how-to
Texas Medical Records Privacy Act Explained
Table of Contents
- What Is the Texas Medical Records Privacy Act?
- How the Texas Medical Records Privacy Act Relates to HIPAA
- Chapter 181 of the Texas Health and Safety Code: The Legal Foundation
- Covered Entities and Business Associates Under Texas Law
- HB 300 Compliance Requirements for Healthcare Practices
- Patient Data Breach Notification Rules and Your Obligations
- Texas Medical Privacy Law Training and Staff Accountability
- Penalties for Non-Compliance and How to Protect Your Practice
- Frequently Asked Questions
Last Updated: September 22, 2026
What Is the Texas Medical Records Privacy Act?
The Texas medical records privacy law is a state statute that protects how healthcare providers handle patient information. It's separate from federal HIPAA rules but works alongside them.
Texas medical records privacy is governed by Chapter 181 of the Texas Health and Safety Code, which controls who can access patient records, how they're stored, when they can be shared, and penalties for violations.
The law applies to any healthcare provider in Texas, doctors, dentists, therapists, clinics, hospitals, and med spas.
Key points about what is the Texas Medical Records Privacy Act:
- Patients own their medical information
- Providers must get written consent before sharing records
- Records must be stored securely
- Breaches must be reported to patients
- Violations can result in fines and license loss

How the Texas Medical Records Privacy Act Relates to HIPAA
HIPAA is federal law; Texas medical records privacy is state law. HIPAA sets a national floor for health information protection, while Texas law often goes further. If both apply to you, you must follow whichever is stricter.
According to HHS guidance on state privacy laws, states can impose stricter protections than HIPAA as long as they don't conflict with federal rules. Texas does exactly that.
Texas law gives patients more direct control over their own records and imposes penalties for violations. Don't assume HIPAA compliance means you're compliant with Texas law, your practice needs policies for both.
Chapter 181 of the Texas Health and Safety Code: The Legal Foundation
Chapter 181 defines what is the Texas Medical Records Privacy Act and covers who must comply, what records are protected, how records must be used and disclosed, patient rights and access, breach notification requirements, and penalties for violations.
Recent amendments, including HB 300, strengthened protections. Key provisions: patients have the right to inspect and copy their records; providers must respond to access requests within 30 days; disclosure requires written authorization; some disclosures are permitted without authorization (emergency care, law enforcement); records must be kept confidential and secure.
Covered Entities and Business Associates Under Texas Law
A covered entity is any person or organization that maintains health records, physicians, dentists, mental health professionals, clinics, hospitals, med spas, physical therapists, and pharmacies. If you collect, store, or use patient health information, you're a covered entity under Chapter 181.
Business associates are vendors or contractors who handle patient data on your behalf, billing companies, EHR vendors, cloud storage providers, IT contractors, transcription services, and others. You're responsible for their compliance with Texas medical records privacy rules. If they breach patient data, you're liable.
Practical Compliance Checklist for Small Practices
Step 1: Inventory Your Data Flows Document every place patient data is stored (paper files, EHR, email, cloud storage), every person and vendor who touches it, and all third-party integrations.
Step 2: Execute Business Associate Agreements Contact every vendor and request a BAA compliant with Texas Chapter 181. Ensure it includes data security requirements, breach notification timelines (without unreasonable delay), restrictions on use of data, and audit rights. Keep signed copies in a central file.
Step 3: Implement Access Controls Assign role-based access to your EHR, enable multi-factor authentication, set automatic session timeouts (15-30 minutes), create audit trails, and review access logs monthly for unusual patterns.
Step 4: Secure Physical and Electronic Records Encrypt all patient data in transit and at rest. Lock paper files in a cabinet with restricted access. Establish a document destruction policy (shred or incinerate after retention period).
Step 5: Create and Distribute Privacy Notices Draft a privacy notice explaining how your practice uses and discloses patient data. Include types of data collected, purposes of use, patient rights, and how to file a complaint. Post in your waiting room and on your website; give patients a copy at first visit.
Step 6: Develop Authorization and Disclosure Forms Create a standard authorization form including patient name, date of birth, specific records requested, recipient name and address, expiration date, and signature. Respond to requests within 30 days.
Step 7: Train Staff Conduct initial training on Texas privacy law, your policies, protected health information, authorized uses, access requests, breach reporting, and consequences. Document attendance. Conduct annual refresher training.
Step 8: Create a Breach Response Plan Document steps your practice will take if a breach occurs. Assign roles, include notification templates, establish a timeline (without unreasonable delay), and test the plan annually.
Step 9: Conduct a Compliance Audit Review your policies, access controls, and business associate agreements. Spot-check patient records for proper authorization. Review audit logs for unauthorized access. Repeat annually.
Step 10: Maintain Documentation Keep a compliance file with privacy notices, authorization forms, business associate agreements, training records, audit logs, and breach response plan. Assign one staff member to own compliance and review it quarterly.
HB 300 Compliance Requirements for Healthcare Practices
HB 300 strengthened Texas medical records privacy protections with enhanced data security standards, mandatory breach notification timelines, patient notification of data collection practices, restrictions on selling or sharing patient data without consent, and stricter penalties. Compliance focuses on three areas: security, transparency, and patient control.
Patient Data Breach Notification Rules and Your Obligations
A data breach happens when unauthorized people access protected health information. If your practice experiences a breach, you have legal obligations to notify affected patients and regulators.
Provider Obligations for Breach Notification
Texas law requires notification within a specific timeframe. You must notify:
- Affected patients
- The Texas Attorney General (if breach affects 250 or more residents) (Data Breach Reporting)
- Media outlets (in some cases, depending on breach scope)
Notification must include:
-
Description of the breach (what happened, when, how it was discovered)
-
Types of information compromised (names, Social Security numbers, medical diagnoses, etc.)
-
Steps patients should take to protect themselves
-
Your contact information for questions
-
Resources for credit monitoring or identity theft protection
-
Information about the patient's right to file a complaint with the Texas Attorney General
-
How to detect a breach (monitoring systems, staff reports, vendor notifications)
-
Who to notify internally (practice owner, office manager, legal counsel)
-
Documentation procedures (what information to collect about the breach)
-
Legal review before notification (to ensure compliance and accuracy)
-
Patient communication templates (pre-drafted notification letters)
-
Vendor notification procedures (if a third party caused the breach)
-
Credit monitoring or identity theft protection services to offer affected patients
Develop your breach response plan now.
What Patients Should Do If They Receive a Breach Notification
If you receive a breach notification, read it carefully and contact the provider if unclear. Place a fraud alert with the three major credit bureaus (free, one year). Consider a credit freeze if your Social Security number was compromised. Review your credit reports at annualcreditreport.com and report any fraudulent activity to the credit bureau and FTC. Monitor your credit reports regularly and watch for unauthorized charges.
How to Proactively Request Your Medical Records
You don't have to wait for a breach to access your own records. Texas law gives you the right to request copies of your medical records at any time.
Proactive privacy protection:
- Request copies of your records annually and review them for accuracy
- Ask your provider what safeguards they use to protect your data
- Request restrictions on who can access your records (e.g., "Do not share my mental health records with my employer's occupational health clinic")
- Opt out of marketing communications if the provider offers this option
- Ask about your provider's breach response plan and what they will do if your data is compromised
Texas Medical Privacy Law Training and Staff Accountability
Every person in your practice who handles patient data needs training on protected health information, authorized use and disclosure, patient rights, access requests, breach notification, and consequences of violations. Training should happen at hire and annually thereafter. Document all training. Establish clear privacy policies, disciplinary procedures for violations, regular audits of staff access, and incident reporting requirements. An informed staff is your strongest protection.
Penalties for Non-Compliance and How to Protect Your Practice
Violating Texas medical records privacy law carries serious consequences: civil penalties, criminal charges, license suspension or revocation, lawsuits, and reputational damage. For healthcare providers, license loss is the real threat. Protect your practice by implementing strong security measures, training staff, maintaining written policies, conducting regular audits, documenting everything, responding quickly to breaches, and working with legal counsel proactively. Proactive compliance is far cheaper than reactive damage control.
Frequently Asked Questions
How does the Texas Medical Records Privacy Act differ from HIPAA?
The Texas Medical Records Privacy Act provides state-level protections that often exceed federal HIPAA requirements. While HIPAA sets a national floor for Protected Health Information security, the Texas law addresses specific state concerns and applies to some entities HIPAA does not cover. Texas law requires stricter breach notification timelines and includes additional patient access rights. Healthcare providers in Texas must comply with whichever law is more stringent in each area.
What are the specific training requirements under HB 300?
HB 300 requires healthcare entities to implement training programs for employees who access patient records. Staff must understand privacy obligations, proper handling of Protected Health Information, and breach response procedures. Training must occur during onboarding and be refreshed periodically. The law emphasizes that all personnel with record access, from clinical staff to administrative employees, need documented training. Compliance requires maintaining records of who completed training and when.
What should I do if my practice experiences a patient data breach?
Under patient data breach notification rules, you must notify affected individuals without unreasonable delay, typically within 30 days of discovery. Notification must explain what information was compromised, steps patients should take, and what your practice is doing to prevent future breaches. You must also notify the Texas Attorney General if the breach affects more than 250 residents. Document all breach response steps and maintain records for regulatory review. Consider consulting legal counsel immediately to ensure compliance.
Who is considered a covered entity under the Texas Medical Records Privacy Act?
Covered entities include hospitals, clinics, medical practices, mental health providers, dental offices, and any healthcare provider that maintains patient medical records. Business associates, such as billing companies, IT vendors, and medical record storage services, that handle Protected Health Information on behalf of covered entities must also comply. Solo practitioners and small medical spas are covered entities if they maintain and use patient health information in their business operations.