Texas HB 300 Covers Businesses HIPAA Does Not — Here Is the Test
Introduction
If your business touches medical information in Texas, the first question is not whether HIPAA applies. It is whether Chapter 181 of the Texas Health and Safety Code does — and it usually does.
Texas HB 300 expanded Health and Safety Code chapter 181. Covered entities must train employees on state and federal PHI law within 90 days of hire, keep signed training attestations six years, provide electronic health records within 15 business days, obtain authorization before electronic PHI disclosure, and post records-request and complaint instructions. The Texas Attorney General enforces.
Where the two definitions diverge
HIPAA’s definition is closed-ended. Under 45 C.F.R. §160.103, a covered entity is a health plan, a health care clearinghouse, or a provider who transmits health information electronically in a covered transaction. Three buckets. Outside them, HIPAA reaches you only as a business associate, by contract.
Texas went wider. Section 181.001(b)(2)(A) covers any person who, “for commercial, financial, or professional gain, monetary fees, or dues, or on a cooperative, nonprofit, or pro bono basis,” engages with real or constructive knowledge in assembling, collecting, analyzing, using, evaluating, storing, or transmitting protected health information. Its examples include an information or computer management entity, a school, and a person who maintains an Internet site — none with a federal counterpart. Subdivisions (B) through (D) add anyone who comes into possession of PHI, plus employees, agents, and contractors.
One correction worth making: HB 300 did not create this breadth. The enrolled bill amended §181.001(b)(1) and (b)(3) and added (b)(2-a) and (b)(2-b), leaving the (b)(2) covered-entity definition untouched. That language dates to 2001; HB 300 (Acts 2011, 82nd Leg., R.S., Ch. 1126) hung new duties and penalties on a class that already existed, effective September 1, 2012.
What HIPAA already requires vs. what chapter 181 adds
| HIPAA already requires | Texas ch. 181 adds |
|---|---|
| Health plans, clearinghouses, and providers transmitting covered electronic transactions (§160.103); business associates by contract. | Anyone handling PHI for gain, or on a nonprofit or pro bono basis — including information or computer management entities, schools, website operators, and their contractors (§181.001(b)(2)). |
| Train new workforce members “within a reasonable period of time” after they join (§164.530(b)(2)); retain documentation six years (§164.530(j)(2)). | Training on state and federal PHI law by the 90th day after hire (§181.101(a)–(b)), retraining within a year of a material change in law (§181.101(c)), and a signed attestation kept to the sixth anniversary of signature (§181.101(d)). |
| Act on a records access request within 30 days (§164.524(b)(2)). | A provider whose EHR system can fulfill the request must supply it within 15 business days of a written request (§181.102(a)); same §164.524 exceptions. |
| Treatment, payment, and operations disclosures need no separate authorization (§164.506). | Notice that PHI is subject to electronic disclosure, plus separate authorization for each electronic disclosure outside the §181.154(c) purposes. |
| No duty to publish records-request or complaint instructions. | Since September 1, 2025, post on your website and at each facility how to request records, reach your licensing authority, and file a complaint (§181.105(a), added by H.B. 4224). |
| Federal enforcement through the HHS Office for Civil Rights. | Attorney General injunctive relief and civil penalties (§181.201), licensing-agency discipline (§181.202), exclusion from state-funded health care programs on a pattern-or-practice finding (§181.203), HHSC audits (§181.206). |
The four-step applicability test
Step 1: Do you touch PHI at all?
Not “do you bill insurance.” Not “are you a clinic.” The question is whether you assemble, collect, analyze, use, evaluate, store, or transmit protected health information with real or constructive knowledge. Hosting a clinic’s file server counts. So does running a therapy practice’s intake form.
Step 2: For gain — or on a nonprofit or pro bono basis?
This traps people who assume the nonprofit label is a shield. Section 181.001(b)(2)(A) covers gain, fees, and dues and cooperative, nonprofit, or pro bono arrangements. Nearly every organized activity clears it.
Step 3: Does an exemption apply?
The step most summaries omit. Section 181.051, “Partial Exemption,” provides that except for Subchapter D, the chapter does not apply to a covered entity under §602.001 of the Insurance Code, an entity established under Article 5.76-3 of that code, or an employer. Narrower carve-outs follow for financial institutions’ payment processing, nonprofit agencies, workers’ compensation, benefit plans, and the American Red Cross (§§181.052–181.056). Section 181.058 differs: it removes FERPA education records from the PHI definition, so a school can be covered for health data yet outside the chapter for student records.
Step 4: Are you a provider with an EHR system?
If yes, the §181.102 deadline attaches. An IT vendor is not a provider, so that deadline is not yours — nor is the §181.105 posting duty, since §181.105(b) exempts entities doing claims processing, data processing, data analysis, utilization review, or billing for another covered entity serving consumers directly. The §181.101 training and attestation duties still apply.
What the penalties look like
Section 181.201(b) sets three tiers, per violation occurring in one year regardless of how long it continues: up to $5,000 negligent, $25,000 knowing or intentional, $250,000 where the entity knowingly or intentionally used PHI for financial gain. Section 181.201(c) adds up to $1.5 million annually — but only where the court finds a frequency constituting a pattern or practice. Quoting “$1.5 million” as a flat cap skips that condition.
Section 181.201(d) makes the court weigh six factors, including compliance history and efforts to correct the violation — documented remediation is a statutory mitigating factor, not decoration. Under §181.201(e), if a Texas agency licenses you, the attorney general can act only on that agency’s referral.
Section 181.201(b-1) is a real safe harbor. For §181.154 violations, a separate $250,000 annual cap applies where the disclosure went only to another covered entity for a §181.154(c) purpose and one of three things holds: the PHI was encrypted or sent using encryption technology designed to protect against improper disclosure; the recipient did not use or release it; or the entity had developed, implemented, and maintained security policies, including training employees responsible for PHI security. Encryption and documented training are written into Texas law as caps on exposure — ordinary work under a security program.
What to do this quarter
- Write down your covered-entity conclusion. One page: which prong of §181.001(b)(2) reaches you, which exemptions you checked, the date.
- Fix the 90-day clock in onboarding — if your HR checklist still says 60 days, it is running on language replaced in 2013 — and keep the signed attestation six years. Electronic is fine.
- Check your website against §181.105 — unless the §181.105(b) processing exemption covers you.
- Add a material-change trigger to your policy calendar. There is no fixed interval anymore, so somebody has to watch for changes.
This is educational, and the applicability call on your business is one to confirm with your own counsel. The controls underneath it — encryption, access logging, training records, retention — are engineering work we handle for Texas healthcare organizations.
Frequently Asked Questions
Does Texas HB 300 apply to my business if I am not a HIPAA covered entity?
Often, yes. Section 181.001(b)(2)(A) reaches anyone handling protected health information for gain, or on a nonprofit or pro bono basis, and names information or computer management entities, schools, and persons who maintain an Internet site — none of which appear in 45 C.F.R. §160.103. Check the §§181.051–181.060 exemptions first.
How quickly must new employees complete HB 300 training?
No later than the 90th day after hire, under §181.101(b). The often-cited 60-day figure is obsolete: S.B. 1609 replaced it with 90 days, effective June 14, 2013, and swapped the old every-two-years retraining rule for the material-change trigger in §181.101(c).
How long do I have to give a patient their electronic health record?
Fifteen business days under §181.102(a), where a provider uses an EHR system capable of fulfilling the request and receives a written request for the electronic record. Information excepted under 45 C.F.R. §164.524 stays excepted. The federal rule allows 30 days, so Texas is tighter.
Who enforces chapter 181 in Texas?
The Texas Attorney General, who may seek injunctive relief and civil penalties under §181.201(a)–(b). Enforcement is shared: licensing agencies discipline licensed entities under §181.202, §181.203 excludes a covered entity from state-funded health care programs on a judicial pattern-or-practice finding, and §181.206 gives HHSC audit and monitoring authority.
For the full side-by-side, read our guide to Texas HB 300 and the TMRPA versus HIPAA, then run our HIPAA risk assessment tool or talk with us about HIPAA and Texas compliance support. 20+ years of experience, 100% Texas-based support.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.