Managed IT services for healthcare Houston TX: HIPAA-compliant IT support from Uprite

HIPAA Security Rule Compliance • Houston, TX

HIPAA Compliant IT Services in Houston

Uprite runs the HIPAA Security Rule program for Houston medical practices: the risk analysis, the risk management plan, and the evidence file OCR asks for first. We can run it alongside the IT team or provider you already have.

Uprite delivers HIPAA compliant IT services in Houston as a documented Security Rule program: an accurate and thorough risk analysis, a written risk management plan, and a maintained evidence file, backed by a 120-day satisfaction guarantee. We support covered entities across Harris County, from Texas Medical Center specialty groups to independent practices in Katy, Sugar Land, and The Woodlands. The program runs whether Uprite manages your whole environment or only the compliance side of it.

Recognized Across Texas for Managed IT, Security and Compliance

What Enforcement Actually Says

OCR Rarely Fines a Houston Practice for Getting Breached

Read the settlements instead of the headlines. A breach opens the file. It is almost never what closes it.

The Office for Civil Rights publishes every resolution agreement it signs. Through July 2026 the agency has closed 21 ransomware enforcement actions, and 14 of those sit inside a program it calls the Risk Analysis Initiative. The name is the finding.

In June 2026 OCR settled with a national retailer’s employee health plan for $450,000 over a 2021 ransomware attack that reached 10,023 people. Neither cited failure was the intrusion. They were failing to conduct an accurate and thorough risk analysis, and failing to implement reasonable and appropriate policies, both worded by OCR as failures that existed prior to the breach incident.

Six weeks later OCR settled with OSF Healthcare System for $552,250. Same lead finding. No accurate and thorough risk analysis of the risks and vulnerabilities to its electronic protected health information.

OCR Director Paula M. Stannard put it plainly in that second announcement: if a regulated entity does not know what threats and vulnerabilities exist to its ePHI, they will often learn the hard way when their systems are hacked.

So the question to ask a prospective IT provider is narrow. Who produces the risk analysis, how often, and what happens to the gaps it finds?

The Deliverables

Three Documents Decide How an OCR Investigation Goes

Security Rule compliance is not a posture. It is a paper trail with dates on it.

Everything in 45 CFR 164.308 through 164.312 eventually resolves into evidence somebody has to hand over. These are the three artifacts that carry the weight.

The Risk Analysis

Required by 164.308(a)(1)(ii)(A). It has to be accurate and thorough, which means it covers everywhere ePHI actually lives: the EHR, the imaging server, the billing clearinghouse, the front desk workstation, the phone that reads the on-call inbox. We map that flow first, then rate each risk by likelihood and by impact on patients, which is the judgment a vulnerability scanner cannot make on your behalf no matter how complete its output looks. A template with your name typed into it is not a risk analysis.

The Risk Management Plan

Required by 164.308(a)(1)(ii)(B). This is the half most practices skip. A risk analysis that lists twenty gaps and stops there reads, to an investigator, as proof you knew. The plan assigns each gap an owner, a control, and a date, and it shows movement quarter over quarter.

The Evidence File

Not named in the rule, and the one that saves you anyway. Training completions. Access reviews. Encryption attestations. Backup restore tests. Signed business associate agreements. Every OCR corrective action plan we have read asks for records like these going back years, not a snapshot from last week. The controls that produce that evidence, and who operates them day to day, are covered on our HIPAA cybersecurity services in Houston page.

Uprite produces all three, keeps them current, and stores them where your practice administrator can reach them without calling us.

Scope of Work

What the HIPAA Compliance Program Covers

Annual Risk Analysis and Quarterly Reassessment

A full 164.308(a)(1)(ii)(A) analysis every year, plus a lighter review each quarter and after any material change: a new EHR module, a new location, a new vendor, a merger. HHS does not set a frequency. Investigations set it retroactively, by asking when yours was last updated and then reading the gap between that date and the date of the incident as a finding in itself.

Business Associate Agreement Chain

We map every vendor that touches ePHI, confirm a signed BAA exists for each, and flag the ones that expired or never existed. Most practices we assess find at least one live vendor with no agreement on file, and in almost every case that vendor has been receiving protected health information for years without anybody noticing the omission. Transcription and IT support are the usual two.

Technical Safeguard Implementation

Encryption at rest and in transit, unique user identification, automatic logoff, audit controls, and multi-factor authentication on everything that reaches ePHI from outside the building. Where a control is addressable rather than required, we document the decision and the reason. Addressable does not mean optional. It means you have to write down why.

Breach Response and OCR Support

A written incident response procedure, tested. If something does happen, we assemble the notification timeline, produce the evidence file, and stay in the room for the investigation. That last part is not standard in an MSP contract. Read yours.

Why Timing Matters

The Investigation Outlives the Incident by Years

This is the part that reframes the purchase.

OSF Healthcare filed its breach report in October 2021. OCR announced the settlement on July 29, 2026. The Spencer Gifts health plan reported in January 2022 and settled on June 18, 2026. Four and a half years. Nearly five.

Think about what that means operationally. The IT provider you had at the time of the incident may not be the one you have when the request for information lands. Whoever configured the backup may have moved on. Your vendor list has turned over twice.

What survives that gap is documentation, and documentation cannot be created backwards. OCR asks for the risk analysis that existed before the attack. Either it was being maintained on a schedule, with dates, or it was not, and no amount of remediation afterward changes which of those is true.

So we treat the compliance file as a standing deliverable with a calendar attached, not a project that closes.

What Clients Say

★★★★★4.957 Google reviews
★★★★★

Hector and Kareem are super helpful! They are always willing to take on my computer problems even if its small. I had my mouse disappear off my screen, it was an user issue but Hector didn't make me feel small or "dumb" for this error. We love uprite!

Starla Lawhon -DyerGoogle review · Houston
★★★★★

I had been having trouble with an IT matter that I didn't think would be fixed but Arvin Ebueng from Upright took his time with me and worked with me until we were able to resolve the issue. The issue was an internal issue with the way the program was written, but Arvin came up with a great work around so that I am now able to do what I need to do at my job. Long story short, he got me access to both things that I need access to simultaneously and daily. Thanks 😊 Arvin, you are much appreciated 👏 💐 🥳.

Sheila SpencerGoogle review · Houston
★★★★★

I'm am not a "tech" person, however the team at Uprite gets me through the technological side of computers and software so that I can function on a daily basis... but the most enduring quality is that they care. Special shoot out to Mary, Sergio, Eufemio, Hector, and Jeff just to name a few... I appreciate each of you and the help you give me.

Evan HurleyGoogle review · Houston
★★★★★

Sergio Rios is a rock star. I spent about 2 hours trying to fix a problem myself, then called him, and in under 3 minutes my issue was resolved. I highly recommend Uprite, and especially Sergio.

Michael DahlenburgGoogle review · Houston
★★★★★

We use this IT Service at Delta Fastener, they are always helpful and prompt with their responses. They solve our computer issues quickly and effectively. A knowledgeable staff is the most important asset to a company - Uprite fills that gap for us by being a partner in business for all of our IT issues. Outsource what you don't know and focus on what is really making you money!

Trey ClarkGoogle review · Houston

The Texas Layer

In Texas, Your Compliance Perimeter Is Wider Than HIPAA’s

Federal HIPAA draws a line. Covered entities on one side, business associates on the other, a signed agreement bridging them.

Texas draws a different line, and it is drawn wider. Chapter 181 of the Texas Health and Safety Code, the statute HB 300 amended, defines a covered entity as any person who assembles, collects, analyzes, uses, evaluates, stores, or transmits protected health information. There is no business associate tier.

Read that against your vendor list. Your billing service, your transcription provider, your cloud backup, and your IT company are covered entities under Texas law in their own right, not contractors standing behind your compliance. So is Uprite.

Two practical consequences follow. HB 300 requires PHI training for workforce members within 90 days of hire, and that clock runs at your vendors too. Section 181.102 gives a patient the right to an electronic health record within 15 business days of a written request, where HIPAA allows 30 calendar days. Houston practices routinely quote the federal number.

We assess against both regimes, because a Texas Attorney General inquiry and an OCR inquiry ask for different things. The statewide version of this is covered on our HIPAA-compliant IT page, and the practical control list lives in our HIPAA IT compliance checklist for Texas practices.

Notification Timing

Three Clocks Start on the Same Bad Morning

A breach at a Houston practice does not trigger one deadline. It triggers several, and they run at different speeds from different starting guns.

HIPAA gives you 60 days from discovery to notify affected individuals. If 500 or more people are involved, HHS and prominent local media get notified inside that same window. Under 500, HHS can wait for the annual filing, and that exception is the one practices most often misread.

Texas Business and Commerce Code Section 521.053 runs on its own schedule. Individual notice is due within 60 days of determining the breach occurred. If 250 or more Texas residents are affected, the Attorney General must be notified, and Senate Bill 768 cut that window to 30 days.

So a 400-patient breach at a Houston clinic can sit below the HHS media threshold and still owe the Texas Attorney General a filing in half the federal time, which then appears on the AG’s public breach listing.

Nobody works this out correctly under pressure at 9pm. It belongs in a written procedure, decided in advance. If you also fall under Texas SB 2610, our breakdown of HIPAA versus Texas SB 2610 explains how the safe harbour interacts with these deadlines.

HIPAA and Texas breach notification deadlines for a Houston medical practice

Straight Answer

The 2026 Security Rule Overhaul Is Not Law Yet

HIPAA compliant IT services are the technical and administrative work a covered entity needs to satisfy the HIPAA Security Rule: a documented risk analysis under 164.308(a)(1)(ii)(A), a risk management plan under 164.308(a)(1)(ii)(B), implemented administrative, physical and technical safeguards, signed business associate agreements with every vendor that touches ePHI, workforce training, and retained evidence that all of it happened on dates you can prove.

You have been getting emails about it. Here is where it actually stands.

HHS published the proposed Security Rule overhaul in the Federal Register on January 6, 2025. The comment period closed on March 7, 2025 with roughly 4,745 comments filed. As of August 2026, OCR is still working through them. The Office of Management and Budget’s regulatory agenda now shows a final rule in July 2027.

  • Already required today: a risk analysis that is accurate and thorough, and updated when the environment changes
  • Already required today: a risk management plan that acts on what the analysis found
  • Already required today: business associate agreements with every vendor handling ePHI
  • Addressable today, proposed as mandatory: encryption of ePHI at rest and in transit
  • Not currently named, proposed as mandatory: multi-factor authentication on ePHI access
  • Proposed: a maintained technology asset inventory and network map on a fixed cycle
  • Proposed: removal of the addressable category, making the full control set required

So the headline items, mandatory encryption, mandatory multi-factor authentication, removal of the addressable category, and asset inventories on a fixed cycle, are proposals. They are not enforceable. No compliance deadline exists for them.

What is enforceable is the Security Rule as written in 2003, and OCR settled two cases on it in the last three months. We build toward the proposal where it costs nothing extra, because encryption and MFA are good ideas regardless. We do not sell a deadline that has not been set.

When It Happens

What Actually Happens When OCR Opens a File

It starts quietly. A letter, not a raid.

OCR sends a data request. It typically asks for your risk analysis, your risk management plan, your policies and procedures with version dates, your training records, and your business associate agreements. You get weeks, not months.

The practices that come through this well are not the ones with the best security. They are the ones who can answer in the first response, from files that already existed, without a scramble.

We assemble that package, walk your leadership through what it shows before anything goes out, and stay engaged for the duration rather than handing you a folder and disappearing. We also tell you honestly what it shows, including the gaps, because a response that overstates the record is a far worse problem than one that documents a gap and the plan that was closing it.

If your current IT contract does not say who does this work, it is worth reading before you need to know.

Scope Check

Compliance Program, Full Managed IT, or Both

HIPAA Compliance Program (this page)Uprite MED℠ Managed IT Instead
You have IT you are happy with, in house or outsourced, and need the Security Rule work done properlyYou want one provider accountable for the help desk, the EHR, the network, and compliance together
You need a risk analysis, a risk management plan, and an evidence file that survives an investigationYou are losing clinical hours to tickets, downtime, and slow response
You failed or barely passed a compliance review and need remediation with dates attachedYou are replacing an IT provider entirely
You are a covered entity under Texas Chapter 181 and unsure what that adds to your obligationsYou are opening a second or third Houston location and need the build standardized
A payer, hospital system, or acquirer has asked to see your security documentationYou want 24/7 help desk and onsite support across Harris County

These are two different purchases and they get confused constantly. This page is about the first one. If you want Uprite running the help desk, the EHR support, and the infrastructure as well, that is our Houston healthcare managed IT program, and it is the better fit.

Co-Managed by Design

This Works Alongside the IT You Already Have

Most compliance engagements fail on politics, not technique.

A practice hires a compliance firm, the firm writes findings, the incumbent IT provider reads them as an audit of their work, and remediation stalls in a standoff nobody wants to escalate. We have walked into that room more than once.

So we scope it explicitly. Uprite owns the risk analysis, the risk management plan, the evidence file, and the BAA chain. Your existing team or provider owns implementation on the systems they already run, on dates agreed together. Where they would rather we do that work, we do, and the split is written down.

The practice administrator ends up with one document saying who is responsible for what. That is usually the first time it has existed in writing.

How It Runs

How the Engagement Actually Runs

Week 1: ePHI Discovery

We map where protected health information enters, moves, rests, and leaves. Systems, vendors, devices, and the workarounds staff quietly built because the official process was too slow to survive a full clinic day, which is the category where the real findings almost always sit.

Weeks 2 to 4: Risk Analysis

A full 164.308(a)(1)(ii)(A) analysis against both HIPAA and Texas Chapter 181, rated by likelihood and impact, written the way an investigator reads it rather than the way a scanner exports it.

Week 5: Risk Management Plan

Every finding gets an owner, a control, a target date, and a cost. You approve the sequence. Nothing on that plan becomes a surprise line item later.

Ongoing: Evidence and Reassessment

Quarterly review, annual full reassessment, training tracked against the 90-day HB 300 clock, BAAs monitored for expiry, and a file you can hand to a payer, an acquirer, or OCR without preparing it first.

Numbers That Matter

Numbers That Matter

21

Ransomware enforcement actions OCR has closed through July 2026, 14 of them inside its Risk Analysis Initiative (HHS OCR, 2026)

$552,250

Paid by OSF Healthcare System in the July 2026 settlement whose lead finding was no accurate and thorough risk analysis (HHS OCR, 2026)

15 days

Business days a Texas provider has to release an electronic health record on written request, half the federal allowance (Tex. Health & Safety Code 181.102)

30 days

Deadline to notify the Texas Attorney General when a breach reaches 250 or more Texas residents (Tex. Bus. & Com. Code 521.053)

120 days

Uprite satisfaction guarantee: exit the contract within the first 120 days if the program is not delivering

★★★★★

4.9 average across 57 verified Google reviews

Houston organizations rate Uprite on responsiveness, technical depth, and the documentation discipline that keeps clinical and business operations running through an audit.

Talk to a HIPAA Compliance Specialist

FAQ

Questions Houston Practices Ask About HIPAA Compliant IT

What does a HIPAA risk analysis actually have to include?

It has to cover every place electronic protected health information lives, moves, or rests, rate each risk by likelihood and impact, and carry a date. A vulnerability scan is not a risk analysis. A scan tells you which machines are missing patches. A risk analysis tells you what would happen to patient data if one of them were exploited, how likely that is, and what you decided to do about it. OCR’s cited failures name the analysis, not the scan.

How often does a Houston practice need to redo its HIPAA risk analysis?

HIPAA sets no fixed interval. Uprite runs a full reassessment annually, a lighter review quarterly, and an immediate update after any material change such as a new EHR, location, or vendor. The absence of a stated frequency is not permission to leave it. Investigators establish the frequency retroactively by asking when yours was last updated, and a four-year-old analysis answers that question badly.

Is my IT provider a business associate or a covered entity in Texas?

Both. Federally your IT provider is a business associate. Under Texas Health and Safety Code Chapter 181 it is also a covered entity in its own right, because it stores or transmits PHI. That matters when you are evaluating vendors. A provider who describes itself only as a business associate is describing half its obligations, and the Texas half includes workforce training within 90 days of hire.

Do we have to comply with the 2026 HIPAA Security Rule changes yet?

No. The proposed Security Rule overhaul published January 6, 2025 has not been finalized. The federal regulatory agenda currently shows a final rule in July 2027, so no compliance deadline exists. Anyone selling you a 2026 deadline is selling a rule that has not been written. The current Security Rule is what OCR is enforcing, and it is being enforced actively.

Can Uprite do the compliance work if we already have an IT provider?

Yes. That is the standard version of this engagement. Uprite owns the risk analysis, risk management plan, evidence file, and BAA chain, while your existing provider handles implementation on the systems they run. The division of responsibility goes in writing before we start. Practices that keep an incumbent they like, and add compliance ownership on top, tend to move faster than practices that change everything at once.

What happens if we get breached and OCR opens an investigation?

OCR sends a data request asking for your risk analysis, risk management plan, policies, training records, and business associate agreements. We assemble that package and stay engaged through the investigation. Timelines are long. OSF Healthcare reported in October 2021 and settled in July 2026, so assume the file outlives the incident by years and keep the documentation accordingly.

How fast do we have to report a breach in Texas?

Individuals get notice within 60 days. If 250 or more Texas residents are affected, the Texas Attorney General must be notified within 30 days, and the breach then appears on the AG’s public listing. The federal and state clocks are separate. A breach can fall below HIPAA’s 500-person media notification threshold and still owe Texas a filing in half the federal time.

Does Uprite sign a business associate agreement?

Yes. Uprite signs a BAA with every healthcare client before touching an environment that contains protected health information. We also audit your other vendors’ agreements as part of the program, because the gap we find most often is not a missing Uprite BAA. It is a transcription service or a legacy imaging vendor that nobody papered.

Start Here

Start With Your Risk Analysis

Most Houston practices we meet have something. A binder from 2019. A vendor questionnaire. A scan report somebody filed. What they usually do not have is a current, dated risk analysis with a management plan attached, which is the first thing OCR asks for.

Our review is free and diagnostic, not a pitch. We look at what exists, tell you which of it would hold up, and price the gap. If your documentation is already in good shape, we will say so.

That happens sometimes. Not often.

Or call our Houston office directly at (281) 606-0274.