Texas · TDPSA

Texas privacy law, explained for practice owners

No threshold. Small businesses exempt — except for section 541.107.

Exempt in general — one rule survives In effect since July 1, 2024 HIPAA exemption: entity-level Reviewed July 25, 2026

The short answer

Texas has no volume threshold. It exempts HIPAA covered entities at the entity level and SBA-defined small businesses generally — but § 541.107 survives the small-business exemption, and § 541.107 says you may not sell sensitive personal data without prior consent. Health diagnosis data is sensitive data. Texas defines “sale” to include exchanges for other valuable consideration. So the one obligation Texas kept applicable to small businesses is the one an advertising pixel on a treatment page is most likely to trigger. Add the most active privacy enforcement office in the country, and Texas deserves more attention than its $7,500 penalty ceiling suggests.

In effect sinceJuly 1, 2024
Applies atNo volume threshold —
SBA small-business test
Max penaltyUp to $7,500
per violation
Cure period30 days
(no sunset)

The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.

Scope

Does TDPSA actually apply to your practice?

Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.

1

Are you a HIPAA covered entity?

If yes, TDPSA does not apply to you at all — Texas exempts covered entities and business associates at the entity level, not just their patient records.

If you have never had that determination made in writing, treat it as unanswered. A provider who never transmits a HIPAA standard transaction electronically may not be a covered entity.

2

If not, do you cross the threshold?

Without the entity-level exemption, the applicability test is the only thing between you and the statute. No volume threshold — SBA small-business test.

Count website visitors, not just patients. Personal data includes the identifiers your site collects.

3

Either way, three things still bind you

HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.

No state privacy exemption reaches any of those three.

Reference

Texas privacy law: the key facts

Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code § 541.001 et seq.. Last reviewed July 25, 2026 against the statute text and the enforcing agency's own material.
LawTexas Data Privacy and Security Act (TDPSA)
CitationTex. Bus. & Com. Code § 541.001 et seq.
EffectiveJuly 1, 2024
No volume threshold. The Attorney General has built a dedicated data privacy enforcement team and has been the most active state privacy enforcer in the country.
Who enforces itAttorney General, Consumer Protection Division (dedicated data privacy team)
Applicability

Texas threw out volume thresholds. The TDPSA applies to a person that:

  • conducts business in Texas or produces a product or service consumed by Texas residents;
  • processes or engages in the sale of personal data; and
  • is not a small business as defined by the US Small Business Administration — except to the extent that § 541.107 applies.

That final clause is the whole page. The SBA definition commonly means fewer than 500 employees and covers nearly every independent practice — but § 541.107 survives the exemption, and § 541.107 is about sensitive data.

HIPAA exemption

Entity-level — a HIPAA covered entity is outside the statute

Texas exempts HIPAA covered entities and business associates at the entity level, along with PHI, HIPAA de-identified data, and information used for public health activities.

So most practices have two independent shelters in Texas: covered-entity status and small-business status. Neither one covers the sensitive-data sale provision — the entity exemption does, but only if you are actually a covered entity, and the small-business exemption expressly does not.

Sensitive data

Sensitive data requires opt-in consent, and the category includes personal data revealing mental or physical health diagnosis, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and personal data of a known child.

And § 541.107 is the provision that survives the small-business exemption: a person may not engage in the sale of sensitive personal data without receiving prior consent from the consumer. Small business or not.

Definition of “sale”

Broad — monetary or other valuable consideration

Texas uses the broad definition: sharing personal data for monetary or other valuable consideration is a sale. This is what makes § 541.107 live for a medical website — an advertising platform receiving visitor data in exchange for better targeting is the paradigm case of other valuable consideration.

Universal opt-out / GPC

Yes. Texas has required controllers to recognize a universal opt-out mechanism since January 1, 2025.

Consumer rights
  • Access, correction, deletion, and portability
  • Opt out of sale, targeted advertising, and consequential profiling
  • Consent required before processing sensitive data
  • Appeal a denied request, with escalation to the Attorney General
  • For exempt small businesses: § 541.107's sensitive-data sale consent requirement still applies
Cure period

Texas provides a 30-day cure period with no expiration. The Attorney General must give written notice specifying the alleged violations and allow thirty days to cure before filing suit.

This is a real protection, and the Texas AG has used the notice mechanism actively — which means the notices go out, and they go out to businesses that assumed nobody was looking.

Penalties

Up to $7,500 per violation, plus injunctive relief, attorney fees, investigative costs, and the possibility of court-ordered compliance programs. Available after the 30-day cure window closes.

Private right of action

No private right of action. Exclusive enforcement by the Texas Attorney General — which, in Texas, is not the relief it is elsewhere.

What it means for you

The parts that actually change how you operate

Section 541.107 is the entire Texas question for most practices

Texas's applicability section does something unusual. It excludes small businesses, and then it adds five words: except to the extent that Section 541.107 applies.

Section 541.107 reads, in substance: a person may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer.

So the structure is: almost nothing in the TDPSA applies to a small practice, and the one thing that does is a consent requirement on selling sensitive data. Now assemble the three definitions:

  • Sensitive data includes personal data revealing a mental or physical health diagnosis.
  • Sale includes sharing for monetary or other valuable consideration.
  • An advertising pixel on a treatment page shares visitor identifiers with a platform, in exchange for improved targeting.

Whether a specific tag on a specific page crosses that line depends on what it actually transmits, and that is a question for counsel reviewing your real configuration. But the design intent is not subtle. Of everything Texas could have preserved against the small-business exemption, it preserved the provision that maps onto healthcare digital advertising.

Texas enforces. That is the part that makes it different.

Most state privacy laws are, so far, more risk than event. Texas is the exception. The Attorney General's office established a dedicated team within the Consumer Protection Division focused specifically on data privacy and security enforcement, publicized the initiative, and has pursued significant matters since.

Two consequences for a practice. First, the 30-day cure notice is not hypothetical — Texas sends them. Second, the office has signalled its priorities publicly, and sensitive data handling is high on the list.

A permanent cure period plus an active enforcer is actually a workable combination for an operator who is paying attention: you get notice, and thirty days is enough to fix a tag configuration. It is a bad combination for one who is not, because the notice arrives and the clock runs whether or not anyone opens the envelope.

Covered-entity status is the stronger card here too

The entity-level HIPAA exemption covers the whole statute, § 541.107 included. The small-business exemption does not. So in Texas, as in Nebraska and Minnesota, your covered-entity determination is worth more than your size.

And it is the determination most practices have never actually made. A HIPAA covered entity is a health plan, a healthcare clearinghouse, or a provider that transmits health information electronically in connection with a HIPAA standard transaction. Cash-pay practices — aesthetics, hair restoration, elective and cosmetic procedures, wellness and weight management — frequently do not meet that last test, and would be relying entirely on a small-business exemption with a health-data hole in it.

Texas added an AI statute for 2026

House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, took effect January 1, 2026. It is not a privacy statute, but it reaches practices deploying AI-driven tools in ways that affect consumers, and it is enforced by the same Attorney General's office that runs TDPSA enforcement.

If you are using automated intake triage, AI scheduling, or algorithmic lead scoring, this belongs on your counsel's list alongside the privacy analysis.

Where the risk lives

Your website is the exposed surface, not your chart system

Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.

Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.

That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.

What a regulator or a plaintiff can check without asking you anything

  • Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
  • Whether your site responds to a Global Privacy Control signal.
  • Whether the opt-out your privacy policy describes actually exists and actually works.
  • Whether your privacy policy's claims match your site's behavior.

All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.

The federal floor, stated accurately

HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.

What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.

Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.

Consequences

What it costs when it goes wrong in Texas

Up to $7,500 per violation, plus injunctive relief, attorney fees, investigative costs, and the possibility of court-ordered compliance programs. Available after the 30-day cure window closes.

The arithmetic nobody puts in a proposal

Texas's per-violation figure is unremarkable. Its enforcement volume is not. The Texas Attorney General stood up a dedicated data privacy and security enforcement team inside the Consumer Protection Division and has pursued high-profile matters at a pace no other state has matched.

Which changes the calculation in a specific way: in most states you are modeling penalty exposure against a low probability of enforcement. In Texas you are modeling it against an office that is actively looking.

“We're a small business” is the answer to the wrong question

Texas's small-business exemption is real and it removes almost every obligation. It does not remove § 541.107, and § 541.107 is the provision most likely to be triggered by the advertising tags on a medical website.

An owner who confirms small-business status and stops has verified the exemption while skipping the carve-back that was written specifically to survive it.

Do this

Your Texas action list

In order. Items one and two are the ones that change your answer to everything else.

  1. Read § 541.107 directly. It is short, it survives the small-business exemption, and it is the operative Texas rule for most practices.
  2. Confirm your HIPAA covered-entity status in writing — it is the only exemption that covers § 541.107 too.
  3. Confirm your SBA small-business status by NAICS code; the definition is industry-specific.
  4. Get prior consent before any transfer of health-revealing data to a third party for advertising value.
  5. Honor universal opt-out signals; required since January 1, 2025.
  6. Make sure legal notices reach a human within days — the 30-day cure clock starts when Texas sends, not when you read.
  7. Keep timestamped consent records. “Prior consent” is a factual claim you have to be able to evidence.
  8. If you use AI-driven intake, scheduling, or scoring tools, add HB 149 to your counsel's review.

Questions

Texas privacy law FAQ

Does the Texas Data Privacy and Security Act have a threshold?

No volume threshold. It applies to any person doing business in Texas or serving Texas residents that processes or sells personal data and is not an SBA-defined small business — except that § 541.107 applies to small businesses too.

Are small businesses exempt from the TDPSA?

Largely, but § 541.107 survives the exemption. A small business may not engage in the sale of personal data that is sensitive data without prior consent from the consumer. For medical practices this is the most relevant provision in the statute, because health diagnosis data is sensitive data and Texas defines “sale” to include exchanges for other valuable consideration.

Are HIPAA covered entities exempt in Texas?

Yes, at the entity level, and that exemption covers the whole statute including § 541.107 — unlike the small-business exemption. This makes covered-entity status the stronger protection in Texas.

Does Texas have a cure period?

Yes, 30 days after written notice from the Attorney General specifying the alleged violations, with no sunset. The Texas AG uses this notice mechanism actively.

Who enforces the Texas privacy law?

The Texas Attorney General's Consumer Protection Division, which has established a dedicated data privacy and security enforcement team. There is no private right of action, but Texas has been the most active state privacy enforcer in the country.

Verify it yourself

Official sources

Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.

Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Texas and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.

Honest about the legal layer

Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.

We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.

Find out what your site is doing right now

Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.

Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.

The rest of the map

Privacy law in the other 19 states

Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.

Back to state privacy detection · How the consent layer works · Pricing