Data Rule Most Practices Don’t Know They’re Breaking

Texas healthcare practices are operating under three overlapping privacy laws simultaneously. However, most are only tracking one.

Federal HIPAA has been the baseline since 1996. But in Texas, it sits between two additional layers: the Texas Medical Records Privacy Act (TMRPA), amended by HB 300, and Senate Bill 1188 (SB 1188), which took effect September 1, 2025. 

Most practices are familiar with HIPAA. But fewer have reviewed TMRPA. Almost none have verified whether their EHR vendor complies with SB 1188, which since January 1, 2026, requires all Texas patient data to be stored physically inside the U.S.

So if your EHR vendor has not confirmed U.S.-based servers and disaster recovery infrastructure in writing, your practice might be out of compliance. 

This guide covers what each law requires, where the gaps are, and what Houston-area practices need to do now. 

The Three-Layer Texas Privacy Framework You Must Navigate

Texas healthcare privacy requirements do not replace federal HIPAA. They add additional obligations for healthcare practices to follow. 

  1. Federal HIPAA

    Federal HIPAA has served as the foundation for healthcare privacy requirements since 1996. It applies to health plans, healthcare clearinghouses, covered healthcare providers, and business associates that handle patient data. 

    Key HIPAA requirements include:

    • Protecting protected health information (PHI) through administrative, physical, and technical safeguards. 
    • Notify affected individuals of a breach within 60 days. 
    • Granting patients access to their medical records within 30 days of a valid request. 

     

  2. The Texas Medical Records Privacy Act (TMRPA) and HB 300

    House Bill 300 (HB 300) strengthened TMRPA in 2011, making Texas more restrictive than federal HIPAA in several key areas. 

    Some of the biggest differences include:

    • Broader Coverage: TMRPA applies to any individual or a wide range of organizations that collect, store, use, or share protected health information (PHI). It includes some businesses that are not covered by HIPAA, such as IT vendors, billing companies, and accountants. 
    • Faster record access: Certain electronic health record (EHR) requests must be completed within 15 business days, compared to HIPAA’s 30-day deadline.
    • Lower breach reporting threshold: Organizations must notify the Texas Attorney General when a breach affects 250 or more Texas residents, while HIPAA’s federal reporting threshold is 500 individuals.
    • Stricter authorization: TMRPA requires written patient authorization for most PHI disclosures. Under HIPAA, providers can share patient information for treatment and operations without written permission.
    • Stronger penalties: TMRPA allows penalties of up to $250,000 per violation and up to $1.5 million for a pattern of noncompliance.
    • Employee training: Staff must complete HIPAA and TMRPA privacy training within 90 days of hire, and organizations must keep signed training records for six years.

     

  3. SB 1188: the 2025 law most practices haven’t read

    SB 1188 was signed on June 20, 2025. Access control requirements took effect on September 1, 2025. The data localization requirement, U.S. only storage, took effect January 1, 2026.  SB 1188 explicitly extends compliance obligations to EHR vendors, cloud providers, and subcontractors. 

    Here is how three laws can be compared:

    RequirementFederal HIPAATMRPA / HB 300SB 1188 (2025)
    Who it coversProviders, health plans, clearinghouses, BAsAny entity handling Texas PHISame as TMRPA and  vendors/subcontractors
    PHI access deadline30 days15 business days for certain  EHR requestsN/A (EHR-specific)
    Breach report threshold500  affected individuals (federal)250 Texas residentsNo separate threshold 
    Data storage locationNo restrictionNo restrictionPatient data must be stored in the U.S. starting Jan. 1, 2026
    AI use disclosureNot requiredNot requiredPatients must be informed when AI is used in diagnosis or treatment. 
    PenaltiesUp to $1.9M/yearUp to $1.5M/year$5,000–$250,000 per violation

Texas Medical Records Privacy Act vs HIPAA

TMRPA and HIPAA both protect patient health information, but TMRPA is stricter on every front that matters operationally. 

It covers more entities than HIPAA, gives patients faster record access, sets a lower breach reporting threshold, and requires employee training with signed documentation. 

The one difference the comparison table above doesn’t capture: under TMRPA, written patient authorization is required for most PHI disclosures. Under HIPAA, providers can share information for treatment and operations without it. In Texas, the default is locked, not permissive.

What Texas SB 1188 Actually Requires

SB 1188 adds new rules on EHR data storage, vendors, and AI use that practices need to know. 

  1. Data localization

    SB 1188 requires all Texas patient EHR data to be stored physically within the U.S. This applies to your practice and to every third-party vendor, cloud provider, and subcontractor that handles patient records. 

    The rule applies to all records managed by remote employees as well as how they interact with your revenue cycle and EHR systems, whether it’s new patient data or old. Since January 1, 2026, offshore storage of Texas patient data is permitted under limited conditions. The data cannot be stored, cached, copied, or replicated outside the U.S. 

    For example, a virtual medical assistant can access Texas patient data but cannot save it to a local device or system. The data must remain stored inside the U.S. at all times. 

    Inquire with your EHR vendor about where their backups are stored. Where does their disaster recovery data go? If the vendor fails to provide you with clear answers, it can be a risk for compliance. So choose vendors carefully. 

  2. Access controls

    Since September 1, 2025, Texas patient data in EHR systems can only be accessed by the people who need it for their job. These are the roles that specifically involve treatment, payment, or healthcare operations. Practices must implement administrative, physical, or technical safeguards that are consistent with, but not limited to, HIPAA Security Rule requirements.

  3. AI Disclosure

    SB 1188 allows healthcare providers to use AI for diagnostic purposes. But it requires providers to disclose to the patient, in writing, whenever AI is used in their diagnosis or treatment. This is a legal requirement and not a best practice. 

    Make sure you, a healthcare provider, also review all AI-generated records to make sure they meet the same standards as other medical records.

  4. Minor records access

    SB 1188 requires healthcare organizations to give minors’ parents or guardians full access to EHR data. But if there is a restriction under any state or federal law, then this access is prohibited. Minor records access.

  5. Prohibited data fields

    SB 1188 also limits what type of information healthcare practices cannot collect. For example, you cannot collect, store, or share a patient’s credit score or voter registration status.

    This law also prevents EHR systems from being used for voter registration or processing mail-in ballots. If your intake forms or patient portals collect this type of information, you need to review and update them to avoid any inconvenience later.

Note: Because Texas privacy laws change over time, practices should review guidance from the Texas Attorney General, the Texas Health and Human Services Commission, and legal counsel when updating compliance policies.

When Does State Privacy Law Supersede HIPAA?

State privacy law supersedes HIPAA when it provides patients more protection than HIPAA. 

If a state law is stricter, healthcare organizations must follow state law. 

Patient record access: HIPAA allows 30 days to provide the medical record. TMRPA requires 15 business days for certain EHR requests. Follow TMRPA’s deadline. 

Data storage: HIPAA has no storage location requirement. SB 1188 requires patient data in EHR systems to be stored in the United States. Texas practices must follow SB 1188. 

Restricted data fields: HIPAA does not regulate credit scores or voter registration data in health records. SB 1188 prohibits collecting them. Follow SB 1188. 

A good rule is that every health care provider needs to follow Texas law if it provides stronger privacy protections than HIPAA.

This same principle applies across states. See how it plays out in North Carolina’s HIPAA compliance framework

Houston HIPAA Compliance: What Local Practices Need to Know Now

Houston is home to one of the largest healthcare communities in the country, including the Texas Medical Center. Cloud-based EHR systems are standard across hospitals, clinics, and specialty practices. 

For many Houston practices, SB 1188’s data localization rules create new compliance exposure. If your EHR vendor stores patient data outside the United States, even as a part of backup or disaster recovery systems, your practice can face compliance issues. 

If you manage a Houston-area practice, review these three things:

  1. Audit where your EHR vendor stores patient data. Confirm that their primary servers and backup systems are located in the United States.  
  2. Review your responsibilities under TMRPA. If your organization collects, stores, or shares protected health information (PHI), Texas law may apply even if you are not covered by HIPAA alone. 
  3. Update your AI disclosures. If your practice uses AI for the sake of diagnosis and treatment, make sure you inform the patient about it.

 

Taking these steps can minimize compliance risk and prepare your practice to comply with Texas privacy requirements.

SB 1188 and TMRPA Penalties: What Non-Compliance Actually Costs

Beyond financial penalties, Texas regulators have three additional enforcement tools: 

LawTier / TriggerPenaltyEnforcer
TMRPA / HB 300NegligenceUp to $5,000per violation per yearTexas Attorney General
TMRPA / HB 300Knowing violationUp to $25,000/violation/yearTexas Attorney General
TMRPA / HB 300Intentional  violation for financial gainUp to $250,000/violation/yearTexas Attorney General
TMRPA / HB 300Pattern of noncomplianceUp to $1.5M/yearTexas Attorney General
SB 1188Negligent violation$5,000/violationTexas Attorney General and Texas Health and Human Services Commission (HHSC) 
SB 1188Intentional violations or financial gainUp to $250,000 per violationTexas Attorney General, HHSC, and the Texas Medical Board 

In addition to financial penalties, Texas regulators can take other enforcement actions as well:

  • The Texas Medical Board can suspend or revoke a physician’s license after three or more SB 1188 violations.
  • The Texas Health and Human Services Commission (HHSC) can investigate suspected violations and may suspend or revoke certain healthcare licenses or registration. 
  • The Texas Attorney General can seek court orders requiring a practice to stop violating the law and change its operations, in addition to imposing civil penalties.

Stop Assuming HIPAA Alone Covers You in Texas

HIPAA is only a part of the privacy framework Texas healthcare practices must follow. Federal HIPAA, TMRPA, and SB 1188 create three separate and simultaneous compliance obligations.  

SB 1188 has introduced new requirements around EHR data storage, vendors, and AI use. It shows that compliance is no longer limited to your own policies. You also need to make sure your EHR vendors and other service providers meet Texas requirements. 

Check your policies, verify locations where patient data is stored, review your vendor agreements, and make sure your practice complies with both HIPAA and Texas laws. 

This is where many practices get caught. Remote clinical staff, medical scribes, virtual assistants, billing teams, and others access EHR data daily. Under SB 1188, it is not enough that your systems are compliant. People accessing those systems must operate within a compliance framework too. 

Remote Scouts places remote healthcare professionals who are trained from day one. Every team member operates under documented protocols, so your practice is covered in reality. You can talk to us about building a compliant remote healthcare team.

Most Frequently Asked Questions

What are the HIPAA laws in Texas?

Practices in Texas include three overlapping laws: federal HIPAA, the Texas Medical Records Privacy Act (TMRPA, amended by HB 300), and Senate Bill 1188. 

Texas doesn’t have its own HIPAA law. HIPAA is federal legislation that no state can replicate by name. States cannot pass their own HIPAA laws. Instead, Texas passed its own independent state law called the Texas Medical Records Privacy Act (TMRPA), which functions as Texas’s own healthcare privacy law and is stricter than federal HIPAA in several areas. 

SB 1188 requires Texas EHR patient data to be stored in U.S. territory only. It also requires providers to inform patients whenever they use AI for diagnosis or treatment purposes. Additionally, it prohibits EHR systems from collecting or storing patient credit scores or voter registration status. 

State privacy law supersedes HIPAA when it gives patients more protection than HIPAA. In Texas, it means practices must follow TMRPA’s 15-business-day record access deadline and SB 1188’s data storage requirements. They also have to comply with HIPAA. 

TMRPA applies to any individual or organization that assembles, collects, or analyzes protected health information. This includes healthcare organizations, IT vendors, billing companies, and other businesses that handle PHI for Texas residents.

Penalties vary depending on the types of law violated and whether it was violated intentionally or accidentally. Under TMRPA, fines range from $5,000 for negligent violations to $1.5 million for a pattern of noncompliance. Under SB 1188, penalties range from $5,000 to $250,000 per violation. In addition to fines, Texas regulators can investigate violations and, in some cases, suspend or revoke healthcare licenses or registrations.

Yes. SB 1188 applies to EHR vendors, cloud providers, and subcontractors that store or manage patient data for healthcare organizations. If a vendor fails to meet the law’s requirements, like storing Texas patient data outside the USA. It can create compliance risks for healthcare practices as well. 

Houston healthcare practices must follow TMRPA’s 15-business-day record access deadline and 250-person breach notification threshold. Both are stricter than federal HIPAA. The Texas G and HHSC both have jurisdiction to investigate and penalize non-compliant Texas practices independently of federal OCR enforcement. 

Subscribe to Our Newsletter
Receive occasional updates, hiring insights, and practical tips on building reliable remote teams, sent only when it’s useful.

Build Your Expert Remote Team in Less Than 10 Days.
Hiring top-tier talent is simple, fast, and reliable through Remote Scouts. 100% risk-free virtual assistant staffing with top 3% vetted candidates across multiple industries and regions. No more work delays.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Begin Your Risk-Free Hiring Process
Looking for a job? View Our Current Openings.