Texas SB 1188: The US-Only Health Record Storage Rule, Explained (2026)
HIPAA Compliant Hosting · https://hipaacomplianthosting.com/blog/texas-sb-1188-health-record-storage-rule
Last updated: September 23, 2026
Texas SB 1188 requires covered entities to keep electronic health records physically in the United States or a US territory. Texas SB 1188 (89th Legislature, 2025) added Chapter 183 to the Health and Safety Code. The storage rule has applied since January 1, 2026, to records of any age. It reaches records held by cloud providers and subcontractors. The Attorney General can seek civil penalties of up to $5,000, $25,000, or $250,000 per violation, depending on intent. We sell HIPAA compliant hosting, so weigh our advice accordingly. Statute quotes below were read on September 23, 2026.
TL;DR: Quick answer
Texas SB 1188 was signed June 20, 2025, and took effect September 1, 2025. The storage rule applies from January 1, 2026, to records of any age.
"Covered entity" comes from Health and Safety Code Section 181.001, which names "a business associate" and an "information or computer management entity". Section 183.001(2) excludes nursing facilities and assisted living.
The law targets where records are physically kept. The filed bill's offshore access ban was dropped before passage, and offshore viewing is still debated.
Section 183.011 caps civil penalties at $5,000, $25,000, or $250,000 per violation, depending on intent. Section 183.010 allows license discipline after three or more violations.
HIPAA has no data-location rule, and the Texas Data Privacy and Security Act exempts HIPAA entities and PHI. We found no agency rule or FAQ on Chapter 183 as of September 23, 2026.
What Texas SB 1188 requires: electronic health records stored in the United States

The core rule is Section 183.002(a). Here it is in full, from the enrolled bill.
(a) A covered entity shall ensure that electronic health records under the control of the entity that contain patient information are physically maintained in the United States or a territory of the United States. This subsection applies to:
(1) electronic health records that are stored by a third-party or subcontracted computing facility or an entity that provides cloud computing services; and
(2) electronic health records that are stored using a technology through which patient information may be electronically retrieved, accessed, or transmitted.
Section 183.002(b) limits access to people whose job duties involve treatment, payment, or health care operations. It covers Texas residents' records "other than open data". Section 183.002(c) requires "reasonable and appropriate administrative, physical, and technical safeguards".
In plain English, Texas SB 1188 means every copy of a record you control must sit on hardware in the United States or a US territory. That includes copies a cloud host keeps. The required location is the United States, not Texas. One gap matters: Chapter 183 does not define "electronic health record" or "patient information".
Who Texas SB 1188 applies to

Section 183.001(2) borrows "covered entity" from Section 181.001 and adds "a health care practitioner". The Texas definition is much wider than HIPAA's. Section 181.001(b)(2)(A) covers anyone engaged in "assembling, collecting, analyzing, using, evaluating, storing, or transmitting protected health information", paid or not.
Who | Status | Statutory basis |
|---|---|---|
Health care practitioners licensed or authorized in Texas | Covered | Sec. 183.001(2) and (4) |
Hospitals, clinics, providers, and payers | Covered | Sec. 181.001(b)(2)(A) |
Business associates, computer management firms, website operators, and contractors that handle PHI | Covered on the face of the text | Sec. 181.001(b)(2)(A) and (D) |
Out-of-state vendors holding Texas patients' records | Covered on the face of the text | Sec. 181.001(b)(2); no in-state limit in the definition |
Nursing facilities, assisted living, home and community support agencies, and four other long-term care and waiver groups | Excluded | Sec. 183.001(2)(A) to (G) |
Whether Chapter 183 binds a vendor directly or only through its client | Unclear | A legal question; no agency guidance found |
Hosting companies, SaaS EHR vendors, and billing firms fit the words of Section 181.001 when they store PHI. Whether the Attorney General would pursue a vendor directly under Texas SB 1188 is unsettled. Billing and RCM vendors face this most often; see HIPAA compliant hosting for medical billing. Most of these vendors already sign a Business Associate Agreement under HIPAA. Texas SB 1188 adds a location duty. For the HIPAA side of your role, see who needs HIPAA compliant hosting.
Storage, not viewing: what changed between the filed bill and the law

The version of Texas SB 1188 filed February 7, 2025, went further. Its Section 183.002(b) required records to be "inaccessible to any person located outside of the United States". The enrolled law replaced that with the role-based rule quoted above, which says nothing about geography.
The Senate Research Center's analysis, dated June 10, 2025, says records must be "stored physically within the U.S. and its territories". It adds that "those records may be accessible to physicians or other practitioners with reasonable safeguards". That is a staff summary, not law. Three law firms read the change differently.
Buchalter (Janice Suchyta, commentary, October 1, 2025) says offshore access is "somewhat more permissible, so long as data is not stored, cached, or copied offshore".
Hall Render (commentary, August 19, 2025) calls the law "ambiguous regarding whether the prohibition relates only to storage or would also apply to offshore view-only access".
Katten (Lisa Prather, commentary, September 18, 2025) says safeguards "would likely need to include system level restrictions on the downloading/copying of remotely accessed EHRs".
No agency or court had settled offshore viewing as of September 23, 2026. The safe design keeps every copy in the United States and blocks downloads and exports by offshore roles.
What counts as offshore storage of patient records?

Because Section 183.002(a)(1) names cloud providers, the question under Texas SB 1188 is where every copy lands. AWS signs a BAA. It states: "We will not move or replicate your content outside of your chosen AWS Region(s), except as necessary to provide the services you initiated". Backups, replicas, and caches are services you initiate. For what the AWS BAA covers, see is AWS HIPAA compliant.
As of September 23, 2026, AWS lists six US Regions: four commercial Regions in Virginia, Ohio, Northern California, and Oregon, plus two GovCloud Regions. Copies outside them tend to appear here:
Cross-Region backups. AWS Backup lets you copy backups "to multiple AWS Regions", and the destination is your choice. Pick a second US Region and block others by written policy. See HIPAA backup and disaster recovery.
Database replicas and disaster recovery sites. A replica or standby in a Canadian or European Region is a stored copy.
CDN edge caches. CloudFront usually routes a request to "the nearest CloudFront POP in terms of latency" and caches the object there. A clinician abroad could leave a cached copy at a foreign edge. The statute is silent on short-lived caches; Buchalter's reading includes them. Send Cache-Control: no-store on PHI responses. We could not confirm a CloudFront setting that limits edges to the United States.
Log and analytics exports. Logs with names or record numbers are copies too. See HIPAA tracking technologies for the analytics side.
SaaS vendors and their subprocessors. An EHR add-on, billing tool, or AI scribe may keep data in its own cloud. Ask for its Regions in writing.
Offshore engineers with shell or database access. A database dump creates a copy wherever the engineer sits.
Texas SB 1188 deadlines and penalties

The table follows the enrolled text of Texas SB 1188.
Item | What the text says | Source |
|---|---|---|
Act takes effect | September 1, 2025 | Act, Section 4 |
Storage rule | Applies to storage on or after January 1, 2026, no matter when the record was prepared | Act, Section 2(b) |
Negligent violation | Up to $5,000 for each violation in a single year, however long it continues that year | Sec. 183.011(b)(1) |
Knowing or intentional violation | Up to $25,000 for each violation in a single year | Sec. 183.011(b)(2) |
PHI knowingly or intentionally used for financial gain | Up to $250,000 for each violation, with no single-year wording | Sec. 183.011(b)(3) |
Injunction | The Attorney General may sue to stop a violation | Sec. 183.011(a) |
License discipline | After three or more violations, up to suspension or revocation | Sec. 183.010 |
Aggregate annual cap | None; each cap applies per violation | Sec. 183.011(b) |
Private right of action | None appears in the chapter | Chapter 183 |
Section 183.009 says HHSC or the right regulator "shall conduct an investigation of any credible allegation". Section 183.012 directs HHSC, the Texas Medical Board, and other regulators to sign a memorandum of understanding and adopt rules "as necessary". We found no such memorandum, rule, or FAQ as of September 23, 2026.
The other rules in Chapter 183
Texas SB 1188 does more than set a storage location. Section 183.004 bars storing a patient's credit score or voter registration status in the record. Section 183.005 lets practitioners use AI for diagnosis if they review AI-created records under Texas Medical Board standards and tell patients. Section 183.006 gives parents immediate access to a minor's record unless law or a court order restricts it. Sections 183.007 and 183.008 require a biological sex field and limit amendments to it.
How Texas SB 1188 fits with HIPAA and Texas privacy law
HIPAA has no data-location rule. HHS cloud guidance asks whether a cloud provider may store ePHI outside the United States. Its answer: "Yes, provided the covered entity (or business associate) enters into a business associate agreement (BAA) with the CSP". Texas SB 1188 removes that option for covered entities. The BAA is still required under 45 CFR § 164.308(b); see our HIPAA business associate agreement guide. Texas adds a location duty on top. If you run a site from outside the United States, the HIPAA side is covered in is HIPAA only for US sites.
The Texas Data Privacy and Security Act adds nothing here. Section 541.002(b)(3) exempts HIPAA covered entities and business associates, and Section 541.003 exempts PHI. On preemption, HIPAA overrides only state laws that are "contrary" to it under 45 CFR § 160.203. Our reading, not legal advice: you can follow both laws at once, so the storage rule is unlikely to be preempted.
What to check in your hosting and vendor contracts

Check these terms with every vendor that stores records. The list works for any HIPAA compliant cloud hosting provider you compare under Texas SB 1188.
The primary Region, named in writing.
Backup and replica Regions, plus a written policy that denies non-US destinations.
CDN caching rules for PHI responses, such as no-store or no CDN on signed-in pages.
The subprocessor list, with the country of each one.
Offshore staff roles, and limits on downloads, exports, and database dumps.
Storage statements from your SaaS EHR and add-on vendors, including AI and billing tools.
BAA or data processing terms that add a US-only storage and backup clause.
A dated inventory of where every copy sat on and after January 1, 2026.
Texas SB 1188 vs Florida 408.051

Florida passed a similar rule in 2023. Here is how the two compare.
Question | Texas SB 1188 | Florida 408.051(3) |
|---|---|---|
Where records may sit | The United States or a US territory | The continental United States, its territories, or Canada |
What triggers the rule | Being a covered entity under Sec. 181.001, or a practitioner | A health care provider using certified EHR technology |
Effective date | January 1, 2026 for storage | July 1, 2023 |
Attestation | None in the statute | AHCA licensees sign an affidavit at licensure and every renewal |
Penalties | Civil penalties up to $5,000, $25,000, or $250,000 per violation; license discipline | No dollar amount in the section; AHCA fines and license discipline |
A Canadian Region satisfies Florida but not Texas SB 1188. A vendor serving both states should keep every copy in US Regions.
If you want the location question answered in writing
We sell hosting, so weigh this section as a disclosure. Our managed HIPAA cloud hosting runs in US AWS Regions, and backups stay in US Regions. We put the Region and backup location in the BAA paperwork. The BAA is signed within 24 hours, and migration is included. We do not attest to Texas SB 1188 compliance for you; we give you the facts for your own inventory.
Here is the honest inverse. A nursing facility or assisted living facility is excluded by Section 183.001(2). A practice whose EHR vendor already attests to US-only storage and backups needs nothing new from us. For everyone else, our HIPAA compliant hosting plans are public. You can request a quote or ask us where your data sits today.
Frequently asked questions
Who does Texas SB 1188 apply to?
Texas SB 1188 applies to "covered entities" under Health and Safety Code Section 181.001, plus health care practitioners. That definition names business associates, computer management firms, and website operators. Section 183.001(2) excludes nursing facilities, assisted living, and some long-term care providers.
Does SB 1188 ban offshore access to medical records or only offshore storage?
The text requires physical storage in the United States. An earlier ban on offshore access was removed before passage. Law firms disagree on offshore viewing, and no agency had ruled as of September 23, 2026.
Does SB 1188 apply to records created before 2026?
Yes, for any storage on or after January 1, 2026. Section 2(b) of the Act applies the rule "regardless of the date on which the electronic health record was prepared".
What are the penalties under Texas SB 1188?
The Attorney General can seek up to $5,000 per negligent violation per year and $25,000 per knowing or intentional violation per year. The cap rises to $250,000 when PHI was knowingly or intentionally used for financial gain. Licensing agencies may discipline after three or more violations.
Does HIPAA already require health records to be stored in the United States?
No. HHS guidance allows a cloud provider that stores ePHI outside the United States if a BAA is in place. The location duty comes from Texas law.
Recap: Texas SB 1188
Texas SB 1188 requires covered entities to keep electronic health records physically in the United States or a US territory. Since January 1, 2026, it has reached records of any age, including cloud copies and backups. Offshore viewing under Texas SB 1188 is unsettled. Keep every copy in the US and put Regions in your contracts.
This article is general information, not legal advice. Statute and commentary as read on September 23, 2026; no agency rule or guidance was found. Confirm current law with counsel and the relevant Texas agency, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting. Reviewed September 2026.
Sources
Texas Legislature: SB 1188 enrolled text, SB 1188 introduced text, and bill history.
Senate Research Center: SB 1188 enrolled bill analysis, June 10, 2025.
Texas statutes (mirror): Health and Safety Code 181.001, Business and Commerce Code 541.002, and 541.003.
45 CFR § 160.203 (preemption): law.cornell.edu.
AWS: HIPAA compliance, Data Privacy FAQ, Regions, AWS Backup cross-Region copy, and How CloudFront delivers content.
Commentary: Buchalter, October 1, 2025, Hall Render, August 19, 2025, and Katten, September 18, 2025.