HIPAA IT Compliance Checklist for Texas Medical Practices

HIPAA IT compliance in Texas requires 3 layers of safeguards around electronic patient data, which are administrative, physical, and technical. Texas medical practices carry a second layer as well, because HB 300 adds state training rules, faster record access, and a shorter breach reporting clock than federal law.

Every Texas clinic answers to 2 privacy regimes at once. Federal HIPAA sets the floor, and the Texas Medical Records Privacy Act raises it. This checklist walks through the IT controls we verify during a healthcare assessment, the evidence you need to keep for each one, how often to redo it, and where Texas rules bite harder than federal ones. Practices that want the operational side handled for them can start with managed IT for healthcare.

What Does HIPAA IT Compliance Require in Texas?

HIPAA IT compliance is the set of administrative, physical, and technical safeguards a practice builds around electronic protected health information, backed by written policies, signed vendor agreements, and 6 years of retained documentation. In Texas, that same program also has to satisfy HB 300, which layers state training and notification duties on top of the federal rule.

The tricky part is that HIPAA never hands you a shopping list. The Security Rule is deliberately technology neutral, so it names outcomes instead of products. A 4-person dental office and a 40-provider multispecialty group are held to the same standards, scaled to size, complexity, and risk.

That flexibility gets misread constantly. Because the rule rarely says “buy this,” practice managers treat controls as optional. Most are not optional at all. They are simply written as goals so the rule survives a decade of changing technology.

One honest caveat before the checklist. No vendor can sell you compliance. Your EHR platform can be capable of supporting HIPAA and your practice can still be out of compliance on the same day, because the gaps usually sit in access reviews, training records, and vendor paperwork rather than in the software itself. If you want the general-purpose version of this list, our HIPAA compliance checklist covers the non-technical pieces too.

Step 1. Run the Risk Analysis, Because OCR Asks for It First

Network rack and firewall inside a Texas medical practice IT closet during a technology asset inventory

If you only fix 1 thing this quarter, fix this. A security risk analysis is the requirement that shows up in nearly every HIPAA enforcement action involving a small provider, and it is the first document the Office for Civil Rights asks for when an investigation opens.

OCR launched a dedicated Risk Analysis Initiative and has been steadily closing cases under it, with published resolution amounts for smaller providers landing well inside the range a private practice would feel. The full list of OCR resolution agreements and civil money penalties is public, and the pattern is hard to miss. Ransomware gets the headline, the missing risk analysis gets the fine.

A defensible risk analysis is not a 1-page questionnaire. HHS spells out what it expects in its guidance on risk analysis, and the short version is that you have to know where every piece of ePHI lives, how it moves, what could go wrong, how likely that is, and what you did about it.

Small practices do not need to buy expensive software for this. HHS and the Assistant Secretary for Technology Policy publish a free Security Risk Assessment Tool, now at version 3.6, as both a Windows desktop app and an Excel workbook. It walks you through asset inventory, vendor tracking, and threat rating, and version 3.6 added a reviewed-by confirmation with a date stamp for each section, which is exactly the kind of artifact an investigator wants to see.

Redo the analysis at least annually, and again whenever you add a location, swap EHR vendors, move a system to the cloud, or work through a security incident. A risk analysis dated 4 years ago is worse than none at all, because it proves you knew the requirement existed.

The Administrative Safeguards Checklist

Administrative safeguards account for more than half of the Security Rule, which surprises owners who assume compliance is mostly firewalls and antivirus. These are the policy and people controls, and they are the ones most often missing when we assess a new healthcare client.

  • A current security risk analysis with a documented risk management plan showing what you decided to fix, defer, or accept, and why.
  • A named security official who owns the program. In a 6-person clinic this is usually the practice administrator, and the appointment needs to be in writing.
  • Workforce training at hire and annually after that, with signed completion records.
  • A sanction policy that says what happens when a staff member violates privacy rules, applied consistently.
  • Regular review of system activity, meaning somebody actually reads the audit logs and login reports rather than just collecting them.
  • Access authorization and termination procedures, so accounts are provisioned by role and killed the day someone leaves.
  • A written contingency plan covering data backup, disaster recovery, and emergency mode operation, plus evidence you tested it.
  • An incident response plan with named roles, escalation paths, and a breach assessment workflow.

Notice how many of those produce paperwork. That is the point. Under 45 CFR 164.316, policies, risk assessments, training records, and system activity reviews have to be retained for 6 years from creation or from the date they were last in effect, whichever is later. A control you cannot evidence is a control you did not have.

The Technical Safeguards Checklist

Clinician approving a multi-factor authentication prompt on a smartphone while signing in to a clinical workstation

These are the controls inside your systems. Work down the list and mark each one as in place, partially in place, or absent. Partial counts as absent until you can show the evidence.

  • Unique user IDs for every person who touches ePHI. Shared front desk logins destroy the audit trail and are the fastest way to fail an investigation.
  • Multi-factor authentication on email, remote access, the EHR, and any cloud admin console. Treat this as required even though federal law still lists it as addressable.
  • Role-based permissions that match the minimum necessary standard, reviewed at least twice a year against your current staff roster.
  • Encryption of ePHI at rest on servers, workstations, laptops, and portable drives. A stolen encrypted laptop is an inconvenience, and a stolen unencrypted one is a reportable breach.
  • Encryption in transit for email, patient portal traffic, remote sessions, and any file transfer to a billing partner or lab.
  • Automatic logoff on every workstation, tuned short enough for exam rooms and the front desk.
  • Audit logging that captures logins, failed attempts, record access, permission changes, and data exports, retained for 6 years.
  • Integrity controls that detect improper alteration or destruction of records.
  • Patched systems on a defined cadence, with an inventory that proves nothing is running an unsupported operating system.
  • Tested backups with a documented restore, not just a green checkmark in a backup console.

The backup line is worth pausing on. Almost every practice we assess has backups. Far fewer can produce a dated restore test. If you have never actually pulled a file back from your backup and timed it, you have a backup product, not a recovery capability.

How Often to Redo Each Control, and What Evidence to Keep

Auditors care about cadence and proof as much as the control itself. This is the version of the checklist we hand to practice administrators, because it answers the 2 questions they always ask next.

ControlCadenceEvidence to keep on file
Security risk analysisAnnually and after any material changeSigned report, asset inventory, threat ratings, risk management plan
Workforce privacy and security trainingAt hire, then annuallyAttendance sheets, signed completion statements, course content
Texas HB 300 role-based trainingWithin 90 days of hire, then within 1 year of a material law changeSigned acknowledgment, date of hire, training date
User access reviewEvery 6 months at minimumReviewed roster with role, system, and reviewer signature
Business associate agreementsOn vendor onboarding, then reviewed annuallyExecuted BAA per vendor, plus a master vendor list
Backup restore testQuarterlyRestore log with date, file set, and elapsed recovery time
Incident response tabletopAnnuallyScenario notes, participants, gaps identified and closed
Audit log reviewMonthlyReview notes with anomalies and follow-up actions
Vulnerability scanEvery 6 months, moving toward the proposed federal cadenceScan report plus remediation tracking

The Physical Safeguards Checklist

Physical controls get skipped because they feel obvious, and then a laptop walks out of an unlocked office. Run through these once a year with a clipboard and your own eyes.

  • Server, network, and telecom equipment behind a locked door with a documented list of who holds a key or badge.
  • Front desk and nurse station monitors angled or filtered so patients in the waiting area cannot read them.
  • A device inventory covering every workstation, laptop, tablet, phone, and portable drive that touches ePHI.
  • A written media disposal process, including certificates of destruction for retired drives and printers.
  • Facility access records for after-hours entry, including vendors and cleaning crews.
  • Workstation use rules that say what staff may and may not do on clinic machines.

What Texas Adds on Top of HIPAA

Texas medical practice staff attending a HIPAA and HB 300 privacy training session and signing attendance records

This is where national checklists stop being useful. The Texas Medical Records Privacy Act, Health and Safety Code Chapter 181, better known as HB 300, applies a broader definition of covered entity than HIPAA does and adds duties that catch practices off guard.

Start with training. Texas requires role-relevant training on both state and federal PHI rules by the 90th day after hire, not within the first year. The training has to reflect what that person actually does with PHI, the employee has to sign a statement confirming completion, and the record stays on file for 6 years. Retraining is required within a reasonable period after a material change in the law, and no later than 1 year.

Then there is patient access. Texas gives you 15 business days to produce an electronic record when a patient requests it in electronic form, which is materially tighter than the federal 30-day window. Practices that route every records request through a busy front desk queue tend to discover this deadline the hard way.

The breach clock is the item most likely to trip you. Under Texas Business and Commerce Code Chapter 521, individuals get notice without unreasonable delay and no later than 60 days after discovery. Separately, if 250 or more Texas residents are affected, the Texas Attorney General has to be notified within 30 days. That is 2 clocks with 2 different deadlines, and the shorter one belongs to the state.

ObligationFederal HIPAATexas requirement
Workforce training deadlineWithin a reasonable time after hireWithin 90 days of hire, role specific
Electronic record access30 days, 1 extension permitted15 business days on electronic request
Individual breach noticeWithout unreasonable delay, up to 60 daysWithout unreasonable delay, up to 60 days
Regulator notice for large breachesHHS OCR within 60 days for 500 or more individualsTexas Attorney General within 30 days for 250 or more Texas residents
Documentation retention6 years6 years, including signed training statements

One more Texas-specific angle worth knowing. Senate Bill 2610, effective September 1, 2025, created a safe harbor from exemplary damages for Texas businesses with fewer than 250 employees that adopt and maintain a recognized cybersecurity framework. The requirements scale with headcount, from basic password and awareness practices under 20 employees, to CIS Controls Implementation Group 1 between 20 and 99, to a full framework such as NIST CSF or ISO 27001 between 100 and 249. Most independent practices land squarely in that range. We broke the mechanics down in our Texas SB 2610 compliance guide, and the overlap with HIPAA is covered in HIPAA vs Texas SB 2610.

Every Vendor That Touches PHI Needs a Signed Agreement

Medical practice office manager reviewing vendor contracts to confirm signed business associate agreements

Business associate agreements are the cheapest compliance win available and one of the most common findings against small practices. The paperwork is free. The gap is that nobody keeps a complete vendor list.

Practices usually have a BAA with the obvious 3, which are the EHR vendor, the billing company, and the clearinghouse. What goes missing is everything that crept in later.

  • Cloud storage and file sharing accounts used by clinical staff.
  • Email and productivity platforms. Microsoft covers Exchange Online, SharePoint, OneDrive, and Teams under its standard BAA terms on paid commercial plans, but only once you have identified your organization as HIPAA regulated.
  • Your IT provider, including any subcontracted help desk.
  • Backup and disaster recovery services.
  • Transcription, answering, and after-hours triage services.
  • Shredding and document destruction vendors.
  • Patient communication tools such as reminder texting, telehealth, and online scheduling.
  • Any AI scribe, coding assistant, or analytics tool that sees clinical notes.

That last one deserves attention right now. Ambient documentation tools are landing in practices faster than the vendor review process can keep up, and not every AI vendor will sign a BAA. Ask before the pilot, not after. If you want a second set of eyes on the whole vendor list, a compliance and regulatory assessment is usually the fastest way to find what is missing.

Are Mandatory Encryption and MFA Already the Law? Not Yet

Here is a correction worth making, because a lot of 2026 content gets it wrong. Several widely shared articles state that mandatory encryption, mandatory MFA, biannual vulnerability scanning, and 72-hour breach reporting now apply to every covered entity. They do not. Not yet.

HHS published the proposed Security Rule overhaul as a Notice of Proposed Rulemaking on January 6, 2025, and the comment period closed on March 7, 2025. It remains a proposal. OCR has not issued a final rule, and the current regulatory agenda points to final action no earlier than 2027, as HIPAA Journal has tracked.

The substance still matters. The HHS fact sheet on the proposed rule confirms the biggest structural change, which is removing the addressable designation. Since 2003, safeguards like encryption and MFA have been addressable, meaning a practice could document why an alternative was reasonable. In the field, addressable quietly became optional. If the proposal is finalized in anything close to its current form, that escape hatch closes.

What the proposal would require, once final, is worth planning against now.

  • Encryption of ePHI at rest and in transit, with narrow exceptions.
  • Multi-factor authentication on systems that access ePHI.
  • Vulnerability scanning every 6 months and annual penetration testing.
  • A maintained technology asset inventory and network map, reviewed at least annually.
  • Network segmentation separating clinical systems from general office and IoT devices.
  • Restoration of ePHI systems within 72 hours of an incident.
  • Business associates notifying covered entities within 24 hours of activating a contingency plan.

Our position is simple. Every item on that list is already the right call for a Texas practice, rule or no rule, and most of them are cheaper to implement on your own schedule than under a compliance deadline. Build toward it now and the final rule becomes a paperwork exercise instead of a fire drill. There is more detail on the operational side in our guide to HIPAA-compliant IT.

What Getting This Wrong Actually Costs

Healthcare IT security team working a breach incident response timeline at night on dual monitors

Healthcare has been the most expensive industry to breach for 13 straight years. The 2026 IBM Cost of a Data Breach Report puts the healthcare average at 6.64 million dollars, down from 7.42 million the year before but still far ahead of every other sector.

The volume tells the same story. Since mandatory reporting began in October 2009, more than 7,400 large healthcare breaches have been posted to the HHS breach portal, affecting over 935 million individuals, and 2025 set an annual record at 772 large breaches, according to HIPAA Journal breach statistics. Small practices are well represented in that list, because attackers know the defenses are thinner.

Then there are the penalties themselves, which rose again on January 28, 2026 with the annual inflation adjustment.

TierWhen it appliesPer violationAnnual cap
1The practice did not know and could not reasonably have known145 dollars to 36,505 dollars36,505 dollars
2Reasonable cause, not willful neglect1,461 dollars to 73,011 dollars146,053 dollars
3Willful neglect, corrected within 30 days14,602 dollars to 73,011 dollars365,052 dollars
4Willful neglect, not corrected73,011 dollars to 2,190,294 dollars2,190,294 dollars

Current tier amounts are published by HIPAA Journal and reflect the 2026 adjustment. Worth noting that the fine is rarely the worst part. A corrective action plan can put an external monitor inside your practice for years, and that cost never shows up in a settlement headline.

A 90-Day Plan for Closing the Gaps

Nobody clears a full checklist in a weekend. This is the sequence we use with new healthcare clients, ordered by how much risk each step removes per hour spent.

  1. Days 1 to 15. Build the asset and vendor inventory. You cannot protect or contract for what you have not listed. Include every device, cloud service, and third party that touches PHI.
  2. Days 16 to 30. Run the risk analysis using the HHS SRA Tool or an outside assessor, and write the risk management plan that comes out of it.
  3. Days 31 to 45. Close the access gaps. Kill shared logins, turn on MFA everywhere it will go, and run a full permission review against the current staff roster.
  4. Days 46 to 60. Chase the missing BAAs and confirm encryption on every laptop, server, and portable drive.
  5. Days 61 to 75. Test a restore, time it, and write down what happened. Then run a 1-hour tabletop on your breach response, including who calls the Texas Attorney General and by when.
  6. Days 76 to 90. Fix the training record. Confirm every hire from the past year was trained inside the Texas 90-day window and that signed statements are on file.

A 6-person clinic can realistically run this with 2 to 4 hours a week of administrator time plus IT support. A multi-location group should expect to add a project owner. Either way, the sequence matters more than the speed, because the inventory feeds the risk analysis and the risk analysis justifies everything after it.

Questions Texas Practices Ask Us About HIPAA IT Compliance

How often does a Texas practice need to redo its HIPAA risk analysis?

At least once a year, plus any time something material changes in your environment. HIPAA does not name a fixed interval, but OCR treats a stale analysis the same way it treats a missing one.

Material changes include opening a location, replacing your EHR, moving records to a new cloud platform, adding a telehealth or AI documentation tool, or working through a security incident. If you cannot remember the date on your last analysis, that is your answer.

Does HB 300 apply to a small independent clinic, or only to hospitals?

It applies to a small clinic. HB 300 uses a broader definition of covered entity than HIPAA and reaches essentially any person or business in Texas that assembles, obtains, stores, or transmits PHI.

Practically, that means a solo practitioner, a 3-provider dental group, and a hospital system are all in scope for the 90-day training rule, the 15 business day electronic records deadline, and the state notification requirements.

Is encryption optional under HIPAA right now?

Technically it is addressable, not required, which is not the same as optional. You may implement an equivalent alternative, but you have to document why encryption was not reasonable and what you did instead.

In practice that documentation is harder to defend than just encrypting the drive. Encryption also functions as a safe harbor, because a lost device with properly encrypted data generally is not a reportable breach. The proposed Security Rule update would make encryption mandatory outright.

What happens if we discover a breach affecting 300 Texas patients?

You are on 2 clocks at once. Notify affected individuals without unreasonable delay and within 60 days, and notify the Texas Attorney General within 30 days because the count exceeds 250 Texas residents.

Because the number is under 500, the HHS notification for that incident goes in the annual submission rather than within 60 days. The state deadline is the tight one, and it is the one practices miss.

Our EHR vendor says they are HIPAA compliant. Is that enough?

No. A vendor can only make their platform capable of supporting compliance. They have no control over your logins, your permissions, your network, your training records, or your other 12 vendors.

Read the fine print on those claims. What the vendor is certifying is their own environment and their own obligations as a business associate. Your practice is separately responsible for the safeguards on your side of the connection, and OCR investigates you, not them.

How much should a Texas medical practice budget for HIPAA IT compliance?

It depends on your starting point, but the first year is almost always the expensive one because it front-loads the risk analysis, remediation, and any hardware or licensing you have been deferring.

The cheaper path is steady state. Once MFA, encryption, logging, tested backups, and training are running on a schedule, ongoing cost looks like normal managed IT plus an annual assessment. Practices that let it lapse and rebuild every 3 years pay for the same work repeatedly.

Does SB 2610 protect us if we get breached?

Partially, and only against exemplary damages. SB 2610 does not shield you from HIPAA enforcement, from actual damages, or from the notification obligations.

What it does is reward documentation. If your practice has under 250 employees and can show it implemented and maintained a recognized framework appropriate to its size, that becomes an affirmative defense against punitive damages in a Texas data breach suit. It is a reason to write the program down, not a reason to relax it.

Where to Start if This List Found Gaps

Most practices that work through this checklist find between 5 and 15 open items, and the majority sit in documentation rather than technology. That is good news, because paperwork gaps close faster than infrastructure gaps.

Uprite has supported Texas medical practices since 1999, with teams in Houston, San Antonio, and Dallas. If you want the assessment run for you, we can map your ePHI, produce the risk analysis, and build the remediation plan in a single engagement. Local starting points are available for healthcare IT in Houston, healthcare IT in Dallas, and healthcare IT in San Antonio, along with HIPAA cybersecurity services for practices that need the security layer first.

Find out where your practice actually stands

Book a HIPAA IT assessment and get a written gap list, a prioritized remediation plan, and the documentation OCR would ask for. No obligation, and you keep the report either way.

If you would rather scope the security side on its own first, our cybersecurity solutions page covers monitoring, endpoint protection, and incident response for regulated Texas businesses.

About Author