Developments In Texas

Texas passed a law (H.B. 300) in the fall of 2011 that will take effect on September 1, 2012. The law imposes new employee training and notification obligations related to protected health information (PHI), exceeding the requirements of the HIPAA Privacy Rule. The law provides patients with increased rights and remedies over electronic health records, and increases penalties for non-compliance. Significantly, the law incorporates an expanded definition of the term "covered entity" in Texas's existing health privacy law, such that it could have a broad effect on many non-HIPAA-covered entities. The definition of "covered entity" under the law includes any entity that engages in assembling, collecting, analyzing, using, evaluating, storing or transmitting protected health information, as well as any entity that comes into possession or obtains or stores PHI.

The law also amends the existing breach notification law, Business & Commerce Code, Section 521.053, and purports to expand coverage to all citizens of the United States. In particular, the new law provides that if an entity conducting business in Texas suffers a...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT