how-to
Managing Telehealth Data Breach Notifications in Texas
Table of Contents
- When a Telehealth Data Breach Notification Is Required
- Statutory Deadlines for Breach Reporting in Texas
- HIPAA Breach Notification Rule vs. Texas State Law
- How to Use the Texas Attorney General Data Breach Reporting Portal
- What to Include in Patient Notification Letter Templates for Healthcare Breaches
- Post-Breach Remediation Workflow for Covered Entities
- Coordinating Legal Counsel and Cyber-Insurance After a Breach
- Build a Compliant Breach Response Plan
- Frequently Asked Questions
Last Updated: September 6, 2026
When a Texas telehealth practice experiences a security incident, the clock starts immediately. A telehealth data breach is any unauthorized acquisition of unsecured protected health information that compromises its privacy or security, and Texas law imposes obligations that run parallel to federal HIPAA rules. Brewster Law Firm, PLLC guides healthcare providers through these moments with a focus on clear action and regulatory compliance.
Two separate legal frameworks apply at once, and they do not perfectly overlap. Many practice owners assume HIPAA compliance covers everything, but Texas state law adds reporting requirements that can trigger obligations even when the federal rule does not.
When a Telehealth Data Breach Notification Is Required
A notification obligation arises when unsecured protected health information is accessed, acquired, or disclosed without authorization. The key word is "unsecured," meaning the data was not rendered unusable through encryption or another specified method. If encrypted data is compromised and the encryption key remains secure, the breach generally does not trigger notification duties.
Texas law applies to covered entities and their business associates operating in the state. The trigger for state reporting is broader than many realize, extending to any breach of computerized data that includes sensitive personal information, which can overlap with but differ from HIPAA's definition of protected health information.
Telehealth-Specific Technical Breach Scenarios
Video consultation platform vulnerabilities. A telehealth visit over a platform like Zoom for Healthcare or Doxy.me transmits audio and video streams that may contain PHI. A breach occurs when an unauthorized party accesses a recorded session, joins a live consultation without authorization ("Zoom bombing"), or exploits a platform vulnerability to intercept the stream. The determining factor is whether the data was accessible, not whether it was actually viewed or misused.
Remote patient monitoring (RPM) data streams. RPM devices, blood glucose monitors, blood pressure cuffs, cardiac monitors, and wearable sensors, transmit patient data through cloud-based portals. A breach scenario includes a vendor's unsecured API that exposes patient readings, a lost or stolen smartphone used to sync device data, or a compromised clinician account that accessed the RPM dashboard.
Patient portal and messaging system compromises. Many telehealth practices use patient portals for scheduling, refill requests, and secure messaging. A phishing attack on a staff member's portal credentials can expose a broad swath of patient communications, including medication lists and treatment summaries.
Business associate and vendor failures. Telehealth practices rely on a chain of vendors: video platforms, EHR systems, billing services, and cloud storage providers. A breach at any vendor can trigger your notification obligations. The HIPAA Breach Notification Rule holds covered entities responsible for breaches at their business associates, and Texas law similarly requires notification when a vendor's breach exposes patient data (hhs.gov).
The "Reasonably Should Have Known" Standard in a Telehealth Context
The clock starts when the breach is discovered, not when it is confirmed. Discovery occurs on the first day the breach is known or reasonably should have been known, meaning willful ignorance does not pause the deadline. For telehealth practices, this standard has specific implications:
- Vendor breach announcements. If your video platform vendor announces a security incident, you may be deemed to have discovered the breach on the date of the announcement, not on the date you completed your own investigation into whether your patients were affected.
- Unusual access patterns. If your IT team notices unusual login activity on your patient portal but does not investigate for several days, the discovery date may be backdated to when the activity was first visible.
- Lost or stolen devices. If a clinician reports a lost laptop that contains unencrypted patient data, discovery occurs when the loss is reported, not when you confirm the data was accessed.
Practical Assessment Framework
To determine whether a notification obligation exists for a telehealth incident, work through this sequence:
- Was the data unsecured? Was it encrypted with a secure key, or otherwise rendered unusable? If yes, no notification is required.
- Was it PHI or sensitive personal information? Under HIPAA, PHI includes any health information linked to an individual. Under Texas law, sensitive personal information includes an individual's name combined with medical or health insurance information.
- Was there unauthorized access, acquisition, or disclosure? This includes not just external hackers but also internal misuse by employees who accessed records without a job-related purpose.
- Was there a reasonable likelihood of harm? Texas law requires notification when there is a reasonable likelihood of harm to the individual. HIPAA uses a risk assessment framework that considers the nature and extent of the data, the unauthorized person who accessed it, and whether the data was actually viewed.
Document your answers to each question. This documentation becomes the foundation of your compliance record and demonstrates good-faith analysis if a regulator or plaintiff later questions your decision.
For telehealth practices, breaches often originate outside your own network. Building relationships with vendors and understanding their security practices before an incident occurs is the single most effective way to manage the discovery clock when something goes wrong.
Statutory Deadlines for Breach Reporting in Texas
Texas imposes a strict statutory deadline for breach reporting that requires action within 60 days of discovery (texasattorneygeneral.gov). This 60-day window applies to notifications to affected individuals and, in many cases, to the Texas Attorney General, creating a compressed timeline for investigation and remediation.
The clock starts when the breach is discovered, not when it is confirmed. Discovery occurs on the first day the breach is known or reasonably should have been known, meaning willful ignorance does not pause the deadline. For practices serving more than 250 residents, additional federal requirements under the HIPAA Breach Notification Rule require reporting to the Department of Health and Human Services Office for Civil Rights without unreasonable delay and no later than 60 days. A common mistake is waiting for a full forensic investigation to conclude before notifying, which can consume the entire window and leave no time for the notification letters themselves.
HIPAA Breach Notification Rule vs. Texas State Law
The HIPAA Breach Notification Rule and Texas state law operate concurrently, and compliance with one does not satisfy the other. HIPAA requires covered entities to notify affected individuals, the Secretary of Health and Human Services, and in certain cases the media. Texas law, codified in the Business and Commerce Code, adds its own notification duties to the Texas Attorney General for breaches involving sensitive personal information. maintaining HIPAA compliance.
Where the laws diverge, the stricter requirement controls. For a telehealth practice, this means comparing the definitions of a breach, the types of data that trigger notification, and the content required in notification letters under each framework. Texas law, for instance, may require notification for a breach of unencrypted personal information even when the data does not meet HIPAA's definition of protected health information. The practical approach is to assess every security incident against both standards and document the analysis.
How to Use the Texas Attorney General Data Breach Reporting Portal
The Texas Attorney General maintains an online portal for breach reporting, and covered entities must submit notifications through this system. The portal requires specific information about the breach, including the nature of the incident, the number of affected individuals, and the types of data exposed.
Before submitting, confirm whether the breach meets the threshold for state reporting. Texas law requires notification to the Attorney General when a breach affects more than 250 residents of the state. For breaches affecting fewer residents, individual notifications may still be required, but the state-level report may not be. The portal submission should include a description of the breach, the date it occurred, the date it was discovered, and the steps taken to contain and remediate the incident. Keep a copy of every submission and the confirmation received, as this documentation becomes part of your compliance record.
What to Include in Patient Notification Letter Templates for Healthcare Breaches
Patient notification letter templates for healthcare breaches must contain specific elements to satisfy both Texas law and HIPAA. The letter should describe the breach in plain language, including what happened, the date of the incident, and the types of information involved. It must also outline steps the patient can take to protect themselves, such as monitoring credit reports or placing a fraud alert.
A compliant notification letter includes the following components:
- A description of the breach and its timing
- The types of unsecured protected health information involved
- Steps the covered entity is taking to investigate and mitigate the breach
- Steps patients should take to protect against potential harm
- Contact information for the covered entity and, where relevant, the Office for Civil Rights
For telehealth providers, the letter should also address any specific risks related to the compromised data, such as exposed treatment notes or medication histories. The tone should be factual and supportive, avoiding language that shifts blame or minimizes the incident. Sample templates are available from the HHS Office for Civil Rights breach notification guidance, and reviewing those examples before drafting your own letters can prevent costly omissions.
Post-Breach Remediation Workflow for Covered Entities
Once notifications are sent, the work shifts to remediation and prevention. A structured post-breach workflow helps covered entities contain the damage, restore trust, and reduce the risk of repeat incidents. This workflow should begin immediately after discovery and run parallel to the notification process.

The remediation workflow follows five phases:
- Contain the incident by isolating affected systems and revoking compromised credentials
- Preserve evidence for forensic analysis and potential legal proceedings
- Conduct a risk assessment to determine the scope of exposed data and the likelihood of harm
- Notify affected parties and regulators according to the statutory deadlines
- Implement corrective actions, including staff training, updated policies, and enhanced technical safeguards
Throughout this process, document every action taken and every decision made. This documentation demonstrates good-faith compliance to regulators and provides a factual record if litigation arises. For telehealth practices, remediation often includes reviewing access logs for the compromised platform, resetting all user credentials, and evaluating whether the breach originated from a vendor or business associate.
Coordinating Legal Counsel and Cyber-Insurance After a Breach
A data breach is a legal event as much as a technical one, and coordinating legal counsel with your cyber-insurance response is essential from the first hours. Legal counsel should review the breach assessment, advise on notification obligations, and manage communications to protect privilege where possible. Cyber-insurance policies often include breach response coverage, providing access to forensic vendors, notification services, and credit monitoring.
The coordination between counsel and insurers requires care. Insurers may push for specific vendors or timelines that do not align with your legal obligations, and legal counsel should ensure that regulatory deadlines take priority. Review your cyber-insurance policy before a breach occurs to understand what is covered and what steps the policy requires you to take following an incident. Many policies require prompt notice to the insurer as a condition of coverage, so delaying that notice can jeopardize your claim. This is also the moment to assess whether the breach triggers obligations in multiple states, since managing telehealth data breach notifications in Texas may not be the only jurisdiction requiring action if patients reside elsewhere.
Build a Compliant Breach Response Plan
The most effective breach response is the one you prepare before the breach happens. A compliant breach response plan documents your internal escalation procedures, identifies your response team, and pre-drafts notification templates so you are not drafting letters under deadline pressure. The plan should assign specific roles, including who determines whether a breach occurred, who notifies the Texas Attorney General, and who communicates with affected patients.
Your plan should also address the specific risks of telehealth operations, including breaches involving third-party platforms, remote staff devices, and business associates who handle your electronic health records. The plan should be reviewed and tested at least annually, with tabletop exercises that simulate a breach scenario to identify gaps in your workflow. When you work with legal counsel to build this plan, you gain the benefit of proactive guidance rather than reactive crisis management. Brewster Law Firm, PLLC helps Texas healthcare providers construct breach response plans that align with both state and federal requirements, combining healthcare compliance expertise with practical operational advice.
Managing telehealth data breach notifications in Texas requires navigating overlapping state and federal rules under tight deadlines, and the cost of getting it wrong extends beyond fines to patient trust and professional reputation. A proactive legal partner who understands both healthcare compliance and the operational realities of telehealth makes the difference between a chaotic response and a controlled one. Brewster Law Firm, PLLC provides clear, supportive guidance on breach response, regulatory compliance, and the corporate structure that protects your practice. Book a consultation and build the legal foundation your practice deserves.
Frequently Asked Questions
What are the specific notification timelines for data breaches under Texas law?
Texas law requires you to notify affected individuals within 60 days of discovering a breach involving computerized data that includes sensitive personal information. If the breach affects 250 or more Texas residents, you must also report it to the Texas Attorney General through their data breach reporting portal. This 60-day window runs concurrently with HIPAA's 60-day deadline, so you should start your incident response immediately upon discovery to meet both obligations.
Are telehealth providers required to notify the Texas Attorney General of a breach?
Yes. Telehealth providers that are covered entities under HIPAA and handle protected health information must report breaches affecting 250 or more Texas residents to the Texas Attorney General. You submit this notice through the Texas Attorney General data breach reporting portal. The report must include a description of the breach, the number of affected individuals, and the steps you are taking to investigate and mitigate the incident.
What is the difference between HIPAA breach notification and Texas state requirements?
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals, the HHS Secretary, and in some cases the media. Texas law adds a separate state-level requirement: you must notify the Texas Attorney General when a breach affects 250 or more residents. The content requirements and deadlines are similar, but you must file separate reports. Texas also has its own enforcement authority and consumer protection statutes that apply alongside HIPAA.
What information must be included in a patient data breach notification?
Your patient notification letter should describe the breach, the types of information involved, and what you are doing to investigate and mitigate the incident. Include steps patients can take to protect themselves, such as monitoring accounts or placing a fraud alert. Provide contact information for your response team. For Texas Attorney General reporting, you will need additional details about the breach scope and your remediation efforts, so keep thorough incident documentation.