State Breach Laws: Why Oklahoma and Texas Operators Should Check Both

When a healthcare organization suffers a data breach, the conversation usually starts and ends with HIPAA. That is understandable, since the HIPAA Breach Notification Rule is well known. But it is not the only law that may apply. States have their own breach notification statutes, and operators that serve residents or employees across state lines may owe notices under more than one.

This post gives general orientation for Oklahoma and Texas operators. It is not legal advice, and the details change, so involve qualified counsel as soon as an incident is suspected.

HIPAA is the floor, not the ceiling

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, HHS and, in larger breaches, the media when unsecured protected health information is compromised. Business associates have duties to notify the covered entity.

State laws operate separately. They may:

Cover different kinds of information, such as Social Security numbers, financial account numbers or driver's license numbers, whether or not they are part of a medical record

Apply to employee data, which HIPAA generally does not treat as protected health information in the employer role

Set different deadlines for notification

Require notice to a state attorney general or other regulator

Specify content or method for the notice

Have their own exemptions, including for entities that follow federal rules, which may or may not fully apply

Complying with HIPAA does not automatically satisfy every state requirement.

Why Oklahoma and Texas operators should look at both

Many operators in the region have employees, residents or family members who live in neighboring states. A facility in Oklahoma may have staff living in Texas or Arkansas. A company with buildings in several states may hold records on people in each. State breach laws typically apply based on where the affected individual lives, not just where your headquarters sits. That means one incident can trigger obligations in multiple states.

Both Oklahoma and Texas have their own breach notification statutes, and Texas also has additional medical privacy requirements. Rather than rely on a summary, ask counsel to confirm the current requirements for every state where affected people live, including deadlines and any regulator notice thresholds.

Questions to ask your attorney

Prepare to discuss these early in an incident:

Which state laws apply, given where the affected individuals reside?

What types of data were involved, and does each law cover them?

What are the notification deadlines, and when does the clock start?

Do we need to notify a state attorney general or other agency, and under what conditions?

Are there exemptions for encrypted data or for organizations that follow federal rules?

What must the notice say, and how must it be delivered?

Do we owe notice to credit reporting agencies?

How do contractual duties, such as obligations to business partners and insurers, fit in?

Get ready before an incident

Preparation makes a stressful week more manageable.

Know what data you hold

Maintain an inventory of where personal information lives, including systems, cloud services and paper records, and which populations it covers: residents, families, employees, applicants and vendors.

Include state law in your response plan

Add a one-page reference listing the states in which you have people, the contact for your counsel and a reminder to check each state's requirements. Have counsel review it annually.

Review contracts and insurance

Your cyber insurance policy may require notice to the carrier within a short time and use of approved response firms. Customer and partner contracts may carry their own notice duties.

Keep evidence

Document what you know and when you learned it. Dates matter for deadlines, and logs and timelines help counsel determine who must be notified.

Do not wait for certainty

Because deadlines can start when you discover a breach, or reasonably should have, it is wise to contact counsel and your insurer quickly rather than waiting until the investigation is complete.

UnityCare IT supports healthcare operators with the technical side of incident response, including preserving logs and building the timeline your attorney needs, while leaving the legal determinations to your counsel.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172