Not every business is subject to the same rules. Use this page to see which requirements may apply to you, then confirm with your attorney, compliance advisor or the official source.
At a glance
| Requirement | Generally applies to | What it covers |
|---|---|---|
| HIPAA Security Rule | Healthcare providers, health plans, clearinghouses and their business associates | Protecting electronic protected health information (ePHI) |
| FTC Safeguards Rule (GLBA) | Non-bank financial institutions under FTC jurisdiction, such as mortgage lenders, finance companies and tax preparers | A written information security program for customer information |
| PCI DSS v4.0.1 | Anyone who stores, processes or transmits payment card data, and their service providers | Payment card data security (industry standard, not a law) |
| Texas Data Privacy and Security Act | Businesses that meet its applicability tests; most small businesses are excluded | Consumer personal data privacy rights |
| Texas breach notification law | Anyone doing business in Texas that owns or licenses sensitive personal information | Notifying individuals and the Attorney General after a breach |
| Texas cybersecurity safe harbor | Optional for Texas businesses with fewer than 250 employees | Protection from punitive damages for businesses with a qualifying program |
| CMMC / NIST SP 800-171 | Defense contractors and subcontractors, as specified in their contracts | Protecting federal contract information and CUI |
| GDPR | Organizations processing personal data of people in the EU, within its scope | Personal data privacy and protection |
HIPAA: healthcare
Applies to: covered entities (healthcare providers that bill electronically, health plans and clearinghouses) and their business associates, including IT providers with access to ePHI, who must sign a Business Associate Agreement (BAA).
The Security Rule requires three kinds of safeguards:
- Administrative: risk analysis and risk management, workforce training, contingency (backup and disaster recovery) planning, incident procedures.
- Physical: facility access controls and workstation and device security.
- Technical: access controls, audit controls, integrity controls, authentication and transmission security.
What's changing: HHS proposed a major update to the Security Rule in January 2025. As of October 2026 it has not been finalized; the current rule remains in effect.
Official sources: HHS: The HIPAA Security Rule · NIST SP 800-66 Rev. 2 (HIPAA Security Rule implementation guide)
FTC Safeguards Rule and GLBA: financial businesses
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customer information. For non-bank financial businesses under FTC jurisdiction, that requirement is carried out through the FTC Safeguards Rule (16 CFR Part 314). Banks and credit unions follow their own regulators' versions.
The written information security program must include:
- A designated Qualified Individual to oversee the program.
- A written risk assessment.
- Safeguards, including access controls, encryption, multi-factor authentication and secure data disposal.
- Regular monitoring and testing.
- Security awareness training for staff.
- Oversight of service providers.
- Keeping the program current.
- A written incident response plan.
- Regular reporting to the board or a senior officer.
Good to know: the Qualified Individual may work for a service provider such as an MSP, but the business stays responsible and must designate a senior employee to oversee that person. Institutions with information on fewer than 5,000 consumers are exempt from some requirements. A breach involving unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery.
Official source: FTC Safeguards Rule: What Your Business Needs to Know
PCI DSS: payment cards
The Payment Card Industry Data Security Standard is an industry standard set by the PCI Security Standards Council, not a government law. It is enforced through card brand and merchant agreements. The current version is v4.0.1. If you accept cards, your payment processor can tell you which self-assessment questionnaire (SAQ) applies; using a reputable processor that keeps card data off your systems can greatly reduce your scope.
Official source: PCI Security Standards Council
Texas Data Privacy and Security Act (TDPSA)
In effect since July 1, 2024. It applies only to a business that (1) does business in Texas or offers products or services used by Texans, (2) processes or sells personal data and (3) is not a small business as defined by the U.S. Small Business Administration. Small businesses are generally excluded, except that they may not sell sensitive personal data without the consumer's consent. HIPAA-covered entities and business associates and GLBA financial institutions are also exempt. The Texas Attorney General enforces the law.
Official sources: Texas AG: Consumer Privacy Rights · Texas Business & Commerce Code Chapter 541
Texas data breach notification law
If you do business in Texas and a breach exposes sensitive personal information (Texas Business & Commerce Code §521.053):
- Affected individuals: notify without unreasonable delay and no later than 60 days after you determine the breach occurred.
- Texas Attorney General: if 250 or more Texas residents are affected, report through the AG's online form as soon as practicable and no later than 30 days after you determine the breach occurred.
Official source: Texas AG: Data Breach Reporting
Texas cybersecurity safe harbor (SB 2610)
Effective September 1, 2025 (Texas Business & Commerce Code Chapter 542). For a Texas business with fewer than 250 employees that owns or licenses computerized sensitive personal information, a person harmed by a breach may not recover exemplary (punitive) damages if the business shows it had a qualifying cybersecurity program at the time of the breach. It does not prevent lawsuits or other damages, and it does not replace breach notification duties.
| Business size | Program requirements (in addition to conforming to a recognized framework) |
|---|---|
| Fewer than 20 employees | Simplified requirements, including password policies and appropriate employee cybersecurity training |
| 20 to 99 employees | Moderate requirements, including CIS Controls Implementation Group 1 |
| 100 to 249 employees | Full conformance to a recognized framework |
Recognized frameworks named in the law include the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53, the CIS Critical Security Controls, the ISO/IEC 27000 series, HITRUST CSF, the Secure Controls Framework, SOC 2 and FedRAMP, plus HIPAA, GLBA and PCI DSS where they apply. When a framework is updated, a business has until the later of the new version's implementation date or one year after publication to update its program.
Official source: Texas Business & Commerce Code Chapter 542
CMMC and NIST SP 800-171: defense contractors
Businesses that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under Department of Defense contracts, including subcontractors, may need to meet Cybersecurity Maturity Model Certification (CMMC) requirements. Your contract determines the level and whether a self-assessment or third-party assessment is required. CMMC Level 2 is based on NIST SP 800-171 Revision 2, even though NIST has since published Revision 3. DoD's rollout schedule has changed during 2026, so check the DoD CMMC site for current status.
Official sources: DoD CIO: CMMC · NIST SP 800-171
GDPR
The European Union's General Data Protection Regulation can apply to U.S. businesses that offer goods or services to, or monitor the behavior of, people in the EU. Most local Texas businesses won't be affected, but it's worth checking if you sell online internationally.
Official source: Regulation (EU) 2016/679 (GDPR)
Last reviewed: October 2026. Laws and standards change; always confirm with the official source.
