AI Compliance for Texas Healthcare Providers
For Texas providers and practices, the operative AI law is SB 1188 — diagnostic disclosure, record review, and US data residency — layered under TRAIGA's intent-based prohibitions and its NIST AI RMF safe harbor.
- Sept 1, 2025
- SB 1188 effective (H&S Code ch. 183)
- § 183.005(b)
- diagnostic-AI patient disclosure
- § 183.002
- US EHR data residency
- $250K
- top SB 1188 penalty tier
SB 1188: Duties for Practitioners Using AI
SB 1188 (effective September 1, 2025, Health & Safety Code Chapter 183) sets three operational duties:
- Diagnostic disclosure (§ 183.005(b)) — practitioners using AI for diagnostic purposes must disclose that use to patients.
- Record review (§ 183.005(a)(3)) — AI-created records must be reviewed in accordance with Texas Medical Board standards.
- Data residency (§ 183.002) — electronic health record data must be stored in the United States.
- Enforcement — the Texas Attorney General enforces SB 1188 with penalty tiers of $5,000, $25,000, and $250,000.
TRAIGA for Healthcare Organizations
TRAIGA (effective January 1, 2026) imposes no inventory, assessment, disclosure, training, or reporting mandates on private healthcare organizations. Its prohibited-use provisions (§§ 552.052–.057) apply under an intent standard — and § 552.056(c) confirms disparate impact alone is not sufficient to show discriminatory intent.
Enforcement is exclusive to the Attorney General with 60-day notice-and-cure; penalties run $10,000–$12,000 curable, $80,000–$200,000 uncurable, and $2,000–$40,000 per day ongoing. Substantial compliance with the NIST AI RMF is a recognized safe harbor (§ 552.105(e)) — making documented clinical AI governance directly liability-reducing.
HIPAA Interplay and How Risk Meridian Helps
Note the HIPAA interplay: HIPAA governs safeguards for protected health information but does not require US-only storage. SB 1188 § 183.002 adds a Texas-specific data-residency layer on top of your existing HIPAA obligations — so vendor and cloud-hosting diligence needs to cover both.
Risk Meridian generates SB 1188 diagnostic-AI patient disclosures, tracks record-review controls aligned to Texas Medical Board standards, documents EHR data-residency attestations, and assembles TRAIGA prohibited-use screening with NIST AI RMF safe-harbor evidence.
Frequently asked questions
Must I tell patients when AI assists with diagnosis?
Yes. Under SB 1188 § 183.005(b), practitioners using AI for diagnostic purposes must disclose that use to patients.
Can AI draft my chart notes?
SB 1188 does not ban AI-created records — it requires that they be reviewed in accordance with Texas Medical Board standards (§ 183.005(a)(3)). Documented review workflows are the compliance mechanism.
Can our EHR data be hosted outside the United States?
No. SB 1188 § 183.002 requires US data residency for electronic health record data — a requirement that goes beyond HIPAA, which does not mandate US-only storage.
Does TRAIGA add disclosure duties for private clinics?
Yes — twice over. TRAIGA § 552.051(f) requires any provider of health care services or treatment who uses AI in relation to that care to disclose it to the patient no later than the first service (emergencies: as soon as reasonably possible), and SB 1188 § 183.005(b) separately requires disclosure when AI is used for diagnostic purposes. Beyond disclosure, private clinics face the intent-based prohibitions (§§ 552.052–.057) and can claim the NIST AI RMF safe harbor (§ 552.105(e)) through documented governance.
Related resources
Start your AI governance program today
Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.
✓ No credit card ✓ Full platform access ✓ Cancel anytime