HIPAA is the floor in Texas, not the full stack
Texas clinics that treat HIPAA as the complete privacy rule set are leaving obligations on the table. The Texas Medical Records Privacy Act — commonly called HB 300 — builds on federal HIPAA with state-specific training, disclosure, and enforcement expectations that reach covered entities and many of the businesses that handle protected health information for them. If your practice operates in Texas, employs Texas staff, or uses a documentation vendor that processes Texas patient data, HB 300 belongs in the same conversation as your Business Associate Agreement. It is not a restatement of HIPAA in Texas stationery. It is a second layer with its own clocks, training duties, and penalties.
This article is a clinic-facing deep dive, not a repeat of the multi-state overview in our earlier privacy post. The goal is practical: what changes in how you train people, how you release records, how you evaluate an AI medical scribe or transcription partner, and what “U.S.-based processing” should mean in a Texas contract. Nothing here is legal advice. Your counsel should review how HB 300 applies to your entity type and your vendor stack. What follows is the checklist physicians and practice managers actually need when the binder still only cites 45 C.F.R.
Who HB 300 reaches beyond the obvious covered entity
Covered entities are the starting point, not the edge of the map. HB 300’s definitions and duties can pull in people and companies that create, receive, or maintain protected health information in the course of serving Texas patients — including documentation vendors, billing partners, and cloud tools that sit in the charting path. That matters when a clinic assumes “the EHR vendor handles privacy” and never asks where an ambient recording is transcribed, stored, or reviewed. If a scribe draft, dictation file, or finished note is PHI, the companies that touch it are part of your compliance picture whether or not they brand themselves as a healthcare company.
For multi-state groups with a Texas location, do not assume a California-tuned policy pack covers Austin. Training content, patient rights language, and vendor questionnaires should call out Texas explicitly. For a Texas-only independent practice, the risk is the opposite: copying a generic HIPAA policy from a national template and never mapping it to HB 300’s training and disclosure timelines. Either way, put the Texas state page and your vendor list in the same folder — our Texas medical transcription overview is a useful companion when you are inventorying who touches records for Lone Star patients.
Workforce training is a calendar item, not a one-time PDF
One of the clearest differences clinics feel on the ground is training cadence. HIPAA already expects workforce training appropriate to a person’s role. Texas adds sharper expectations around when employees who will handle PHI receive privacy training — including relative to hire — and how that training is documented. Practices that onboard a new medical assistant on Monday and “get to HIPAA training when there is time” are inventing risk. Build training into day-one access: no EHR login, no scribe portal, and no transcription upload rights until the Texas-aware module is complete and logged.
Training content should not stop at “do not gossip about patients.” Include how documentation tools work in your clinic: where ambient audio goes, who may listen to dictation, how corrections are requested, and what to do if a note appears on the wrong chart. Vendors can supply materials, but the clinic still owns the roster and the proof. When a surveyor or plaintiff asks who was trained and when, a signed BAA is not an answer. A dated training log tied to role-based access is. If you use temporary staff or locums, put them on the same clock — credentials without privacy training are unfinished onboarding.
Electronic records release timelines clinics actually miss
Patients and authorized requestors expect electronic copies on a predictable timeline. Texas rules around electronic health records access and release sit alongside HIPAA’s right of access, and clinics get into trouble when front-desk scripts still quote a single federal number while the state clock is shorter or more specific for electronic formats. Map your release desk to the stricter applicable timeline, not the one that feels familiar. Spell out who owns the queue when a request arrives Friday afternoon and who escalates when a vendor portal is the only place the note lives.
Documentation vendors affect this clock even when they never speak to patients. If signed notes sit in a transcription holding area or a scribe review queue that staff check twice a week, your “access” process is slower than your policy claims. Align filing SLAs with release SLAs. Overnight medical audio transcription that lands in the chart before the next clinic day is not only an operational convenience — it is how you keep release commitments honest when volume spikes. Measure time from signature to chart availability the same way you measure turnaround from dictation to draft.
Vendor questions that go past “Are you HIPAA compliant?”
Every documentation company will say yes to HIPAA. HB 300-aware due diligence asks narrower questions. Where is PHI stored and processed — which country, which region, which subprocessors? Who can listen to ambient audio or dictation files? How long are recordings retained, and who deletes them? What training do vendor staff complete before they see Texas patient data? Can they produce a written subprocessors list and a breach-notification contact that answers the phone? If the sales deck only offers a logo wall and a BAA PDF, keep asking until you get architecture answers.
“U.S.-based processing” should be a defined phrase in the contract, not a marketing adjective. Specify whether it means continental United States only, includes territories, allows remote workers abroad on U.S. servers, or permits offshore QA. Sunrise executes a BAA before PHI moves and keeps processing in the United States — put that same clarity in whatever vendor you choose. For AI scribes, add model-training language: whether your audio or notes may be used to improve models, and how opt-out works. Pair those answers with a technical review using the same lens as our Business Associate Agreement page and security architecture checklist.
How documentation workflows should change on Monday
Policy without workflow change is theater. On Monday, do three concrete things. First, freeze access provisioning until Texas-aware privacy training is logged. Second, rewrite the records-release script so electronic requests cite the timeline you can actually meet with your current filing SLA. Third, send every documentation vendor a one-page questionnaire covering storage location, subprocessors, audio retention, and workforce training — and set a date when non-responses lose PHI access. None of that requires a new EHR module. It requires naming owners.
If you are mid-rollout on an ambient scribe, pause wide deployment until consent language, retention settings, and Texas training are settled. Expanding a half-configured tool multiplies the number of people who can create a reportable problem. A short parallel trial on real encounters is still the right way to judge note quality — just run it inside a privacy-complete sandbox. Practices that treat compliance as a go-live gate, not a follow-up ticket, keep both their evenings and their enforcement risk under control.
Enforcement posture and why documentation quality still matters
State privacy enforcement is not abstract. Texas has pursued meaningful penalties when entities mishandle protected health information, and clinics should assume investigators will ask for policies, training logs, BAAs, and evidence of where data lived. Incomplete charts and loose vendor chains make those conversations worse. A clean note that was filed on time, created under a signed BAA, and handled by trained staff is easier to defend than a brilliant diagnosis buried in an unsigned inbox with an undocumented overseas QA step.
Documentation quality and privacy compliance share a spine: accountability. Who captured the visit, who drafted the note, who signed it, and who could access the audio along the way should be reconstructable. That is true for human transcription and for AI-assisted drafts. If your current stack cannot answer those questions for a single Tuesday encounter, HB 300 is not your only problem — your medical records process is underspecified. Fix the chain of custody and the clinical note usually gets sharper at the same time.