Quick answer
A new healthcare practice in Texas answers to two privacy laws from its first day. Federal HIPAA attaches once you transmit health information electronically in connection with billing, eligibility, or other covered transactions, which for any practice that takes insurance means immediately. Texas House Bill 300, codified in Health and Safety Code Chapter 181, reaches further than the federal law: it covers anyone who comes into possession of protected health information, cash-only practices included. New employees must be trained within 90 days. Electronic records requests must be filled within 15 business days. And before any of that matters, OCR expects a written risk analysis. The agency has brought 14 enforcement actions under its Risk Analysis Initiative as of June 18, 2026, and a missing risk analysis appeared in every 2026 settlement reviewed for this post.
You picked the space, signed the lease, credentialed with payers, and bought an EHR. Privacy compliance is probably the last box on the opening checklist, and most new owners assume it can wait until the practice is busy enough to matter. The 2026 enforcement record says otherwise. This post covers what actually applies to a new Texas practice, in what order, with the deadlines that catch people.
Does HIPAA apply to your new practice on day one?
The federal definition is narrower than most people think. Under 45 CFR 160.103, a health care provider becomes a covered entity when it transmits any health information in electronic form in connection with a transaction covered by the HIPAA rules. Those transactions are the plumbing of insurance billing: claims, eligibility checks, payment and remittance, prior authorization. Submit your first electronic claim and you are a covered entity from that point forward.
A strictly cash-pay practice that never bills electronically can sit outside the federal definition. That is a real category: some direct primary care clinics and cash-based physical therapy practices are built this way on purpose. If that is your model, do not celebrate yet. Texas law was written for you, and we cover it in the next section.
Vendors come under the federal umbrella with you. The same regulation defines a business associate as a person who creates, receives, maintains, or transmits protected health information on your behalf. Your cloud EHR, your billing service, your IT company, and your answering service all likely qualify, and each one needs a signed business associate agreement before it touches patient data. Their breaches become your problem on a fixed schedule: as OCR’s director noted in the March 2026 MMG Fusion settlement announcement, a business associate must notify affected covered entities within 60 calendar days of discovering a breach. We wrote about what happens when a business associate gets you investigated if you want the enforcement detail.
What does Texas HB 300 add on top of HIPAA?
Texas defines “covered entity” so broadly that the federal question almost stops mattering. Health and Safety Code 181.001 covers any person who, for gain or even on a pro bono basis, assembles, collects, analyzes, uses, stores, or transmits protected health information. It separately covers anyone who simply comes into possession of PHI, plus their employees, agents, and contractors. Business associates, payers, researchers, schools, and even a person who maintains an internet site all appear in the definition by name. If your new practice touches Texas patient information in any form, Chapter 181 applies to you, insurance billing or not.
Three of its requirements matter most for a new practice.
The training deadline arrives fast. Under Section 181.101, every employee must complete training on state and federal PHI law within 90 days of hire, scoped to their actual duties. Each employee signs a verification statement, electronically or on paper, and you keep that statement for six years. When a material change in the law affects an employee’s duties, retraining is due within a reasonable period and no later than one year after the change takes effect. For a practice hiring its opening staff, the 90-day clocks all start together, so build training into onboarding rather than treating it as a someday project.
Records move on a state clock, not just the federal one. Section 181.102 gives a practice using a capable electronic health records system 15 business days from a written request to provide the patient’s electronic record. The federal exceptions to access at 45 CFR 164.524 still apply, but the timeline is Texas law, and patients in Houston, Katy, and everywhere else in the state are entitled to rely on it.
The penalty structure has real teeth. Under Section 181.201, the Texas Attorney General can seek civil penalties up to $5,000 per negligent violation per year, $25,000 per knowing or intentional violation, and $250,000 per violation where PHI was used for financial gain. A pattern or practice of violations can draw up to $1.5 million annually. The statute also tells courts what to weigh in setting the amount, including your compliance history and your efforts to correct the problem. Documentation you create now is mitigation evidence later.
Breach duties come from a separate statute and run on two clocks at once. Texas Business and Commerce Code 521.053 requires notice to affected individuals without unreasonable delay and no later than 60 days after you determine a breach occurred. If at least 250 Texas residents are involved, you must also notify the Texas Attorney General through the AG’s electronic form as soon as practicable and no later than 30 days after determination. The AG then posts the breach on a public website listing, updated within 30 days of each report. Your breach becomes a public record your patients and competitors can look up.
What has to be in place before your first patient walks in?
Start with the document OCR asks for first. The Security Rule at 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of the risks and vulnerabilities to the electronic PHI you hold. For a new practice this is genuinely easier than for an established one: your systems are few, your data flows are simple, and nothing has accreted yet. A risk analysis written before opening day maps every place ePHI will live, from the EHR to the practice management system to the email account the front desk uses, and states what could go wrong and what you decided to do about it.
The rest of the opening stack follows from there. HIPAA’s notice requirement at 45 CFR 164.520 means a direct treatment provider must give patients a Notice of Privacy Practices no later than first service delivery, post it prominently where patients can read it, keep copies available, and make a good faith effort to get written acknowledgment. Business associate agreements need signatures before vendors touch PHI, not after go-live. Training needs a calendar slot inside the 90-day window. And the breach plan should name who determines that a breach occurred, who drafts the individual notices inside 60 days, and who files the AG form inside 30.
None of this requires an enterprise compliance department. It requires a written risk analysis, a handful of policies someone actually owns, signed BAAs, training records, and a breach procedure. A solo dentist in Katy can hold all of it in one binder and one shared drive folder.
What does enforcement look like for a practice your size?
The 2026 record answers the question most new owners ask quietly: would OCR really bother with someone as small as us?
In March 2026, OCR settled with MMG Fusion, LLC, a Maryland software company serving as a business associate, after a December 2020 intrusion exposed the PHI of approximately 15 million individuals. The payment was $10,000. OCR said plainly that it considered MMG’s financial condition in reaching the settlement, and it still attached a corrective action plan it will monitor for three years. Being small does not put you below OCR’s attention. It just changes the check size while the monitoring stays.
On April 23, 2026, OCR announced four ransomware settlements in a single day totaling $1,165,000 and affecting more than 427,000 individuals, including a $245,000 settlement with an employer’s self-funded health plan covering 9,316 members. In June, an employer-sponsored plan with 10,023 members settled for $450,000, OCR’s 20th ransomware enforcement action and 14th under the Risk Analysis Initiative. A year earlier, a small New York neurology practice paid $25,000 after ransomware may have exposed 6,800 patient records. These are not health system numbers. They are small entity numbers, and the common finding across all six 2026 settlements reviewed for this post is the same: no accurate and thorough risk analysis.
The pattern for a new Texas practice is encouraging, in a backhanded way. Every recurring enforcement theme points at documents you can create in your first month, before you have any patients at all.
Where to start
If you are opening a practice in Houston, Katy, or anywhere in Texas this year, the order of operations is simple. Get the risk analysis written before opening day. Stand up the Notice of Privacy Practices, the BAAs, and the training calendar the same week. Write the breach procedure while nobody is panicking.
North Privacy Advisors builds HIPAA compliance programs for small and mid-size practices, starting with a HIPAA risk analysis mapped to what OCR actually examines. If you want a local advisor who has read the settlements instead of just the checklists, start with our Houston HIPAA consulting page or book a call before your opening date gets close.
Last Updated: July 24, 2026