25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Texas Governor Signs Bill Providing Cybersecurity Safe Harbor for SMBs

Small businesses in Texas have been given protection from liability in data breach lawsuits if they implement and maintain a compliant cybersecurity program. State Governor Greg Abbott signed S.B. 2610 into law last Friday, which establishes a cybersecurity safe harbor for businesses with fewer than 250 employees, provided they implement and maintain a cybersecurity program that meets certain criteria. The new law does not protect businesses from all liability in the event of a security breach, but it does shield businesses from exemplary (punitive) damages arising from a breach of system security, limiting their financial exposure.

If a business can demonstrate that at the time of a breach of system security, they had implemented and maintained a cybersecurity program, a person harmed by that breach may not recover exemplary damages. The cybersecurity program must:

  • Contain administrative, technical, and physical safeguards for protecting personal identifying information and sensitive personal information
  • Conform to an industry-standard cybersecurity framework
  • Be a) designed to protect the security of personal identifying information and sensitive personal information, and b) protect against threats and hazards to the integrity of personal identifying information and sensitive personal information, and c) protect against unauthorized access to or the acquisition of personal identifying information and sensitive personal information

The HIPAA Journal

Cybersecurity Training

for Healthcare Employees

Because most HIPAA breaches stem from human error, our Cybersecurity Training teaches staff how attackers actually get in, and how to stop them.

The Gold Standard in HIPAA Training

by The HIPAA Journal Team

View HIPAA Training

The HIPAA Journal

Cybersecurity Training for Healthcare Employees

Because most HIPAA breaches stem from human error, our Cybersecurity Training teaches staff how attackers actually get in, and how to stop them.

The Gold Standard in HIPAA Training by The HIPAA Journal Team

Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | View HIPAA Training

 

The required cybersecurity measures are scaled based on the size of the business. A business with fewer than 20 employees has simplified requirements, such as password policies and cybersecurity training. Businesses with between 20 and 99 employees have moderate requirements, including the Center for Internet Security Controls Implementation Group 1.

Businesses with between 100 and 249 employees must implement a recognized cybersecurity framework, such as the NIST Cybersecurity Framework or the Health Information Trust Alliance’s Common Security Framework. Businesses that are covered entities under the Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act, or PCI DSS, will be covered if they are in full compliance with those standards. The new law takes effect on September 1, 2025.

The new law mirrors the safe harbor laws introduced in Ohio and Utah and is intended to encourage businesses to implement reasonable cybersecurity measures. Since the safe harbor laws were introduced in Ohio in 2018 and Utah in 2021, there has been a significant increase in investments in cybersecurity by SMBs.

The HIPAA Journal

Cybersecurity Training

for Healthcare Employees

Because most HIPAA breaches stem from human error, our Cybersecurity Training teaches staff how attackers actually get in, and how to stop them.

The Gold Standard in HIPAA Training

by The HIPAA Journal Team

View HIPAA Training

The HIPAA Journal

Cybersecurity Training for Healthcare Employees

Because most HIPAA breaches stem from human error, our Cybersecurity Training teaches staff how attackers actually get in, and how to stop them.

The Gold Standard in HIPAA Training by The HIPAA Journal Team

Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | View HIPAA Training

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

The HIPAA Journal

Cybersecurity Training

for Healthcare Employees

HIPAA Training covers the required security rules for protecting PHI, but because most HIPAA breaches stem from human error, our Cybersecurity Training goes a step further by teaching staff how attackers actually gain access and how to stop them.

The Gold Standard in HIPAA Training

by The HIPAA Journal Team