San Antonio managed IT & cybersecurity · 24/7 support available for opt-in clients Call 210-979-1886  ·  info@nexgenguard.com
Resource Center

Regulations & industry requirements

Who each requirement applies to, what it covers and where to find the official source.

Not every business is subject to the same rules. Use this page to see which requirements may apply to you, then confirm with your attorney, compliance advisor or the official source.

At a glance

RequirementGenerally applies toWhat it covers
HIPAA Security RuleHealthcare providers, health plans, clearinghouses and their business associatesProtecting electronic protected health information (ePHI)
FTC Safeguards Rule (GLBA)Non-bank financial institutions under FTC jurisdiction, such as mortgage lenders, finance companies and tax preparersA written information security program for customer information
PCI DSS v4.0.1Anyone who stores, processes or transmits payment card data, and their service providersPayment card data security (industry standard, not a law)
Texas Data Privacy and Security ActBusinesses that meet its applicability tests; most small businesses are excludedConsumer personal data privacy rights
Texas breach notification lawAnyone doing business in Texas that owns or licenses sensitive personal informationNotifying individuals and the Attorney General after a breach
Texas cybersecurity safe harborOptional for Texas businesses with fewer than 250 employeesProtection from punitive damages for businesses with a qualifying program
CMMC / NIST SP 800-171Defense contractors and subcontractors, as specified in their contractsProtecting federal contract information and CUI
GDPROrganizations processing personal data of people in the EU, within its scopePersonal data privacy and protection

HIPAA: healthcare

Applies to: covered entities (healthcare providers that bill electronically, health plans and clearinghouses) and their business associates, including IT providers with access to ePHI, who must sign a Business Associate Agreement (BAA).

The Security Rule requires three kinds of safeguards:

  • Administrative: risk analysis and risk management, workforce training, contingency (backup and disaster recovery) planning, incident procedures.
  • Physical: facility access controls and workstation and device security.
  • Technical: access controls, audit controls, integrity controls, authentication and transmission security.

What's changing: HHS proposed a major update to the Security Rule in January 2025. As of October 2026 it has not been finalized; the current rule remains in effect.

Official sources: HHS: The HIPAA Security Rule · NIST SP 800-66 Rev. 2 (HIPAA Security Rule implementation guide)

FTC Safeguards Rule and GLBA: financial businesses

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customer information. For non-bank financial businesses under FTC jurisdiction, that requirement is carried out through the FTC Safeguards Rule (16 CFR Part 314). Banks and credit unions follow their own regulators' versions.

The written information security program must include:

  1. A designated Qualified Individual to oversee the program.
  2. A written risk assessment.
  3. Safeguards, including access controls, encryption, multi-factor authentication and secure data disposal.
  4. Regular monitoring and testing.
  5. Security awareness training for staff.
  6. Oversight of service providers.
  7. Keeping the program current.
  8. A written incident response plan.
  9. Regular reporting to the board or a senior officer.

Good to know: the Qualified Individual may work for a service provider such as an MSP, but the business stays responsible and must designate a senior employee to oversee that person. Institutions with information on fewer than 5,000 consumers are exempt from some requirements. A breach involving unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery.

Official source: FTC Safeguards Rule: What Your Business Needs to Know

PCI DSS: payment cards

The Payment Card Industry Data Security Standard is an industry standard set by the PCI Security Standards Council, not a government law. It is enforced through card brand and merchant agreements. The current version is v4.0.1. If you accept cards, your payment processor can tell you which self-assessment questionnaire (SAQ) applies; using a reputable processor that keeps card data off your systems can greatly reduce your scope.

Official source: PCI Security Standards Council

Texas Data Privacy and Security Act (TDPSA)

In effect since July 1, 2024. It applies only to a business that (1) does business in Texas or offers products or services used by Texans, (2) processes or sells personal data and (3) is not a small business as defined by the U.S. Small Business Administration. Small businesses are generally excluded, except that they may not sell sensitive personal data without the consumer's consent. HIPAA-covered entities and business associates and GLBA financial institutions are also exempt. The Texas Attorney General enforces the law.

Official sources: Texas AG: Consumer Privacy Rights · Texas Business & Commerce Code Chapter 541

Texas data breach notification law

If you do business in Texas and a breach exposes sensitive personal information (Texas Business & Commerce Code §521.053):

  • Affected individuals: notify without unreasonable delay and no later than 60 days after you determine the breach occurred.
  • Texas Attorney General: if 250 or more Texas residents are affected, report through the AG's online form as soon as practicable and no later than 30 days after you determine the breach occurred.

Official source: Texas AG: Data Breach Reporting

Texas cybersecurity safe harbor (SB 2610)

Effective September 1, 2025 (Texas Business & Commerce Code Chapter 542). For a Texas business with fewer than 250 employees that owns or licenses computerized sensitive personal information, a person harmed by a breach may not recover exemplary (punitive) damages if the business shows it had a qualifying cybersecurity program at the time of the breach. It does not prevent lawsuits or other damages, and it does not replace breach notification duties.

Business sizeProgram requirements (in addition to conforming to a recognized framework)
Fewer than 20 employeesSimplified requirements, including password policies and appropriate employee cybersecurity training
20 to 99 employeesModerate requirements, including CIS Controls Implementation Group 1
100 to 249 employeesFull conformance to a recognized framework

Recognized frameworks named in the law include the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53, the CIS Critical Security Controls, the ISO/IEC 27000 series, HITRUST CSF, the Secure Controls Framework, SOC 2 and FedRAMP, plus HIPAA, GLBA and PCI DSS where they apply. When a framework is updated, a business has until the later of the new version's implementation date or one year after publication to update its program.

Official source: Texas Business & Commerce Code Chapter 542

CMMC and NIST SP 800-171: defense contractors

Businesses that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under Department of Defense contracts, including subcontractors, may need to meet Cybersecurity Maturity Model Certification (CMMC) requirements. Your contract determines the level and whether a self-assessment or third-party assessment is required. CMMC Level 2 is based on NIST SP 800-171 Revision 2, even though NIST has since published Revision 3. DoD's rollout schedule has changed during 2026, so check the DoD CMMC site for current status.

Official sources: DoD CIO: CMMC · NIST SP 800-171

GDPR

The European Union's General Data Protection Regulation can apply to U.S. businesses that offer goods or services to, or monitor the behavior of, people in the EU. Most local Texas businesses won't be affected, but it's worth checking if you sell online internationally.

Official source: Regulation (EU) 2016/679 (GDPR)

Last reviewed: October 2026. Laws and standards change; always confirm with the official source.

Ready for IT that just works?

Book a free consultation or IT security audit. No sales team, no pressure — just straight answers.