Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

New accelerator for sports, health AI startups to launch at the Ion

The Collectiv Foundation and Rice University have established a sports, health and wellness startup accelerator at the Ion District’s Collectiv, a sports-focused venture capital platform.

The AI Native Dual-Use Sports, Health & Wellness Accelerator, scheduled to formally launch in March, will back early-stage startups developing AI for the sports, health and wellness markets. Accelerator participants will gain access to a host of opportunities with:

  • Mentors
  • Advisers
  • Pro sports teams and leagues
  • University athletics programs
  • Health care systems
  • Corporate partners
  • VC firms
  • Pilot projects
  • University-based entrepreneurship and business initiatives

Accelerator participants will focus on sports tech verticals inlcuding performance and health, fan experience and media platforms, data and analytics, and infrastructure.

“Houston is quickly becoming one of the most important innovation hubs at the intersection of sports, health, and AI,” Ashley DeWalt, co-founder and managing partner of The Collectiv and founder of The Collectiv Foundation, said in a news release.

“By launching this platform with Rice University in the Ion District,” he added, “we are building a category-defining acceleration engine that gives founders access to world-class research, global sports properties, hospital systems, and venture capital. This is about turning sports-validated technology into globally scalable companies at a moment when the world’s attention is converging on Houston ahead of the 2026 World Cup.”

The Collectiv accelerator will draw on expertise from organizations such as the Rice-Houston Methodist Center for Human Performance, Rice Brain Institute, Rice Gateway Project and the Texas Medical Center.

“The combination of Rice University’s research leadership, Houston’s unmatched health ecosystem, and The Collectiv’s operator-driven investment platform creates a powerful acceleration engine,” Blair Garrou, co-founder and managing partner of the Mercury Fund VC firm and a senior adviser for The Collectiv, added in the release.

Additional details on programming, partners and application timelines are expected to be announced in the coming weeks.

4 Houston-area schools excel with best online degree programs in U.S.

Top of the Class

Four Houston-area universities have earned well-deserved recognition in U.S. News & World Report's just-released rankings of the Best Online Programs for 2026.

The annual rankings offer insight into the best American universities for students seeking a flexible and affordable way to attain a higher education. In the 2026 edition, U.S. News analyzed nearly 1,850 online programs for bachelor's degrees and seven master's degree disciplines: MBA, business (non-MBA), criminal justice, education, engineering, information technology, and nursing.

Many of these local schools are also high achievers in U.S. News' separate rankings of the best grad schools.

Rice University tied with Texas A&M University in College Station for the No. 3 best online master's in information technology program in the U.S., and its online MBA program ranked No. 21 nationally.

The online master's in nursing program at The University of Texas Medical Branch in Galveston was the highest performing master's nursing degree in Texas, and it ranked No. 19 nationally.

Three different programs at The University of Houston were ranked among the top 100 nationwide:
  • No. 18 – Best online master's in education
  • No. 59 – Best online master's in business (non-MBA)
  • No. 89 – Best online bachelor's program
The University of Houston's Clear Lake campus ranked No. 65 nationally for its online master's in education program.

"Online education continues to be a vital path for professionals, parents, and service members seeking to advance their careers and broaden their knowledge with necessary flexibility," said U.S. News education managing editor LaMont Jones in a press release. "The 2026 Best Online Programs rankings are an essential tool for prospective students, providing rigorous, independent analysis to help them choose a high-quality program that aligns with their personal and professional goals."

A little farther outside Houston, two more universities – Sam Houston State University in Huntsville and Texas A&M University in College Station – stood out for their online degree programs.

Sam Houston State University

  • No. 5 – Best online master's in criminal justice
  • No. 30 – Best online master's in information technology
  • No. 36 – Best online master's in education
  • No. 77 – Best online bachelor's program
  • No. 96 – Best online master's in business (non-MBA)
Texas A&M University
  • No. 3 – Best online master's in information technology (tied with Rice)
  • No. 3 – Best online master's in business (non-MBA)
  • No. 8 – Best online master's in education
  • No. 9 – Best online master's in engineering
  • No. 11 – Best online bachelor's program
---

This article originally appeared on CultureMap.com.

Houston wearable biosensing company closes $13M pre-IPO round

fresh funding

Wellysis, a Seoul, South Korea-headquartered wearable biosensing company with its U.S. subsidiary based in Houston, has closed a $13.5 million pre-IPO funding round and plans to expand its Texas operations.

The round was led by Korea Investment Partners, Kyobo Life Insurance, Kyobo Securities, Kolon Investment and a co-general partner fund backed by SBI Investment and Samsung Securities, according to a news release.

Wellysis reports that the latest round brings its total capital raised to about $30 million. The company is working toward a Korea Securities Dealers Automated Quotations listing in Q4 2026 or Q1 2027.

Wellysis is known for its continuous ECG/EKG monitor with AI reporting. Its lightweight and waterproof S-Patch cardiac monitor is designed for extended testing periods of up to 14 days on a single battery charge.

The company says that the funding will go toward commercializing the next generation of the S-Patch, known as the S-Patch MX, which will be able to capture more than 30 biometric signals, including ECG, temperature and body composition.

Wellysis also reports that it will use the funding to expand its Houston-based operations, specifically in its commercial, clinical and customer success teams.

Additionally, the company plans to accelerate the product development of two other biometric products:

  • CardioAI, an AI-powered diagnostic software platform designed to support clinical interpretation, workflow efficiency and scalable cardiac analysis
  • BioArmour, a non-medical biometric monitoring solution for the sports, public safety and defense sectors

“This pre-IPO round validates both our technology and our readiness to scale globally,” Young Juhn, CEO of Wellysis, said in the release. “With FDA-cleared solutions, expanding U.S. operations, and a strong AI roadmap, Wellysis is positioned to redefine how cardiac data is captured, interpreted, and acted upon across healthcare systems worldwide.”

Wellysis was founded in 2019 as a spinoff of Samsung. Its S-Patch runs off of a Samsung Smart Health Processor. The company's U.S. subsidiary, Wellysis USA Inc., was established in Houston in 2023 and was a resident of JLABS@TMC.