§ 74A.002.Limitation on Liability of Health Care Providers Relating to Health Information Exchanges
Title 4. Liability in Tort · Chapter 74A. Limitation of Liability Relating to Health Information Exchanges · Last amended 2015 · Last verified August 29, 2026
Full Text of § 74A.002
Plain-English Summary
The operative provision, and it addresses a specific fear.
Unless the health care provider acts with malice or gross negligence, a provider who provides patient information to a health information exchange is not liable for damages, penalties, or other relief related to the obtainment, use, or disclosure of that information in violation of federal or state privacy laws by a health information exchange, another health care provider, or any other person.
The protection is against someone else's breach. A provider that shares records properly is not answerable for what the exchange, another provider, or a third party then does with them.
Health information exchanges exist so that a patient's records follow them between providers, which requires each provider to release data it no longer controls. Without this section, HIPAA exposure would be a rational reason to decline to participate.
Malice and gross negligence remain outside the shield, so a provider that released records recklessly or deliberately is not protected.
Subsection (b) is a careful disclaimer: nothing in the section may be construed to create a cause of action or to create a standard of care, obligation, or duty that forms the basis for a cause of action.
That forecloses the argument that the section, by protecting providers who act without gross negligence, thereby establishes a duty to avoid it — a reading that would turn an immunity into a source of liability.
Frequently Asked Questions
Is a doctor liable if a health information exchange leaks records?
Not unless the doctor acted with malice or gross negligence. The section shields a provider that supplied information from liability for a privacy-law violation by the exchange, another provider, or any other person.
Why does the protection exist?
Health information exchanges require each provider to release data it no longer controls, and privacy-law exposure would otherwise be a reason not to participate.
Does the section create any duty?
No. It may not be construed to create a cause of action or a standard of care, obligation, or duty forming the basis for one.
Amendment History
- Added by Acts 2015, 84th Leg., R.S., Ch. 1085 (H.B. 2641), Sec. 1, eff. September 1, 2015.