Short version. HIPAA does not publish a checklist. It requires a documented risk analysis, then controls that match what the analysis found. Texas layers HB 300 training rules and a 30-day Attorney General breach notice on top. OCR collected $1,165,000 from four practices this April, and every one of them failed on risk analysis first.
San Antonio medical practices must meet the HIPAA Security Rule’s administrative, physical, and technical safeguards, complete a documented risk analysis under 45 CFR 164.308(a)(1)(ii)(A), and satisfy Texas HB 300 training plus a 30-day Attorney General breach notice. Federal rules set the floor. Texas raises it, and the gap is where most practices get caught.
This guide sits under our wider overview of cybersecurity services in San Antonio and narrows the focus to practices that handle patient records. Start here. Nearly every practice manager we talk to believes their EHR vendor handles HIPAA, and that one assumption is the most expensive belief in healthcare IT. Your vendor secures their platform. Your obligations cover your network, your workstations, your staff, your backups, your remote access, and every single vendor who touches patient data on your behalf, whether or not you ever think about them. Two very different scopes.
This guide is scoped to Bexar County practices. It covers what the law requires today, what Texas adds on top of it, what regulators have actually penalized in 2026, and what changes for your practice when the pending Security Rule update finally lands. No generic safeguards list. We already published the statewide HIPAA IT compliance checklist if that is what you need.
What HIPAA Requires of a Medical Practice, in Plain Terms
The HIPAA Security Rule requires covered entities and business associates to protect electronic protected health information through three families of safeguards. Administrative safeguards cover policy, training, and oversight. Physical safeguards cover facilities and devices. Technical safeguards cover access control, encryption, audit logs, and transmission security.
That is the whole framework. Three families. What trips practices up is that the rule is deliberately scalable by design, so it never tells you which firewall to buy, how long a password should be, or how many days of backup retention are enough. It tells you to analyze your own risks and then address them. Your risks. Not a template.
Which means the risk analysis is not one requirement among many. It is the requirement that generates all the others. HHS guidance on risk analysis makes that structure explicit, and OCR now treats a missing or stale analysis as the violation itself rather than as missing paperwork attached to some other, more serious failure.

Here is the practical translation. If you cannot produce a current written document that names where ePHI lives in your practice, who can reach it, what could go wrong, and what you did about each item, you do not have a HIPAA security program. You have security products. That distinction decides investigations.
The Bexar County Numbers Behind the Problem
San Antonio’s healthcare market is built from small offices, not big systems. Small offices. Big obligations. That shapes the entire compliance problem here.
We pulled the Bureau of Labor Statistics Quarterly Census of Employment and Wages for Bexar County, private ownership, 2025 annual averages. The picture is striking.
| Bexar County sector (NAICS) | Establishments | Employees | Average staff per site |
|---|---|---|---|
| Ambulatory health care services (621) | 4,537 | 76,062 | 17 |
| Offices of physicians (6211) | 1,821 | 24,143 | 13 |
| Offices of dentists (6212) | 845 | 6,412 | 8 |
| Offices of other health practitioners (6213) | 865 | 7,388 | 9 |
Read the last column again. The typical Bexar County physician office runs on 13 people. The typical dental office runs on 8. Nobody in a 13-person office has cybersecurity in their job title, and HIPAA does not care. A solo practice carries the same legal obligation as University Health. Same rule. No exemption.
Scale does change enforcement exposure, though not in the direction most owners expect. Small practices are targeted more, not less, because their defenses are thinner, their downtime tolerance is close to zero, and an attacker knows a clinic with 13 staff cannot run a week on paper charts. The pattern is not limited to medicine, and we mapped which San Antonio industries the FBI reports most outside critical infrastructure.
What Texas Adds That HIPAA Does Not
Texas has its own medical privacy law, and it is broader than HIPAA. The Texas Medical Records Privacy Act, created by HB 300 and codified at Health and Safety Code Chapter 181, applies to almost any Texas business that handles PHI, which sweeps in organizations HIPAA would not reach.
Two Texas requirements catch practices repeatedly.
The first is training. Under Section 181.101, an employee must complete PHI training no later than the 90th day after hire. The employee then signs a statement confirming it, and you keep that signed statement for 6 years. Miss the signature and you have no defensible proof the training happened. Get the signature.
The second is the breach clock. Texas runs a shorter notification deadline than most practices expect. Much shorter.
| Obligation | Federal HIPAA | Texas law |
|---|---|---|
| Notify affected individuals | Within 60 days of discovery | Within 60 days of determining a breach occurred, per Tex. Bus. & Com. Code 521.053 |
| Notify the regulator | HHS OCR within 60 days if 500+ affected, annually if fewer | Texas Attorney General within 30 days if 250+ Texas residents affected |
| How the regulator is notified | OCR breach portal | Electronic filing through the AG’s data breach form, required since September 1, 2023 |
| Training deadline | No fixed deadline in the rule | Within 90 days of hire, with a signed statement kept 6 years |
That 30-day Attorney General window is the one that ruins weekends. A practice with 400 affected patients has to file with the Texas AG a full month before the federal deadline its incident response plan was probably built around, and the two clocks do not even start on the same event. Most plans we review do not mention the state filing at all. Not one line.
Texas also passed SB 2610 in 2025, which offers a liability safe harbor for smaller businesses that adopt a recognized security framework. We broke that down separately in HIPAA vs Texas SB 2610. It does not replace HIPAA. It sits beside it.
What OCR Actually Penalized This Year
Enforcement tells you more than guidance does. So read the settlements. On April 23, 2026, OCR announced four ransomware settlements covering more than 427,000 individuals.
| Entity | Individuals affected | Settlement | Primary finding |
|---|---|---|---|
| Assured Imaging Affiliated Covered Entities | 244,813 | $375,000 | No accurate and thorough risk analysis |
| Regional Women’s Health Group (Axia Women’s Health) | 37,989 | $320,000 | No accurate and thorough risk analysis |
| Star Group Health Benefits Plan | 9,316 | $245,000 | No accurate and thorough risk analysis |
| Consociate Health | 136,539 | $225,000 | No accurate and thorough risk analysis |
Same finding, four times. Total resolution amount was $1,165,000, and each entity accepted a corrective action plan with 2 years of OCR monitoring. Notice the smallest breach in that table. Star Group affected 9,316 people, a patient count a mid-sized San Antonio practice could reach inside 2 years of ordinary operation, and it still paid $245,000 under the same terms as the others. Size did not help.
These sit inside OCR’s Risk Analysis Initiative, which has now produced a dozen enforcement actions since it launched. Nothing about that is subtle. Investigators open on the risk analysis, and when it is missing or years out of date, the outcome is largely settled before anyone looks at your firewall rules or your patching cadence.

Cost data points the same way. IBM’s 2026 Cost of a Data Breach study put the healthcare average at $6.64 million per incident, which is down 10.5% from the $7.42 million reported a year earlier but still the highest figure of any industry in the study. And Texas is not a quiet corner of the map. The FBI’s 2025 Internet Crime Report ranked Texas second nationally with 97,912 complaints and $1.83 billion in reported losses. Second. Out of 50.
The Rule Change That Slipped to 2027
OCR proposed the first major Security Rule overhaul in 20 years. The notice of proposed rulemaking published in the Federal Register on January 6, 2025, and the comment period closed that March.
One headline change drives everything else. Addressable specifications largely go away. What was optional becomes required. Here is what the proposal puts on the table.
- Encryption of ePHI at rest and in transit, no longer addressable
- Multi-factor authentication on systems that touch ePHI
- A written technology asset inventory and network map, updated annually
- Annual penetration testing and semi-annual vulnerability scanning
- Restoration of critical systems within 72 hours of an incident
- Termination of a departing workforce member’s access within 1 hour
- Written verification from business associates that their safeguards are in place
Read item 6 again. Now the timing. HHS originally targeted May 2026 for the final rule. That date moved. The Unified Agenda entry under RIN 0945-AA22 now shows a final action date of July 2027. Fourteen months later.
Here is our honest read, and it cuts against how a lot of vendors are selling right now. Do not buy a “2027 readiness package” today. The rule is not final, the text will move, and you would be paying for compliance with a draft. Do buy encryption, MFA, and an asset inventory now, because those three are already the most common OCR findings under the current rule and they carry no regulatory risk whichever way the final text lands. Buy those. Skip the rest.
One Texas wrinkle almost nobody has connected. Section 181.101 requires retraining within 1 year of a material change in state or federal law affecting an employee’s duties. When the new Security Rule finalizes, that clock starts for every Texas practice. Budget the training refresh, not just the tooling. It adds up.
What Your Practice Should Have in Place Right Now
Requirements do not scale down, but sequencing does. Work in this order.
- A current written risk analysis. Dated within the last 12 months, covering every system that stores or transmits ePHI. This is the document OCR requests first.
- A risk management plan with evidence of action. The 2026 settlements turned on this. Finding a gap and leaving it open is now its own exposure.
- Signed business associate agreements for every vendor touching PHI. Your EHR, your billing service, your imaging vendor, your IT provider, your shredding company.
- MFA on email, remote access, and the EHR. Phishing remains the most common entry point into small practices.
- Encryption on laptops, phones, and backups. Encrypted lost devices are not reportable breaches. Unencrypted ones are.
- Backups that have been restored, not just run. A backup you have never tested is a hypothesis.
- Training completed within 90 days of hire, with signed statements on file for 6 years. This is the Texas requirement, not the federal one.
- An incident response plan that names the Texas 30-day AG deadline. Include who files and what the form needs.

Eight items. Most practices we assess in San Antonio have 3 or 4 of them in place, almost always the technical ones, and are missing the written documentation that would prove any of it to an investigator. Paper is the gap.
Hire a Security Analyst, or Buy the Function
Every practice eventually asks whether to hire for this. San Antonio’s labor market answers it quickly.
BLS occupational data for the San Antonio-New Braunfels metro puts the annual mean wage for an information security analyst at $125,830, drawn from a local pool of just 1,350 people spread across every industry in the region. Apply the standard 1.43x employer cost load from the BLS Employer Costs for Employee Compensation series and a single seat runs to roughly $180,000 a year once benefits, payroll taxes and paid leave are counted. For one person. Business hours only.
| Option | Realistic annual cost | Coverage | Fit for a 13-person practice |
|---|---|---|---|
| Hire an in-house security analyst | About $180,000 loaded | Business hours, one person deep | Poor. Cost exceeds most practices’ entire IT budget |
| Assign it to the office manager | Near zero direct cost | Whatever is left after patient work | Poor. This is where stale risk analyses come from |
| Annual consultant assessment only | Low four figures | One snapshot per year | Partial. Produces the document, not the remediation |
| Managed IT and security partner | Flat monthly, scales with headcount | Continuous, with documentation | Strong. Matches how OCR now evaluates risk management |
Row 3 is the trap. A consultant assessment satisfies the letter of the risk analysis requirement while failing the 2026 enforcement standard, because OCR has made clear it is now scoring what you did in the months after the finding. Documentation without remediation is exactly the profile that got penalized in April. If you want the underlying numbers, our San Antonio cybersecurity cost guide shows what local practices actually pay for security, and our roundup of MSPs for medical practices in San Antonio is the shortlist most of them start from.
Where San Antonio Practices Get Caught
Four patterns show up over and over in our assessments. All four are avoidable.
The risk analysis that was really a vulnerability scan. A scan lists technical findings. A risk analysis covers people, paper, vendors, and facilities too. Practices hand us a 40-page scan report and believe they are covered. They are not.
The BAA inventory nobody owns. Vendors change. Agreements do not follow. We routinely find a signed agreement with a billing company the practice stopped using 3 years ago, nothing at all for the vendor that replaced it, and no named owner to catch the next change.
Shared logins at the front desk. Convenient, common, and fatal to audit logging. If four people share one account, your access log proves nothing about who opened a given chart, which means you cannot answer the first question a breach investigation asks.
The former employee who still has access. The proposed rule sets a 1-hour deprovisioning deadline for a reason. Today the median in small practices is closer to weeks. Weeks.

We should be honest about one thing. For years the standard advice, including ours, treated encryption as addressable and therefore optional if you documented why. That framing has aged badly. Between the enforcement record and the language of the proposed rule, encryption is functionally mandatory now, and any practice still leaning on a documented exception it wrote years ago is carrying real exposure. We got that one wrong.
Questions San Antonio Practices Ask About HIPAA Security
Do we notify the Texas Attorney General, or is HHS enough?
Both, and the Texas deadline comes first. If a breach affects 250 or more Texas residents, you must notify the Attorney General within 30 days through its electronic filing form. HHS notification follows its own 60-day rule for breaches of 500 or more individuals.
We have 6 employees. Does the Security Rule scale down for us?
No. The obligations are identical regardless of headcount. What scales is how you satisfy them. A 6-person practice can meet the same requirements with simpler documentation and far fewer systems, but the risk analysis, the signed business associate agreements and the training records are every bit as mandatory as they are for a hospital.
What proof does OCR accept that we fixed a finding?
Dated evidence tied to a specific risk in your analysis. That means change tickets, configuration screenshots, policy revisions with effective dates, and training completion records. The 2026 settlements show OCR now evaluates remediation, so an unaddressed finding sitting in a 2-year-old report works against you.
If the new Security Rule is not final until 2027, should we wait?
No, but do not overbuy either. Encryption, multi-factor authentication, and an asset inventory are already expected under today’s rule and are safe investments. Anything sold specifically as future-rule compliance is premature, because the final text has not been published.
Does cyber insurance cover a HIPAA penalty?
Usually not the penalty itself. Most policies cover breach response, notification, credit monitoring, and legal defense, while regulatory fines are frequently excluded or sublimited. Insurers also increasingly require MFA and tested backups as a condition of coverage, and a misstatement on the application can void a claim.
Our practice is affiliated with a hospital network. Whose obligation is it?
Yours, unless you are a member of a formal organized health care arrangement or the network is your covered entity. Affiliation agreements rarely transfer Security Rule liability. Read the agreement, confirm whether you are a separate covered entity, and get a BAA in place if the network provides services to you.
Start With the Gap That Would Fail You First
Nothing on this page requires a big budget to begin. It requires knowing where you stand. Pull your last risk analysis and check the date. If it is older than a year, or nobody in the practice can find it at all, then that is your first gap and it happens to be the same one that cost four organizations a combined $1,165,000 this April.
Uprite has supported Texas healthcare organizations for over 25 years, with a local team at 11831 Radium St. in San Antonio and a HIPAA Seal of Compliance verified through the Compliancy Group. If you want the full program rather than the reading, see our HIPAA cybersecurity services for San Antonio practices, our healthcare IT services in San Antonio, or our broader managed IT services for healthcare.
Speak to a San Antonio IT Expert and we will tell you which of the 8 items above your practice is missing. No sales pitch required.









