Dental practice IT security in Texas means running one documented program that meets the HIPAA Security Rule, because Texas SB 2610 pulls HIPAA in by reference for every practice already subject to it. The three laws stacked on a Texas dental office aren’t three projects. They’re one program with three different demands for proof. That is the frame we work from on every dental IT support engagement.
Short version. Texas dental practices sit under the federal HIPAA Security Rule, the Texas Medical Records Privacy Act, and, since September 2025, the SB 2610 liability safe harbor. Nearly every practice in the state qualifies for that safe harbor on headcount alone. Far fewer can prove it. The statute protects a practice only if it can show the program was already running on the day of the breach.
What does dental practice IT security require in Texas?
Dental practice IT security in Texas is the set of administrative, physical, and technical safeguards a practice must run to protect electronic patient records under HIPAA, plus the Texas training and breach notice duties layered on top, plus the documentation that earns the SB 2610 damages shield. Four separate laws. One program.
Practices tend to meet these one crisis at a time. A vendor asks for a business associate agreement, so somebody signs one. An insurer asks whether a risk analysis exists, so somebody buys a template. A patient asks a question nobody can answer. None of it connects. Then a breach happens and the practice discovers that the pile of paperwork doesn’t answer the only question anybody actually asks, which is what was running on the day the attacker got in and who can attest to it.
| Law | What it actually demands | Who enforces it |
|---|---|---|
| HIPAA Security Rule (45 CFR Part 164, Subpart C) | Risk analysis, risk management, administrative, physical, and technical safeguards | HHS Office for Civil Rights |
| Tex. Health & Safety Code ch. 181 (HB 300) | Workforce training within 90 days of hire, signed proof kept 6 years | Texas Attorney General |
| Tex. Bus. & Com. Code sec. 521.053 | Breach notice to individuals in 60 days, to the Texas AG in 30 days at 250+ Texas residents | Texas Attorney General |
| Tex. Bus. & Com. Code ch. 542 (SB 2610) | Voluntary. A documented program blocks exemplary damages in a private suit | Raised as a defense in civil court |
Our healthcare IT practice works the stack in the other direction. Build one program. Let it satisfy all four.
Almost every Texas dental practice already qualifies for the safe harbor
Texas had 12,722 private dental offices in 2025, employing 88,926 people between them, according to Bureau of Labor Statistics QCEW annual averages. Work the division. That comes out to about 7 people per office.

That number decides almost everything about how SB 2610 lands on dentistry.
Senate Bill 2610 added Chapter 542 to the Business and Commerce Code and took effect September 1, 2025, after passing the Senate 31 to 0 and the House 109 to 27. It applies to any Texas business entity with fewer than 250 employees that owns or licenses computerized data containing sensitive personal information, which covers essentially every dental practice in the state that keeps a chart on a computer. A 7 person dental office clears that bar without trying. So does a 40 person group practice. So does a small DSO running 9 locations. That bar is low on purpose.
Under Section 542.003, a person harmed by a breach may not recover exemplary damages from a qualifying business if the business shows that at the time of the breach it was running a compliant cybersecurity program.
Read that clause closely. It’s an affirmative defense, and the burden sits on the practice. Not the plaintiff. The practice has to demonstrate what was in place on a date that has already passed, using evidence it created back when it had no particular reason to think anyone would ever ask for it.
The shield is also narrower than the marketing around it suggests. Exemplary damages are punitive damages. SB 2610 does nothing about actual damages, nothing about the cost of notification, nothing about forensics or credit monitoring, and nothing about an OCR penalty. Section 542.005 says the chapter creates no private cause of action and changes no existing duty. It’s a ceiling on one category of civil award. Useful. Frequently oversold.
Why a dental practice doesn’t get to pick its own framework
This is the part that almost every SB 2610 summary gets wrong, including some written by people who should know better.
Section 542.004(b) lists the frameworks a program can conform to. Subsection (b)(1) reads like a menu. NIST Cybersecurity Framework, NIST 800-171, NIST 800-53, FedRAMP, the CIS Critical Security Controls, ISO 27000, HITRUST CSF, the Secure Controls Framework, SOC 2, or something comparable. Pick one, the summaries say.
Except (b)(1) isn’t the whole subsection.

Subsection (b)(2) adds that the program must also conform to the current version of HIPAA if the business entity is subject to its requirements. A dental practice that transmits any claim electronically is a covered entity. It’s subject to HIPAA. So HIPAA isn’t one option among 10 for a dental office. It arrives automatically, on top of whatever else the practice picks. No opt out.
Then (b)(3) does the same thing with the Payment Card Industry Data Security Standard, where applicable. Practices take cards at the front desk. PCI DSS applies. Two frameworks, uninvited.
The honest reading for a Texas dental practice is that SB 2610 compliance equals HIPAA plus PCI DSS, plus the scale requirements in (a)(4), and the (b)(1) menu everyone quotes is the part a dental office has the least freedom to choose from. A practice that adopts CIS Controls and skips a real HIPAA risk analysis hasn’t built a qualifying program. It’s built half of one. That half won’t hold up.
If you want the general version of this analysis rather than the dental one, we wrote a plain guide to what SB 2610 requires and a separate breakdown of how HIPAA and SB 2610 interact for healthcare providers.
The 20 employee line moves when you hire
Section 542.004(a)(4) scales the program to headcount. Those boundaries land in awkward places for a growing dental practice.
| Employees | What Section 542.004(a)(4) requires | Typical Texas dental practice |
|---|---|---|
| Fewer than 20 | Simplified requirements, including password policies and appropriate employee cybersecurity training | Single location, 3 to 10 operatories |
| 20 to 99 | Moderate requirements, including CIS Controls Implementation Group 1 | Group practice, or 2 to 5 locations |
| 100 to 249 | Full conformance with a framework under Subsection (b) | Regional DSO |
| 250 or more | Chapter 542 doesn’t apply at all | Large DSO, no safe harbor available |
Most single location practices sit in that top row, under 20, where the statutory language is genuinely light. Password policies. Training that fits the job. That’s the text.
The jump is what catches people. Cross 20 employees and the practice inherits CIS Controls Implementation Group 1, which is 56 discrete safeguards covering asset inventory, account management, data recovery, audit log management, and secure configuration across every device the practice owns. Nobody sends a letter when you cross that line. You hire a second hygienist and a treatment coordinator, and the bar has moved. Quietly.
Practices that acquire a second location are the ones this bites. Two 12 person offices under one entity are a 24 person business. Same practice. New tier. The program that qualified in January doesn’t qualify in November.
Section 542.004(c) adds a maintenance duty on top. When a framework publishes an update, the program has to be realigned by the later of the standard’s own implementation date or the first anniversary of publication. Built once and left alone, a program quietly stops qualifying.
What OCR actually punished in 2026
Enforcement tells you more than the statute does about where the risk really sits. Start there.
On April 23, 2026, OCR announced four HIPAA Security Rule ransomware settlements at once, covering breaches that hit more than 427,000 people and totaling $1,165,000 in payments with 2 year corrective action plans attached. Regional Women’s Health Group paid $320,000. Assured Imaging paid $375,000. Consociate paid $225,000. SG Health Plan paid $245,000.
All 4 investigations found the same failure. No accurate and thorough risk analysis. Every single one.
Not weak encryption. Not a missing firewall. The finding OCR reached in every one of those cases was that the organization had never properly assessed where its electronic patient data lived and what could go wrong with it. Our guide to the dental HIPAA security risk analysis covers what that document has to contain and why a vulnerability scan isn’t a substitute.
The dental compliance industry likes to claim that risk analysis failures are the most commonly cited deficiency in OCR enforcement actions against dental practices. Check the official resolution agreements list and that claim falls apart. Every published OCR action against a dental practice is a Privacy Rule matter. Gums Dental Care, $70,000, right of access. Three right of access settlements in September 2022. A social media disclosure in 2019. A disclosure settlement in December 2022.
Zero Security Rule cases against a dental practice. As of September 2026, that’s still true. It won’t hold.
It’s weaker comfort than it looks. The Security Rule penalties that have landed on small providers are the large ones, and dentistry’s absence from that record is a matter of timing rather than exemption.
The dental vendor breach that settles the BAA argument
In March 2026 the dental supply chain finally showed up in the enforcement record. Not in the way practices expect.
OCR settled with MMG Fusion, LLC, a Maryland software company that sells to oral healthcare providers, over a breach affecting roughly 15 million individuals. Dates matter more here than the dollar figure.
- December 2020. An unauthorized actor got into MMG’s systems and took names, phone numbers, mailing addresses, email addresses, dates of birth, and appointment dates and times.
- MMG never reported it.
- March 2023. OCR opened an investigation after receiving a complaint about an unreported incident and patient data appearing on the dark web.
- March 5, 2026. Settlement announced. MMG paid $10,000, a figure OCR reached after considering the company’s financial condition, plus a 3 year corrective action plan.
Part of that corrective action plan requires MMG to go back and, to the extent still possible, run a breach risk assessment of the December 2020 attack and tell the affected dental practices that their patients’ data was taken. More than 5 years after the fact.
A practice on the other end of that had patient records sitting on the dark web since 2020. Its breach notification clock under Texas law never started, because nobody told it anything. Its own security could have been flawless and the outcome would be identical. That’s the uncomfortable part.
OCR Director Paula M. Stannard put the duty plainly in the announcement, noting that business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery, because a covered entity can’t meet its own notification obligations otherwise.
A signed business associate agreement wouldn’t have stopped the breach. It does 2 other things. It creates a contractual notification duty you can actually enforce in court, and it’s the document that shows you exercised diligence over a vendor if an OCR investigator or a plaintiff’s lawyer later asks you to prove it. Practices running Dentrix, Eaglesoft, Open Dental, Curve, or Denticon typically touch 8 to 15 vendors that see patient data, counting imaging, recall messaging, claims clearinghouses, and payment processing. Very few have a current agreement with all of them. Some can’t produce a list. Ask yours.
Worth reading alongside this, our breakdown of what Dentrix, Eaglesoft, and Open Dental actually need from a server covers the other half of the vendor problem, which is what those platforms require of the practice.
The Texas training rule most compliance vendors still get wrong
Search for Texas HB 300 training requirements and you’ll be told that Texas covered entities must train staff at least once every 2 years. It’s on compliance vendor sites, in dental association explainers, and in a fair number of policy templates sold to practices.
It hasn’t been the law since 2013.
The biennial requirement was in the original 2011 bill. Senate Bill 1609 rewrote Section 181.101 in June 2013 and removed it. What the section requires now is different in shape and, in one respect, stricter.
- Training appropriate to each employee’s actual duties, not a generic module.
- Completed within 90 days of hire.
- Repeated within 1 year of any material change in state or federal law affecting that employee’s duties.
- A signed statement from each employee confirming completion, kept until the sixth anniversary of the signature.
That third bullet has a live clock attached to it. The proposed HIPAA Security Rule overhaul published in January 2025 would remove the distinction between required and addressable specifications, making nearly all of them mandatory with narrow exceptions. It’s still a proposal in September 2026. Not a final rule. When it does land, Section 181.101(c) starts a 1 year retraining obligation for every dental practice in Texas, automatically, whether or not anyone at the practice is watching the Federal Register.
That 6 year retention on signed statements is the sleeper. It’s a documentation duty most practices fail quietly. It also happens to be exactly the kind of dated evidence SB 2610 asks for.
What proof looks like when somebody finally asks
Every requirement above resolves into a document with a date on it, which is a less satisfying answer than a piece of software and a considerably more durable one.

SB 2610 asks a practice to demonstrate what existed at the time of the breach. OCR asks for the risk analysis and the risk management plan. The Texas AG asks when you knew and when you told people. All 3 questions arrive after the incident. Nothing can be created retroactively. That’s the design.
A Texas dental practice should be able to hand over all of the following inside a day.
- A dated risk analysis covering every system that touches patient data, including imaging, the practice management server, and anything cloud hosted.
- A risk management plan showing which findings were fixed, which were accepted, and when.
- Signed business associate agreements for every vendor with access, with dates.
- Signed training statements for each employee, filed and retained 6 years.
- Written policies matching what the practice actually does, not a purchased template naming another state.
- Evidence the controls ran, meaning backup restore tests, access reviews, and log retention rather than a screenshot of a dashboard.
- A named framework the program conforms to, and the date it was last realigned under Section 542.004(c).
Texas record retention stretches that timeline further than most practices plan for. Under 22 TAC Section 108.8, a dental record has to be kept 5 years from last treatment for an adult patient, and for a minor until age 21 or 5 years, whichever runs longer. A chart taken today can still be discoverable in 2045. The systems holding it will have been replaced 3 times by then, and the evidence has to survive every one of those migrations intact and readable.
What this costs to run
We publish our rates rather than quoting them after a discovery call. Fully managed IT runs $138 per user per month, co-managed is $100, and security augmentation for a practice that already has IT help is $40, all with a year one rate lock. No discovery call.
For a 7 person practice at the Texas average, fully managed lands near $966 a month. One number, both jobs. That covers the ordinary IT and the compliance layer together, because splitting them creates exactly the gap this article describes. If you’d rather think in chairs than seats, we converted those numbers in our guide to dental IT cost per operatory.
Worth saying plainly. A practice with a capable in-house IT person, a current risk analysis, and a real vendor register doesn’t need us for this. The practices that do are the ones where the last risk analysis is undated, or was done by the software vendor, or doesn’t exist at all.
What Texas dental practices ask about IT security
Does SB 2610 protect our practice if a patient sues us after a breach?
Partly. SB 2610 blocks exemplary damages only, and only if the practice proves a qualifying cybersecurity program was running at the time of the breach. Actual damages, notification costs, and OCR penalties are all untouched.
It’s a real protection with a narrow edge. Treat it as a reason to document the program you should already be running, not as insurance.
We have 11 employees. Is password policy and training genuinely all the statute asks for?
Under Section 542.004(a)(4)(A), yes, that’s the scale requirement for a business with fewer than 20 employees. But subsection (b)(2) still pulls full HIPAA in, because your practice is subject to it.
The light tier describes the scale. Not the substance. An 11 person practice still owes a complete HIPAA risk analysis.
Our practice management software is cloud based. Doesn’t that make security the vendor’s problem?
No. Moving to a cloud platform shifts where the data sits, not who’s accountable for it. The practice stays the covered entity, and the risk analysis still has to cover the cloud system.
MMG Fusion is the cautionary version. Practices using it did nothing wrong and still ended up with patient data on the dark web and no notification for 5 years.
How would we actually prove our program existed before a breach?
Dated artifacts, generated as you go. A risk analysis with a date, a risk management plan showing what got fixed and when, signed training statements, current business associate agreements, and logs showing the controls ran.
None of it can be produced after the fact. That’s the entire design of the statute.
Is the every 2 years HIPAA training rule still in effect in Texas?
It isn’t. Senate Bill 1609 removed the biennial training requirement from Section 181.101 in June 2013, though plenty of compliance vendors still publish it.
What applies now is training within 90 days of hire, retraining within a year of a material change in law, and a signed completion statement kept for 6 years.
What happens if one of our vendors gets breached and never tells us?
Your notification clock never starts, and you find out when somebody else does. That’s precisely what happened to MMG Fusion’s dental clients between 2020 and 2026.
A business associate owes notice within 60 calendar days of discovery. Enforcing that duty takes a signed agreement and a vendor list current enough to know who to chase.
Should we wait for the new HIPAA Security Rule before spending anything?
Waiting costs more than moving. The proposed rule would make currently addressable specifications mandatory, and every control it targets is already defensible under the existing rule.
The practices that struggle when it lands will be the ones starting from no risk analysis. That document is the prerequisite for everything else, and it takes the longest to build honestly.
Get the program documented before you need it
If your last risk analysis is undated, missing, or was run by the company that sold you your practice management software, that’s the place to start. We’ll tell you what’s actually missing rather than selling you a template.
Uprite completed a SOC 2 Type 1 examination in 2023 and supports dental practices across Houston, San Antonio, Dallas, and Fort Worth. See how we work with dental practices day to day, or talk to someone about an assessment.










