Skip to main content

Texas SB 1188: The US-Only Health Record Storage Rule, Explained (2026)

By Joseph Abear ·
Banner reading Texas health records stay in the US: allowed in the United States or a US territory, not allowed offshore, and viewing from abroad still unsettled, from January 1, 2026

Last updated: September 23, 2026

Texas SB 1188 requires covered entities to keep electronic health records physically in the United States or a US territory. Texas SB 1188 (89th Legislature, 2025) added Chapter 183 to the Health and Safety Code. The storage rule has applied since January 1, 2026, to records of any age. It reaches records held by cloud providers and subcontractors. The Attorney General can seek civil penalties of up to $5,000, $25,000, or $250,000 per violation, depending on intent. We sell HIPAA compliant hosting, so weigh our advice accordingly. Statute quotes below were read on September 23, 2026.

TL;DR: Quick answer

  • Texas SB 1188 was signed June 20, 2025, and took effect September 1, 2025. The storage rule applies from January 1, 2026, to records of any age.

  • "Covered entity" comes from Health and Safety Code Section 181.001, which names "a business associate" and an "information or computer management entity". Section 183.001(2) excludes nursing facilities and assisted living.

  • The law targets where records are physically kept. The filed bill's offshore access ban was dropped before passage, and offshore viewing is still debated.

  • Section 183.011 caps civil penalties at $5,000, $25,000, or $250,000 per violation, depending on intent. Section 183.010 allows license discipline after three or more violations.

  • HIPAA has no data-location rule, and the Texas Data Privacy and Security Act exempts HIPAA entities and PHI. We found no agency rule or FAQ on Chapter 183 as of September 23, 2026.

What Texas SB 1188 requires: electronic health records stored in the United States

Quote of Texas Health and Safety Code section 183.002(a) requiring electronic health records to be physically maintained in the United States or a US territory, including third-party and cloud storage

The core rule is Section 183.002(a). Here it is in full, from the enrolled bill.

(a) A covered entity shall ensure that electronic health records under the control of the entity that contain patient information are physically maintained in the United States or a territory of the United States. This subsection applies to:

(1) electronic health records that are stored by a third-party or subcontracted computing facility or an entity that provides cloud computing services; and

(2) electronic health records that are stored using a technology through which patient information may be electronically retrieved, accessed, or transmitted.

Section 183.002(b) limits access to people whose job duties involve treatment, payment, or health care operations. It covers Texas residents' records "other than open data". Section 183.002(c) requires "reasonable and appropriate administrative, physical, and technical safeguards".

In plain English, Texas SB 1188 means every copy of a record you control must sit on hardware in the United States or a US territory. That includes copies a cloud host keeps. The required location is the United States, not Texas. One gap matters: Chapter 183 does not define "electronic health record" or "patient information".

Who Texas SB 1188 applies to

Chart of who the Texas health record storage law covers: practitioners, providers, payers, business associates, and out-of-state vendors; excluded long-term care groups; and the unclear question of direct vendor duties

Section 183.001(2) borrows "covered entity" from Section 181.001 and adds "a health care practitioner". The Texas definition is much wider than HIPAA's. Section 181.001(b)(2)(A) covers anyone engaged in "assembling, collecting, analyzing, using, evaluating, storing, or transmitting protected health information", paid or not.

Who

Status

Statutory basis

Health care practitioners licensed or authorized in Texas

Covered

Sec. 183.001(2) and (4)

Hospitals, clinics, providers, and payers

Covered

Sec. 181.001(b)(2)(A)

Business associates, computer management firms, website operators, and contractors that handle PHI

Covered on the face of the text

Sec. 181.001(b)(2)(A) and (D)

Out-of-state vendors holding Texas patients' records

Covered on the face of the text

Sec. 181.001(b)(2); no in-state limit in the definition

Nursing facilities, assisted living, home and community support agencies, and four other long-term care and waiver groups

Excluded

Sec. 183.001(2)(A) to (G)

Whether Chapter 183 binds a vendor directly or only through its client

Unclear

A legal question; no agency guidance found

Hosting companies, SaaS EHR vendors, and billing firms fit the words of Section 181.001 when they store PHI. Whether the Attorney General would pursue a vendor directly under Texas SB 1188 is unsettled. Billing and RCM vendors face this most often; see HIPAA compliant hosting for medical billing. Most of these vendors already sign a Business Associate Agreement under HIPAA. Texas SB 1188 adds a location duty. For the HIPAA side of your role, see who needs HIPAA compliant hosting.

Storage, not viewing: what changed between the filed bill and the law

Before and after comparison: the filed Texas bill banned access from outside the United States, while the enacted law limits access by job role with no location test, leaving offshore viewing unsettled

The version of Texas SB 1188 filed February 7, 2025, went further. Its Section 183.002(b) required records to be "inaccessible to any person located outside of the United States". The enrolled law replaced that with the role-based rule quoted above, which says nothing about geography.

The Senate Research Center's analysis, dated June 10, 2025, says records must be "stored physically within the U.S. and its territories". It adds that "those records may be accessible to physicians or other practitioners with reasonable safeguards". That is a staff summary, not law. Three law firms read the change differently.

  • Buchalter (Janice Suchyta, commentary, October 1, 2025) says offshore access is "somewhat more permissible, so long as data is not stored, cached, or copied offshore".

  • Hall Render (commentary, August 19, 2025) calls the law "ambiguous regarding whether the prohibition relates only to storage or would also apply to offshore view-only access".

  • Katten (Lisa Prather, commentary, September 18, 2025) says safeguards "would likely need to include system level restrictions on the downloading/copying of remotely accessed EHRs".

No agency or court had settled offshore viewing as of September 23, 2026. The safe design keeps every copy in the United States and blocks downloads and exports by offshore roles.

What counts as offshore storage of patient records?

Six places an offshore copy of patient records can hide: cross-Region backups, database replicas, CDN edge caches, logs and analytics, SaaS vendors, and offshore admin access

Because Section 183.002(a)(1) names cloud providers, the question under Texas SB 1188 is where every copy lands. AWS signs a BAA. It states: "We will not move or replicate your content outside of your chosen AWS Region(s), except as necessary to provide the services you initiated". Backups, replicas, and caches are services you initiate. For what the AWS BAA covers, see is AWS HIPAA compliant.

As of September 23, 2026, AWS lists six US Regions: four commercial Regions in Virginia, Ohio, Northern California, and Oregon, plus two GovCloud Regions. Copies outside them tend to appear here:

  • Cross-Region backups. AWS Backup lets you copy backups "to multiple AWS Regions", and the destination is your choice. Pick a second US Region and block others by written policy. See HIPAA backup and disaster recovery.

  • Database replicas and disaster recovery sites. A replica or standby in a Canadian or European Region is a stored copy.

  • CDN edge caches. CloudFront usually routes a request to "the nearest CloudFront POP in terms of latency" and caches the object there. A clinician abroad could leave a cached copy at a foreign edge. The statute is silent on short-lived caches; Buchalter's reading includes them. Send Cache-Control: no-store on PHI responses. We could not confirm a CloudFront setting that limits edges to the United States.

  • Log and analytics exports. Logs with names or record numbers are copies too. See HIPAA tracking technologies for the analytics side.

  • SaaS vendors and their subprocessors. An EHR add-on, billing tool, or AI scribe may keep data in its own cloud. Ask for its Regions in writing.

  • Offshore engineers with shell or database access. A database dump creates a copy wherever the engineer sits.

Texas SB 1188 deadlines and penalties

Table of Texas Chapter 183 dates and penalties: effective September 1, 2025, storage rule from January 1, 2026, fines up to $5,000, $25,000, or $250,000 per violation, and license discipline after three violations

The table follows the enrolled text of Texas SB 1188.

Item

What the text says

Source

Act takes effect

September 1, 2025

Act, Section 4

Storage rule

Applies to storage on or after January 1, 2026, no matter when the record was prepared

Act, Section 2(b)

Negligent violation

Up to $5,000 for each violation in a single year, however long it continues that year

Sec. 183.011(b)(1)

Knowing or intentional violation

Up to $25,000 for each violation in a single year

Sec. 183.011(b)(2)

PHI knowingly or intentionally used for financial gain

Up to $250,000 for each violation, with no single-year wording

Sec. 183.011(b)(3)

Injunction

The Attorney General may sue to stop a violation

Sec. 183.011(a)

License discipline

After three or more violations, up to suspension or revocation

Sec. 183.010

Aggregate annual cap

None; each cap applies per violation

Sec. 183.011(b)

Private right of action

None appears in the chapter

Chapter 183

Section 183.009 says HHSC or the right regulator "shall conduct an investigation of any credible allegation". Section 183.012 directs HHSC, the Texas Medical Board, and other regulators to sign a memorandum of understanding and adopt rules "as necessary". We found no such memorandum, rule, or FAQ as of September 23, 2026.

The other rules in Chapter 183

Texas SB 1188 does more than set a storage location. Section 183.004 bars storing a patient's credit score or voter registration status in the record. Section 183.005 lets practitioners use AI for diagnosis if they review AI-created records under Texas Medical Board standards and tell patients. Section 183.006 gives parents immediate access to a minor's record unless law or a court order restricts it. Sections 183.007 and 183.008 require a biological sex field and limit amendments to it.

How Texas SB 1188 fits with HIPAA and Texas privacy law

HIPAA has no data-location rule. HHS cloud guidance asks whether a cloud provider may store ePHI outside the United States. Its answer: "Yes, provided the covered entity (or business associate) enters into a business associate agreement (BAA) with the CSP". Texas SB 1188 removes that option for covered entities. The BAA is still required under 45 CFR § 164.308(b); see our HIPAA business associate agreement guide. Texas adds a location duty on top. If you run a site from outside the United States, the HIPAA side is covered in is HIPAA only for US sites.

The Texas Data Privacy and Security Act adds nothing here. Section 541.002(b)(3) exempts HIPAA covered entities and business associates, and Section 541.003 exempts PHI. On preemption, HIPAA overrides only state laws that are "contrary" to it under 45 CFR § 160.203. Our reading, not legal advice: you can follow both laws at once, so the storage rule is unlikely to be preempted.

What to check in your hosting and vendor contracts

Checklist of eight contract terms to get in writing from hosting and software vendors, from the primary Region and US-only backups to a dated inventory of every copy of patient records

Check these terms with every vendor that stores records. The list works for any HIPAA compliant cloud hosting provider you compare under Texas SB 1188.

  1. The primary Region, named in writing.

  2. Backup and replica Regions, plus a written policy that denies non-US destinations.

  3. CDN caching rules for PHI responses, such as no-store or no CDN on signed-in pages.

  4. The subprocessor list, with the country of each one.

  5. Offshore staff roles, and limits on downloads, exports, and database dumps.

  6. Storage statements from your SaaS EHR and add-on vendors, including AI and billing tools.

  7. BAA or data processing terms that add a US-only storage and backup clause.

  8. A dated inventory of where every copy sat on and after January 1, 2026.

Texas SB 1188 vs Florida 408.051

Comparison of the Texas and Florida health record location laws: where records may sit, who is covered, start dates, the Florida AHCA affidavit, and penalties

Florida passed a similar rule in 2023. Here is how the two compare.

Question

Texas SB 1188

Florida 408.051(3)

Where records may sit

The United States or a US territory

The continental United States, its territories, or Canada

What triggers the rule

Being a covered entity under Sec. 181.001, or a practitioner

A health care provider using certified EHR technology

Effective date

January 1, 2026 for storage

July 1, 2023

Attestation

None in the statute

AHCA licensees sign an affidavit at licensure and every renewal

Penalties

Civil penalties up to $5,000, $25,000, or $250,000 per violation; license discipline

No dollar amount in the section; AHCA fines and license discipline

A Canadian Region satisfies Florida but not Texas SB 1188. A vendor serving both states should keep every copy in US Regions.

If you want the location question answered in writing

We sell hosting, so weigh this section as a disclosure. Our managed HIPAA cloud hosting runs in US AWS Regions, and backups stay in US Regions. We put the Region and backup location in the BAA paperwork. The BAA is signed within 24 hours, and migration is included. We do not attest to Texas SB 1188 compliance for you; we give you the facts for your own inventory.

Here is the honest inverse. A nursing facility or assisted living facility is excluded by Section 183.001(2). A practice whose EHR vendor already attests to US-only storage and backups needs nothing new from us. For everyone else, our HIPAA compliant hosting plans are public. You can request a quote or ask us where your data sits today.

Frequently asked questions

Who does Texas SB 1188 apply to?

Texas SB 1188 applies to "covered entities" under Health and Safety Code Section 181.001, plus health care practitioners. That definition names business associates, computer management firms, and website operators. Section 183.001(2) excludes nursing facilities, assisted living, and some long-term care providers.

Does SB 1188 ban offshore access to medical records or only offshore storage?

The text requires physical storage in the United States. An earlier ban on offshore access was removed before passage. Law firms disagree on offshore viewing, and no agency had ruled as of September 23, 2026.

Does SB 1188 apply to records created before 2026?

Yes, for any storage on or after January 1, 2026. Section 2(b) of the Act applies the rule "regardless of the date on which the electronic health record was prepared".

What are the penalties under Texas SB 1188?

The Attorney General can seek up to $5,000 per negligent violation per year and $25,000 per knowing or intentional violation per year. The cap rises to $250,000 when PHI was knowingly or intentionally used for financial gain. Licensing agencies may discipline after three or more violations.

Does HIPAA already require health records to be stored in the United States?

No. HHS guidance allows a cloud provider that stores ePHI outside the United States if a BAA is in place. The location duty comes from Texas law.

Recap: Texas SB 1188

Texas SB 1188 requires covered entities to keep electronic health records physically in the United States or a US territory. Since January 1, 2026, it has reached records of any age, including cloud copies and backups. Offshore viewing under Texas SB 1188 is unsettled. Keep every copy in the US and put Regions in your contracts.

This article is general information, not legal advice. Statute and commentary as read on September 23, 2026; no agency rule or guidance was found. Confirm current law with counsel and the relevant Texas agency, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting. Reviewed September 2026.

Sources

Read full definition

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.