Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA compliance for optometry practices in Texas

Texas keeps obligations of its own alongside HIPAA, with different recipients and triggers from the federal rules. Beyond that, Texas has 3 recorded rules that apply to optometry practices differently from other businesses in the state — set out below with their conditions and sources.

Texas jurisdiction record verified against primary state authority August 2026. General reference, not legal advice.

Does this reach your practice?

Two questions have to be settled before any state rule matters: whether HIPAA reaches a practice like yours, and whether Texas's own law reaches a practice that HIPAA already covers.

Federal — is this practice a covered entity

Optometry practices that electronically conduct medical or vision-plan claims, eligibility, authorization, or other adopted transactions are HIPAA covered entities. The retail optical side does not erase the clinical entity's obligations. Once covered, the duties below are required.

State — how Texas law interacts with HIPAA

Texas substitutes federal notice for part of its scheme but keeps a residual state duty of its own. Optometry practices operating here should expect both a federal and a state obligation, with different recipients and triggers.

Chapter 521 applies alongside HIPAA. Compliance with one does not necessarily satisfy the other's timing, threshold, or regulator-notification requirements. Texas also maintains the Texas Medical Records Privacy Act (Tex. Health & Safety Code Ch. 181), which imposes additional state-law obligations on covered entities.

What Texas adds for optometry practices specifically

Rules that exist because of the combination — not federal HIPAA, which applies the same way everywhere, and not Texas's general breach law, which applies the same way to every business in the state.

Telehealth consent and privacy

Duty to keep an accurate record

The optometrist or therapeutic optometrist providing or facilitating the use of telehealth services shall ensure that the informed consent of the patient, or another appropriate individual authorized to make health care treatment decisions for the patient, is obtained BEFORE telehealth services are provided. A licensee shall MAINTAIN a patient’s informed consent IN THE PATIENT RECORD and, WHENEVER POSSIBLE, it shall be in writing. If the licensee must obtain the informed consent in an audio-only format, the licensee must document in the patient record the TIME AND DATE that the patient granted the consent.

Provider class
optometrists and therapeutic optometrists
Modality
telehealth services
Record class
informed consent to telehealth

What this means operationally

Read the codified text rather than the Board’s summary of it. The adoption preamble says consent “shall be in writing with exceptions for audio-only consent”, but the rule as codified makes only two things unconditional: consent must be obtained before the service, and it must be maintained in the patient record. The writing requirement is qualified by “whenever possible”. What the audio-only route costs is a specific record entry — the time and the date the consent was granted — so a practice taking consent by phone needs a timestamped chart note, not merely a note that consent was given.

Applies when

  • An optometrist or therapeutic optometrist provides or facilitates telehealth services

Exceptions

  • Where writing is not possible the consent may be taken audio-only, but the time and date must then be documented in the patient record
State regulation22 Tex. Admin. Code § 279.16(d)(2), (d)(2)(A)Telehealth patients, and authorized decision-makers acting for themVerified 2026-08-29

Duty to keep an accurate record

At a minimum, the informed consent must include: (i) the patient’s consent to treatment by the optometrist or therapeutic optometrist via telehealth services; (ii) the patient’s acknowledgement that the patient’s health data is being collected and shared using electronic and digital communication; and (iii) the patient’s acknowledgement of a POTENTIAL FOR BREACH OF CONFIDENTIALITY, or inadvertent access, of protected health information using electronic and digital communication in the provision of care.

Provider class
optometrists and therapeutic optometrists
Modality
telehealth services
Record class
informed consent to telehealth

What this means operationally

The third element is the one a generic telehealth consent form will not have. Texas requires the patient to acknowledge a potential for breach of confidentiality or inadvertent access to protected health information — an affirmative statement of risk, not a general privacy notice. A practice reusing an out-of-state or vendor-supplied consent should check for that clause specifically, because the first two elements are common and the third is not.

Applies when

  • Informed consent to optometric telehealth services is taken
State regulation22 Tex. Admin. Code § 279.16(d)(2)(B)Telehealth patientsVerified 2026-08-29

How long records must be kept

Duty to keep an accurate record

Unless previously provided, optometrists or therapeutic optometrists that communicate with patients by electronic communications OTHER THAN TELEPHONE OR FACSIMILE must provide patients with written notification of their privacy practices PRIOR TO evaluation or treatment, with a GOOD FAITH EFFORT to obtain the patient’s written acknowledgement, including by e-mail, of the notice. The notice of privacy practices shall include language that is consistent with federal standards under 45 C.F.R. Parts 160 and 164 relating to privacy of individually identifiable health information.

Provider class
optometrists and therapeutic optometrists
Modality
electronic communication other than telephone or facsimile
Record class
written acknowledgement of notice of privacy practices

What this means operationally

The trigger is the channel, not the service: it fires when the practice communicates with a patient electronically by anything other than telephone or fax, which reaches ordinary patient e-mail and portal messaging and not only formal telehealth encounters. Two limits are worth holding precisely. The notice must go out BEFORE evaluation or treatment, and the duty on the acknowledgement is a good-faith EFFORT to obtain it rather than a requirement to have it — so a documented attempt is the compliance artefact where the patient does not respond. E-mail acknowledgement is expressly sufficient.

Applies when

  • The practice communicates with a patient by electronic means other than telephone or facsimile, and the notice has not previously been provided

Exceptions

  • Not required where the notice was previously provided
State regulation22 Tex. Admin. Code § 279.16(d)(1)Patients communicating with the practice electronicallyVerified 2026-08-29

Each rule above was read against the cited source on the date shown. General reference for compliance planning, not legal advice — confirm current text before relying on it.

Texas breach obligations

These apply to businesses generally rather than to optometry practices in particular, and they are shown after applicability because whether they reach you depends on the answer above.

Texasbreach data →

Individual notice deadline

As quickly as possible and, unless certain law-enforcement or scope-determination exceptions apply, no later than 60 days after determining that the breach occurred.

The outer bound of 60 days aligns with HIPAA's 60-day individual-notice window in duration, but federal and state duties apply independently and may impose different content, recipient, or trigger requirements.

State regulator notice

Required at 250+ residents

The Attorney General must be notified when a breach involves at least 250 Texas residents. Notification is made through the online form maintained by the AG's office.

Source: Tex. Bus. & Com. Code § 521.053(b)

Statewide rules that also reach optometry practices

Minor may consent

Where the person with the right to consent cannot be contacted and has given no actual notice to the contrary, a grandparent, adult sibling, adult aunt or uncle, an educational institution the child attends holding written authorization, an adult with actual care, control and possession of the child holding written authorization, a court with jurisdiction over a suit affecting the parent-child relationship, an adult responsible for a child under juvenile court jurisdiction, or a peace officer who has lawfully taken custody and reasonably believes the minor needs immediate treatment, may consent to medical, dental, psychological and surgical treatment. That consent must be in writing, signed, and given to the practitioner or facility administering treatment, and must state the child's name, the parents' names if known along with any managing conservator or guardian, the consenting person's name and relationship to the child, the nature of the treatment, and the date treatment is to begin.

What this means operationally

Texas answers the personal-representative question with a ranked list and a document, which is unusually concrete. Two conditions do the work and both are easy to lose at the desk: the person with the right to consent must be uncontactable, and they must not have said no. So the record has to show the attempt to reach the parent, not merely the relative's signature. The five required contents of the form are a checklist a practice can actually hold itself to.

Applies when

  • The person with the right to consent cannot be contacted
  • That person has not given actual notice to the contrary
  • The consenting person falls within the enumerated list

Exceptions

  • The section does not apply to consent for the immunization of a child, which runs under § 32.101 instead
  • Consent for a child committed to the Texas Juvenile Justice Department, or for whom the Department of Family and Protective Services is managing conservator, is governed separately
StatewideTex. Fam. Code §§ 32.001, 32.002Children whose parent or guardian cannot be reachedVerified 2026-08-29

What applies to optometry practices everywhere

Optometry crosses clinical care, diagnostic imaging, insurance, prescription transmission, laboratory fulfillment, and retail operations. The SRA must follow patient information across all of those boundaries.

The EHR or practice-management system and access across clinical, optical, billing, and administrative roles
OCT, retinal photography, visual-field, corneal-topography, and other diagnostic systems
The movement and storage of diagnostic images between instruments, workstations, the EHR, specialists, and backup systems
Medical-insurance and vision-plan billing workflows, clearinghouses, and eligibility systems
Prescription transmission, optical-lab, specialty-lens, and fulfillment workflows involving identifiable patient information
Patient portals, scheduling, intake, email, text messaging, and order-status communication
Full optometristscompliance guide →

Knowing the Texas rule is not the same as meeting it.

The risk assessment asks what your practice actually does — which systems hold records, who reaches them, which vendors touch them — and reports against the obligations that apply to you, including the Texas rules on this page.

Start the risk assessment