
HIPAA Security Rule Compliance • Houston, TX
HIPAA Compliant IT Services in Houston
Uprite runs the HIPAA Security Rule program for Houston medical practices: the risk analysis, the risk management plan, and the evidence file OCR asks for first. We can run it alongside the IT team or provider you already have.
Uprite delivers HIPAA compliant IT services in Houston as a documented Security Rule program: an accurate and thorough risk analysis, a written risk management plan, and a maintained evidence file, backed by a 120-day satisfaction guarantee. We support covered entities across Harris County, from Texas Medical Center specialty groups to independent practices in Katy, Sugar Land, and The Woodlands. The program runs whether Uprite manages your whole environment or only the compliance side of it.
Recognized Across Texas for Managed IT, Security and Compliance
What Enforcement Actually Says
OCR Rarely Fines a Houston Practice for Getting Breached
Read the settlements instead of the headlines. A breach opens the file. It is almost never what closes it.
The Office for Civil Rights publishes every resolution agreement it signs. Through July 2026 the agency has closed 21 ransomware enforcement actions, and 14 of those sit inside a program it calls the Risk Analysis Initiative. The name is the finding.
In June 2026 OCR settled with a national retailer’s employee health plan for $450,000 over a 2021 ransomware attack that reached 10,023 people. Neither cited failure was the intrusion. They were failing to conduct an accurate and thorough risk analysis, and failing to implement reasonable and appropriate policies, both worded by OCR as failures that existed prior to the breach incident.
Six weeks later OCR settled with OSF Healthcare System for $552,250. Same lead finding. No accurate and thorough risk analysis of the risks and vulnerabilities to its electronic protected health information.
OCR Director Paula M. Stannard put it plainly in that second announcement: if a regulated entity does not know what threats and vulnerabilities exist to its ePHI, they will often learn the hard way when their systems are hacked.
So the question to ask a prospective IT provider is narrow. Who produces the risk analysis, how often, and what happens to the gaps it finds?
The Deliverables
Three Documents Decide How an OCR Investigation Goes
Security Rule compliance is not a posture. It is a paper trail with dates on it.
Everything in 45 CFR 164.308 through 164.312 eventually resolves into evidence somebody has to hand over. These are the three artifacts that carry the weight.
The Risk Analysis
Required by 164.308(a)(1)(ii)(A). It has to be accurate and thorough, which means it covers everywhere ePHI actually lives: the EHR, the imaging server, the billing clearinghouse, the front desk workstation, the phone that reads the on-call inbox. We map that flow first, then rate each risk by likelihood and by impact on patients, which is the judgment a vulnerability scanner cannot make on your behalf no matter how complete its output looks. A template with your name typed into it is not a risk analysis.
The Risk Management Plan
Required by 164.308(a)(1)(ii)(B). This is the half most practices skip. A risk analysis that lists twenty gaps and stops there reads, to an investigator, as proof you knew. The plan assigns each gap an owner, a control, and a date, and it shows movement quarter over quarter.
The Evidence File
Not named in the rule, and the one that saves you anyway. Training completions. Access reviews. Encryption attestations. Backup restore tests. Signed business associate agreements. Every OCR corrective action plan we have read asks for records like these going back years, not a snapshot from last week. The controls that produce that evidence, and who operates them day to day, are covered on our HIPAA cybersecurity services in Houston page.
Uprite produces all three, keeps them current, and stores them where your practice administrator can reach them without calling us.
Scope of Work
What the HIPAA Compliance Program Covers
Annual Risk Analysis and Quarterly Reassessment
A full 164.308(a)(1)(ii)(A) analysis every year, plus a lighter review each quarter and after any material change: a new EHR module, a new location, a new vendor, a merger. HHS does not set a frequency. Investigations set it retroactively, by asking when yours was last updated and then reading the gap between that date and the date of the incident as a finding in itself.
Business Associate Agreement Chain
We map every vendor that touches ePHI, confirm a signed BAA exists for each, and flag the ones that expired or never existed. Most practices we assess find at least one live vendor with no agreement on file, and in almost every case that vendor has been receiving protected health information for years without anybody noticing the omission. Transcription and IT support are the usual two.
Technical Safeguard Implementation
Encryption at rest and in transit, unique user identification, automatic logoff, audit controls, and multi-factor authentication on everything that reaches ePHI from outside the building. Where a control is addressable rather than required, we document the decision and the reason. Addressable does not mean optional. It means you have to write down why.
Breach Response and OCR Support
A written incident response procedure, tested. If something does happen, we assemble the notification timeline, produce the evidence file, and stay in the room for the investigation. That last part is not standard in an MSP contract. Read yours.
Why Timing Matters
The Investigation Outlives the Incident by Years
This is the part that reframes the purchase.
OSF Healthcare filed its breach report in October 2021. OCR announced the settlement on July 29, 2026. The Spencer Gifts health plan reported in January 2022 and settled on June 18, 2026. Four and a half years. Nearly five.
Think about what that means operationally. The IT provider you had at the time of the incident may not be the one you have when the request for information lands. Whoever configured the backup may have moved on. Your vendor list has turned over twice.
What survives that gap is documentation, and documentation cannot be created backwards. OCR asks for the risk analysis that existed before the attack. Either it was being maintained on a schedule, with dates, or it was not, and no amount of remediation afterward changes which of those is true.
So we treat the compliance file as a standing deliverable with a calendar attached, not a project that closes.
What Clients Say
Hector and Kareem are super helpful! They are always willing to take on my computer problems even if its small. I had my mouse disappear off my screen, it was an user issue but Hector didn't make me feel small or "dumb" for this error. We love uprite!
I had been having trouble with an IT matter that I didn't think would be fixed but Arvin Ebueng from Upright took his time with me and worked with me until we were able to resolve the issue. The issue was an internal issue with the way the program was written, but Arvin came up with a great work around so that I am now able to do what I need to do at my job. Long story short, he got me access to both things that I need access to simultaneously and daily. Thanks 😊 Arvin, you are much appreciated 👏 💐 🥳.
I'm am not a "tech" person, however the team at Uprite gets me through the technological side of computers and software so that I can function on a daily basis... but the most enduring quality is that they care. Special shoot out to Mary, Sergio, Eufemio, Hector, and Jeff just to name a few... I appreciate each of you and the help you give me.
Sergio Rios is a rock star. I spent about 2 hours trying to fix a problem myself, then called him, and in under 3 minutes my issue was resolved. I highly recommend Uprite, and especially Sergio.
We use this IT Service at Delta Fastener, they are always helpful and prompt with their responses. They solve our computer issues quickly and effectively. A knowledgeable staff is the most important asset to a company - Uprite fills that gap for us by being a partner in business for all of our IT issues. Outsource what you don't know and focus on what is really making you money!
The Texas Layer
In Texas, Your Compliance Perimeter Is Wider Than HIPAA’s
Federal HIPAA draws a line. Covered entities on one side, business associates on the other, a signed agreement bridging them.
Texas draws a different line, and it is drawn wider. Chapter 181 of the Texas Health and Safety Code, the statute HB 300 amended, defines a covered entity as any person who assembles, collects, analyzes, uses, evaluates, stores, or transmits protected health information. There is no business associate tier.
Read that against your vendor list. Your billing service, your transcription provider, your cloud backup, and your IT company are covered entities under Texas law in their own right, not contractors standing behind your compliance. So is Uprite.
Two practical consequences follow. HB 300 requires PHI training for workforce members within 90 days of hire, and that clock runs at your vendors too. Section 181.102 gives a patient the right to an electronic health record within 15 business days of a written request, where HIPAA allows 30 calendar days. Houston practices routinely quote the federal number.
We assess against both regimes, because a Texas Attorney General inquiry and an OCR inquiry ask for different things. The statewide version of this is covered on our HIPAA-compliant IT page, and the practical control list lives in our HIPAA IT compliance checklist for Texas practices.
Notification Timing
Three Clocks Start on the Same Bad Morning
A breach at a Houston practice does not trigger one deadline. It triggers several, and they run at different speeds from different starting guns.
HIPAA gives you 60 days from discovery to notify affected individuals. If 500 or more people are involved, HHS and prominent local media get notified inside that same window. Under 500, HHS can wait for the annual filing, and that exception is the one practices most often misread.
Texas Business and Commerce Code Section 521.053 runs on its own schedule. Individual notice is due within 60 days of determining the breach occurred. If 250 or more Texas residents are affected, the Attorney General must be notified, and Senate Bill 768 cut that window to 30 days.
So a 400-patient breach at a Houston clinic can sit below the HHS media threshold and still owe the Texas Attorney General a filing in half the federal time, which then appears on the AG’s public breach listing.
Nobody works this out correctly under pressure at 9pm. It belongs in a written procedure, decided in advance. If you also fall under Texas SB 2610, our breakdown of HIPAA versus Texas SB 2610 explains how the safe harbour interacts with these deadlines.

Straight Answer
The 2026 Security Rule Overhaul Is Not Law Yet
You have been getting emails about it. Here is where it actually stands.
HHS published the proposed Security Rule overhaul in the Federal Register on January 6, 2025. The comment period closed on March 7, 2025 with roughly 4,745 comments filed. As of August 2026, OCR is still working through them. The Office of Management and Budget’s regulatory agenda now shows a final rule in July 2027.
- Already required today: a risk analysis that is accurate and thorough, and updated when the environment changes
- Already required today: a risk management plan that acts on what the analysis found
- Already required today: business associate agreements with every vendor handling ePHI
- Addressable today, proposed as mandatory: encryption of ePHI at rest and in transit
- Not currently named, proposed as mandatory: multi-factor authentication on ePHI access
- Proposed: a maintained technology asset inventory and network map on a fixed cycle
- Proposed: removal of the addressable category, making the full control set required
So the headline items, mandatory encryption, mandatory multi-factor authentication, removal of the addressable category, and asset inventories on a fixed cycle, are proposals. They are not enforceable. No compliance deadline exists for them.
What is enforceable is the Security Rule as written in 2003, and OCR settled two cases on it in the last three months. We build toward the proposal where it costs nothing extra, because encryption and MFA are good ideas regardless. We do not sell a deadline that has not been set.
When It Happens
What Actually Happens When OCR Opens a File
It starts quietly. A letter, not a raid.
OCR sends a data request. It typically asks for your risk analysis, your risk management plan, your policies and procedures with version dates, your training records, and your business associate agreements. You get weeks, not months.
The practices that come through this well are not the ones with the best security. They are the ones who can answer in the first response, from files that already existed, without a scramble.
We assemble that package, walk your leadership through what it shows before anything goes out, and stay engaged for the duration rather than handing you a folder and disappearing. We also tell you honestly what it shows, including the gaps, because a response that overstates the record is a far worse problem than one that documents a gap and the plan that was closing it.
If your current IT contract does not say who does this work, it is worth reading before you need to know.
Scope Check
Compliance Program, Full Managed IT, or Both
| HIPAA Compliance Program (this page) | Uprite MED℠ Managed IT Instead |
|---|---|
| You have IT you are happy with, in house or outsourced, and need the Security Rule work done properly | You want one provider accountable for the help desk, the EHR, the network, and compliance together |
| You need a risk analysis, a risk management plan, and an evidence file that survives an investigation | You are losing clinical hours to tickets, downtime, and slow response |
| You failed or barely passed a compliance review and need remediation with dates attached | You are replacing an IT provider entirely |
| You are a covered entity under Texas Chapter 181 and unsure what that adds to your obligations | You are opening a second or third Houston location and need the build standardized |
| A payer, hospital system, or acquirer has asked to see your security documentation | You want 24/7 help desk and onsite support across Harris County |
These are two different purchases and they get confused constantly. This page is about the first one. If you want Uprite running the help desk, the EHR support, and the infrastructure as well, that is our Houston healthcare managed IT program, and it is the better fit.
Co-Managed by Design
This Works Alongside the IT You Already Have
Most compliance engagements fail on politics, not technique.
A practice hires a compliance firm, the firm writes findings, the incumbent IT provider reads them as an audit of their work, and remediation stalls in a standoff nobody wants to escalate. We have walked into that room more than once.
So we scope it explicitly. Uprite owns the risk analysis, the risk management plan, the evidence file, and the BAA chain. Your existing team or provider owns implementation on the systems they already run, on dates agreed together. Where they would rather we do that work, we do, and the split is written down.
The practice administrator ends up with one document saying who is responsible for what. That is usually the first time it has existed in writing.
How It Runs
How the Engagement Actually Runs
Week 1: ePHI Discovery
We map where protected health information enters, moves, rests, and leaves. Systems, vendors, devices, and the workarounds staff quietly built because the official process was too slow to survive a full clinic day, which is the category where the real findings almost always sit.
Weeks 2 to 4: Risk Analysis
A full 164.308(a)(1)(ii)(A) analysis against both HIPAA and Texas Chapter 181, rated by likelihood and impact, written the way an investigator reads it rather than the way a scanner exports it.
Week 5: Risk Management Plan
Every finding gets an owner, a control, a target date, and a cost. You approve the sequence. Nothing on that plan becomes a surprise line item later.
Ongoing: Evidence and Reassessment
Quarterly review, annual full reassessment, training tracked against the 90-day HB 300 clock, BAAs monitored for expiry, and a file you can hand to a payer, an acquirer, or OCR without preparing it first.
Numbers That Matter
Numbers That Matter
21
Ransomware enforcement actions OCR has closed through July 2026, 14 of them inside its Risk Analysis Initiative (HHS OCR, 2026)
$552,250
Paid by OSF Healthcare System in the July 2026 settlement whose lead finding was no accurate and thorough risk analysis (HHS OCR, 2026)
15 days
Business days a Texas provider has to release an electronic health record on written request, half the federal allowance (Tex. Health & Safety Code 181.102)
30 days
Deadline to notify the Texas Attorney General when a breach reaches 250 or more Texas residents (Tex. Bus. & Com. Code 521.053)
120 days
Uprite satisfaction guarantee: exit the contract within the first 120 days if the program is not delivering
4.9 average across 57 verified Google reviews
Houston organizations rate Uprite on responsiveness, technical depth, and the documentation discipline that keeps clinical and business operations running through an audit.
Talk to a HIPAA Compliance SpecialistFAQ
Questions Houston Practices Ask About HIPAA Compliant IT
It has to cover every place electronic protected health information lives, moves, or rests, rate each risk by likelihood and impact, and carry a date. A vulnerability scan is not a risk analysis. A scan tells you which machines are missing patches. A risk analysis tells you what would happen to patient data if one of them were exploited, how likely that is, and what you decided to do about it. OCR’s cited failures name the analysis, not the scan.
HIPAA sets no fixed interval. Uprite runs a full reassessment annually, a lighter review quarterly, and an immediate update after any material change such as a new EHR, location, or vendor. The absence of a stated frequency is not permission to leave it. Investigators establish the frequency retroactively by asking when yours was last updated, and a four-year-old analysis answers that question badly.
Both. Federally your IT provider is a business associate. Under Texas Health and Safety Code Chapter 181 it is also a covered entity in its own right, because it stores or transmits PHI. That matters when you are evaluating vendors. A provider who describes itself only as a business associate is describing half its obligations, and the Texas half includes workforce training within 90 days of hire.
No. The proposed Security Rule overhaul published January 6, 2025 has not been finalized. The federal regulatory agenda currently shows a final rule in July 2027, so no compliance deadline exists. Anyone selling you a 2026 deadline is selling a rule that has not been written. The current Security Rule is what OCR is enforcing, and it is being enforced actively.
Yes. That is the standard version of this engagement. Uprite owns the risk analysis, risk management plan, evidence file, and BAA chain, while your existing provider handles implementation on the systems they run. The division of responsibility goes in writing before we start. Practices that keep an incumbent they like, and add compliance ownership on top, tend to move faster than practices that change everything at once.
OCR sends a data request asking for your risk analysis, risk management plan, policies, training records, and business associate agreements. We assemble that package and stay engaged through the investigation. Timelines are long. OSF Healthcare reported in October 2021 and settled in July 2026, so assume the file outlives the incident by years and keep the documentation accordingly.
Individuals get notice within 60 days. If 250 or more Texas residents are affected, the Texas Attorney General must be notified within 30 days, and the breach then appears on the AG’s public listing. The federal and state clocks are separate. A breach can fall below HIPAA’s 500-person media notification threshold and still owe Texas a filing in half the federal time.
Yes. Uprite signs a BAA with every healthcare client before touching an environment that contains protected health information. We also audit your other vendors’ agreements as part of the program, because the gap we find most often is not a missing Uprite BAA. It is a transcription service or a legacy imaging vendor that nobody papered.
Start Here
Start With Your Risk Analysis
Most Houston practices we meet have something. A binder from 2019. A vendor questionnaire. A scan report somebody filed. What they usually do not have is a current, dated risk analysis with a management plan attached, which is the first thing OCR asks for.
Our review is free and diagnostic, not a pitch. We look at what exists, tell you which of it would hold up, and price the gap. If your documentation is already in good shape, we will say so.
That happens sometimes. Not often.
Or call our Houston office directly at (281) 606-0274.

















