Texas House Bill 300 is a 2011 Texas law that amended the Texas Medical Records Privacy Act in the Texas Health and Safety Code to expand privacy and security obligations for protected health information, add Texas-specific requirements for electronic disclosures and patient access to electronic records, require workforce training, and strengthen enforcement tools and penalty authority.
Texas House Bill 300 operates through Chapter 181 of the Texas Health and Safety Code and applies state medical privacy obligations in addition to federal HIPAA obligations for regulated organizations. The law also directs the Attorney General to maintain a consumer website describing privacy rights and listing state agencies and complaint processes for reported violations.
Covered Entity Scope Under Texas Law
Texas House Bill 300 strengthened an existing Texas framework that extends beyond the narrower set of HIPAA Covered Entities by using a Texas “covered entity” concept tied to Chapter 181 requirements while also requiring HIPAA-defined covered entities to comply with HIPAA privacy standards. This structure creates overlapping compliance duties for organizations that handle protected health information about Texas residents and operate in Texas-regulated healthcare contexts.
Electronic Records Access Requirements
Texas House Bill 300 added a Texas timeline for access to electronic health records when a provider uses an electronic health records system capable of producing the requested record, requiring production in electronic form within 15 business days after receiving a written request, subject to HIPAA access exceptions and denial grounds.
Electronic Disclosure Authorization Requirements
Texas House Bill 300 addressed authorizations for certain electronic disclosures of protected health information and directs the Attorney General to adopt a standard authorization form for use in complying with the Texas authorization requirement. This Texas authorization structure functions alongside the HIPAA Privacy Rule authorization framework and should be reflected in disclosure workflows and authorization management controls for covered Texas activity.
Enforcement and Penalty Structure
Texas House Bill 300 strengthened state enforcement tools by expanding the Attorney General’s civil penalty authority under Chapter 181 and increasing the annual civil penalty cap for violations that occur with a frequency that constitutes a pattern or practice. The law also ties disciplinary exposure to state licensing agencies for licensed covered entities when violations trigger investigation and disciplinary proceedings under state oversight.
Texas HB 300 Training Requirements
Texas House Bill 300 requires covered entities to provide workforce training on state and federal law concerning protected health information as it relates to the entity’s course of business and the employee’s scope of employment, with completion required within 60 days of hire and refresher training required at least once every two years. The covered entity must also require an employee attestation of attendance and maintain the signed verification as a compliance record.
Texas workforce training programs in Texas need to cover state privacy, security, breach notification, and professional confidentiality requirements that apply alongside HIPAA and the Texas Medical Records Privacy Act as amended by Texas HB 300, because staff workflows can trigger obligations under more than one legal framework during routine access, disclosure, incident response, and technology use.
Training content for these overlapping obligations needs to address the Texas Identity Theft Enforcement and Protection Act, the Texas Data Privacy and Security Act, the Texas Responsible AI Governance Act, Texas SB 1188, and the Texas Medical Practice Act when those laws affect the organization’s collection, use, disclosure, safeguarding, and breach response duties. Training needs to align to staff roles and include practical procedures for consent and authorization management, patient access requests, minimum necessary disclosures, incident identification and escalation, state-specific breach notification triggers, and controls for electronic health records and any use of artificial intelligence in clinical or administrative workflows.
