Texas Compliance8 min read

Texas HB 300: What It Requires of Medical Couriers

August 27, 2026 · By LabPath Logistics Editorial Team, Medical Logistics Desk

Checklist diagram of the five Texas HB 300 obligations that land on a medical courier — a covered-entity definition broader than HIPAA's, training completed within 90 days of hire, signed training statements retained six years, individual breach notice within 60 days, and attorney general notice once 250 Texas residents are affected — attributed to Health and Safety Code Chapter 181

Quick Answer

Texas HB 300 amended the Texas Medical Records Privacy Act — Health and Safety Code Chapter 181 — to define "covered entity" far more broadly than HIPAA does. Under §181.001(b)(2), the term reaches any person who "comes into possession of protected health information," which means a medical courier carrying a requisition form, a labeled specimen bag, or a paper chart is a covered entity under Texas law in its own right, not merely a business associate of one. That status carries its own training deadlines, its own recordkeeping duty, and civil penalties that reach $250,000 per violation when protected health information is used for financial gain.

Most Houston courier contracts are negotiated against HIPAA and stop there. Texas HB 300 is the part nobody reads, and it is the part that changes who is on the hook. Under Texas law a medical courier that handles protected health information is not a downstream vendor of a covered entity — it is a covered entity, with its own training file to maintain and its own clock to run when something goes missing.

The distinction is invisible until the day it matters. The federal question after an incident is whether a business associate agreement was in place and what it assigned to whom. The Texas question is blunter: did protected health information end up in someone's possession, and did that person's employer do what Chapter 181 requires? A signed BAA does not answer the second question.

HIPAA Asks What You Are. Texas Asks What You Held.

HIPAA works by category. It applies to health plans, clearinghouses, and providers who transmit certain transactions electronically, and it reaches everyone else through the business associate chain. If you are not in one of those boxes, the federal rule reaches you only by contract.

Chapter 181 works by conduct. HB 300, passed in 2011, rewrote the Texas Medical Records Privacy Act so that a "covered entity" includes any person who "comes into possession of protected health information", along with anyone who assembles, collects, analyzes, uses, evaluates, stores, or transmits it. The same subsection extends the status to an "employee, agent, or contractor" of such a person insofar as they create, receive, obtain, maintain, use, or transmit PHI.

Read that against a courier route. A driver who accepts a specimen bag with a requisition clipped to it has come into possession of protected health information. So has the dispatcher who reads a manifest with patient names on it. Neither needed a contract to acquire the obligation — under Texas law the possession created it.

A BAA allocates duties. It does not replace them.

A business associate agreement is an arrangement between two parties about how federal obligations are handled. Chapter 181 imposes state obligations directly on each party that possesses the information. Signing a BAA does not move a Texas courier out of Chapter 181's definition, and a courier that has never signed one is not outside it either.

The Obligations That Actually Land on a Courier

Four requirements do most of the work, and all four are auditable from the outside — which is exactly why they belong in a vendor review rather than a legal memo.

  1. Training on state and federal PHI law, appropriate to the employee's duties. Under §181.101 an employee must complete it "not later than the 90th day after the date the employee is hired."
  2. A signed verification of that training — electronic or written — which the entity must keep "until the sixth anniversary of the date the statement is signed."
  3. Retraining after a material change in law, delivered within a reasonable period and no later than the first anniversary of the date the change takes effect.
  4. Breach notification on the Texas clock, which runs separately from the federal one and is shorter in one direction than most operators expect.

That last item deserves precision, because two different statutes are involved and they cover different things. Texas Business and Commerce Code §521.053 governs breaches of computerized data: affected individuals must be notified "without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred," and if at least 250 Texas residents are affected, the attorney general must be notified "as soon as practicable and not later than the 30th day." Since House Bill 3746 took effect in 2021, the attorney general also maintains a public listing of those reports.

For a courier, §521.053 is about the tracking platform, the proof-of-delivery database, and the driver app — not the paper in the bag. A lost manifest is a Chapter 181 and HIPAA problem; a compromised dispatch system is all three. Knowing which statute a given failure triggers is the difference between a 30-day obligation and a missed one.

$250,000

Maximum civil penalty per violation under Tex. Health & Safety Code §181.201 where a covered entity knowingly or intentionally used protected health information for financial gain. Negligent violations carry $5,000 each and knowing or intentional violations $25,000 each; conduct found to be a pattern or practice may be assessed up to $1.5 million annually.

Where a Courier Actually Touches PHI

The specimen itself is rarely the exposure. The paperwork traveling with it almost always is. In practice, protected health information enters a courier operation through five doors:

  • Requisition forms clipped to or bagged with the specimen, carrying name, date of birth, diagnosis codes, and ordering physician.
  • Printed route manifests that list patient names alongside stop addresses.
  • Specimen labels legible through a transparent biohazard bag while it sits on a seat or a dock.
  • Paper charts, consent packets, and imaging media moved between a clinic and a hospital campus.
  • A driver's phone photo of a label or form, kept as informal proof of pickup and never deleted.

The fifth is the one that shows up in incident reviews. It is well intentioned, it is undocumented, it lives on a personal device outside any retention schedule, and it converts a compliant handoff into an uncontrolled copy of PHI. A written rule against it costs nothing and is worth asking for by name.

Picture a route that runs a Texas Medical Center reference lab, two Katy clinics, and a Pearland satellite on the same afternoon loop. Every stop adds paperwork to the same vehicle. A manifest left face-up on a passenger seat during a 20-minute stop is not a hypothetical failure mode — it is the ordinary shape of one.

5.6%

Share of large healthcare data breaches reported in 2025 in which physical protected health information — paper and films — was compromised, per the HIPAA Journal 2025 Healthcare Data Breach Report; 128 of the year's breaches were reported by business associates of HIPAA-covered entities.

Physical PHI is a small slice of the national total and a disproportionate slice of courier risk, because paper is most of what a courier carries. Hardening a dispatch database does nothing for a form on a clipboard.

The Cheapest Compliance Is Not Carrying the Data

A logistics record does not need patient identity to do its job. It needs to prove that a defined item moved from a defined origin to a defined destination, in a defined temperature state, at defined times, in defined hands. Accession numbers and opaque identifiers carry all of that. Names carry none of it.

That is the design decision behind our platform: no patient data in the courier record, by design. Scans resolve to an opaque identifier, and the timestamped custody trail records item, time, temperature state, and person — not who the patient is. It is a narrower attack surface and a narrower breach-notification exposure, because there is less to lose.

It is not a complete answer, and claiming otherwise would be dishonest. The requisition in the bag is still PHI, and the courier still possesses it. Minimization complements access control, training, agreements, and incident response — it does not replace them. What the design does is separate the two problems: the paper is controlled by sealed transfer and handling rules, and the electronic record does not become a second copy of the patient's identity. Our approach to HIPAA-aligned courier operations covers the federal half of that; Chapter 181 is the half specific to operating in Texas.

What to Verify Before You Sign

Every item below is a document the courier either has or does not have. Ask for the artifact, not the assurance — the same standard we apply to chain of custody records:

  • A per-driver training file with signed completion statements, retained six years, dated within 90 days of each hire.
  • A named owner for the Texas breach clock and a written path to attorney general notice within 30 days at the 250-resident threshold.
  • A written prohibition on photographing labels, requisitions, or manifests with personal devices.
  • A plain answer to whether the courier's own electronic record contains patient identifiers at all.
  • A sealed-transfer rule for paperwork riding with specimens, with the seal recorded at both ends.

If a vendor cannot produce the training file, the rest of the conversation is theoretical. It is the single fastest test of whether a courier understands that Texas law applies to it directly. You can see how we document ours on our compliance page.

Key Takeaway

HB 300 did not create a new burden so much as it removed a hiding place. In Texas, the obligation attaches to possession, which means every party that touches a requisition form owns a piece of it — the clinic, the lab, and the courier between them. Write the training file, the device rule, and the 30-day attorney general path into the contract, and then ask the better question: does this record need to contain a patient's name at all? Most of the time, the honest answer is no.

Frequently Asked Questions

Does Texas HB 300 apply to medical couriers?

Yes. Texas Health and Safety Code §181.001(b)(2) defines a covered entity to include any person who comes into possession of protected health information, and extends that status to their employees, agents, and contractors. A courier that transports requisition forms, labeled specimens, or paper charts meets that definition directly, independent of whether it has signed a business associate agreement. HIPAA reaches couriers through the business associate chain; Texas law reaches them through possession.

What training does HB 300 require, and how fast?

Chapter 181 §181.101 requires a covered entity to train employees on state and federal law concerning protected health information, appropriate to their duties, with completion no later than the 90th day after hire. The employee must sign a statement verifying completion — electronically or in writing — and the entity must retain that statement until the sixth anniversary of the signing date. Material changes in law trigger retraining within a reasonable period and no later than the first anniversary of the change taking effect.

How fast must a Texas breach be reported?

Under Texas Business and Commerce Code §521.053, affected individuals must be notified without unreasonable delay and no later than the 60th day after the breach is determined to have occurred. If at least 250 Texas residents are affected, the attorney general must be notified as soon as practicable and no later than the 30th day, using the electronic form on the attorney general's website. Since 2021 the attorney general has also maintained a public listing of those reports. Note that §521.053 governs computerized data — a lost paper manifest is analyzed under HIPAA and Chapter 181 instead.

What are the penalties under the Texas Medical Records Privacy Act?

Section 181.201 sets civil penalties of $5,000 per violation committed negligently, $25,000 per violation committed knowingly or intentionally, and $250,000 per violation where a covered entity knowingly or intentionally used protected health information for financial gain. Conduct that constitutes a pattern or practice may be assessed up to $1.5 million annually. These run alongside federal HIPAA enforcement rather than in place of it.

#Texas-HB-300-medical-courier#Texas-Medical-Records-Privacy-Act#HB-300-compliance-Houston#PHI-in-transit-Texas#Texas-healthcare-breach-notification

Ask your courier for the Texas file, not the assurance

LabPath Logistics operates in Houston on the assumption that Chapter 181 applies to us directly, because it does. Our custody record is built around opaque identifiers rather than patient identity — no patient data in the courier record, by design — and role-appropriate training, signed evidence, and the Business Associate Agreement are verified and retained before a facility goes live, not after. We publish what is live and what is still a release gate on our compliance page rather than claiming a credential no agency issues. Send us your current courier agreement and we will show you which of the five artifacts above it is missing.

Onboard Your Facility