AuditXYZ

Compliance Framework

Health Information Technology for Economic and Clinical Health Act (HITECH)

The HITECH Act strengthened HIPAA enforcement, extended requirements to business associates, and mandated breach notification. This guide covers HITECH's impact on healthcare data security and compliance.

$15,000–$150,0002–6 months2009 (implemented through 2013 Omnibus Rule)
Issuing BodyUnited States Department of Health and Human Services (HHS)
First Published2009-02-17
Latest Version2009 (implemented through 2013 Omnibus Rule)
Typical Cost$15,000–$150,000
Typical Timeline2–6 months
Audit RequiredNo
Audit FrequencyHHS OCR conducts periodic audits and investigates complaints. HITECH strengthened enforcement with tiered penalties.
Geographyunited-states

HITECH Act: Health IT and Enforcement Guide

The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as part of the American Recovery and Reinvestment Act of 2009, fundamentally strengthened HIPAA by extending its requirements to business associates, establishing mandatory breach notification, introducing tiered penalties for violations, and promoting the adoption of electronic health records through the Meaningful Use program. Understanding HITECH is inseparable from understanding HIPAA — the two operate together as the core US health data compliance framework.

What HITECH Is and Who Issues It

HITECH was enacted on February 17, 2009 as Title XIII of the American Recovery and Reinvestment Act (ARRA). It was designed to achieve two complementary goals: accelerate the adoption of electronic health records to improve healthcare quality and reduce costs, and strengthen the privacy and security protections for patient health information to ensure that digitization did not come at the expense of patient trust.

HHS is responsible for implementing HITECH through its Office for Civil Rights (OCR) for HIPAA privacy and security provisions, and through the Office of the National Coordinator for Health Information Technology (ONC) for health IT standards and certification. HITECH's breach notification requirements were implemented through regulations published in August 2009 and subsequently incorporated into the 2013 Omnibus Rule.

HITECH significantly expanded OCR's enforcement authority and resources. Before HITECH, OCR rarely imposed civil monetary penalties — enforcement focused on corrective action and compliance improvement. HITECH's tiered penalty structure created real financial consequences and directed HHS to actively investigate HIPAA complaints and conduct audits.

Who Must Comply

HITECH applies to the same entities as HIPAA, but its most important effect was closing gaps in who bears direct legal responsibility:

Covered Entities continue to face HIPAA requirements, now implemented with stronger enforcement mechanisms. Covered entities are healthcare providers, health plans, and healthcare clearinghouses.

Business Associates — and this is HITECH's most significant structural change — became directly liable for HIPAA compliance. Before HITECH, business associates were only contractually bound to HIPAA through their Business Associate Agreements with covered entities. HITECH made business associates directly subject to many HIPAA requirements and directly liable for civil monetary penalties for non-compliance.

This change is critically important for the health technology sector. Any cloud provider, software vendor, analytics company, or IT services firm that handles PHI on behalf of a healthcare organization is now directly regulated — not just contractually obligated. Technology companies that assumed their HIPAA obligations were limited to contract terms discovered that HITECH created direct regulatory exposure.

Subcontractors of Business Associates became "downstream" business associates under HITECH, meaning a cloud provider that subcontracts to a data center is itself a business associate subject to HIPAA if PHI flows to that subcontractor. The chain of HIPAA accountability extends through the entire technology supply chain.

HITECH's Key Contributions to Healthcare Compliance

Mandatory Breach Notification

HITECH created the HIPAA Breach Notification Rule, which did not exist in the original HIPAA statute. Before HITECH, there was no federal requirement to notify patients about breaches of their health information. HITECH required covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.

The rule established that "breach" means an impermissible use or disclosure of PHI that compromises the security or privacy of the information, unless the covered entity demonstrates (through a four-factor risk assessment) that there is a low probability that PHI has been compromised. The four factors are:

  1. The nature and extent of PHI involved, including the types of identifiers and the likelihood of re-identification
  2. The unauthorized person who used or accessed the PHI, or to whom PHI was disclosed
  3. Whether the PHI was actually acquired or viewed
  4. The extent to which the risk to PHI has been mitigated

If the risk assessment does not demonstrate low probability of compromise, notification is required to individuals, HHS, and — for breaches affecting over 500 state residents — to major media outlets.

The HHS "Wall of Shame" — the publicly accessible list of healthcare breaches affecting 500 or more individuals — was also created by HITECH. The list, maintained at the HHS OCR website, has become an important resource for assessing industry breach trends and the types of violations that lead to large-scale disclosures.

Direct Business Associate Liability

HITECH extended direct HIPAA liability to business associates for certain requirements, including the Security Rule's administrative, physical, and technical safeguard requirements, the breach notification obligation for reporting to covered entities, and restrictions on impermissible uses and disclosures of PHI. Business associates are now subject to civil monetary penalties directly from OCR, not just liability through their covered entity contracts.

For technology companies serving healthcare organizations, this means an OCR investigation can name and fine the technology company directly, independent of any action against the covered entity customer. Several enforcement actions post-HITECH have directly targeted business associates.

Tiered Civil Monetary Penalty Structure

HITECH replaced HIPAA's original flat penalty structure with a four-tier system based on culpability:

TierDescriptionPer ViolationAnnual Maximum
1Did not know (and with reasonable diligence would not have known)$100–$50,000$25,000
2Reasonable cause (not willful neglect)$1,000–$50,000$100,000
3Willful neglect, corrected$10,000–$50,000$250,000
4Willful neglect, not corrected$50,000$1,500,000

These figures have been adjusted for inflation — the current maximum per violation for Tier 4 is approximately $50,000 per violation, with an annual maximum exceeding $1.9 million per violation category. The distinction between violation categories is critical: each separate violation for each separate day of non-compliance is counted independently.

HHS also empowered state attorneys general to bring civil actions for HIPAA violations, adding another enforcement mechanism. State AGs have brought HIPAA enforcement actions, most notably several actions by state attorneys general following major healthcare data breaches.

Accounting of Disclosures from Electronic Health Records

HITECH required HHS to develop regulations expanding patients' right to an accounting of disclosures from electronic health records to include disclosures for treatment, payment, and healthcare operations — categories previously excluded from the accounting requirement. While HHS proposed regulations in 2011, the rulemaking was never finalized. The existing accounting of disclosures requirements (which exclude TPO disclosures) remain in effect.

Prohibition on Sale of PHI

HITECH prohibits covered entities and business associates from receiving remuneration (directly or indirectly) in exchange for PHI without patient authorization, subject to specific exceptions for treatment, payment, healthcare operations, certain research purposes, and public health activities. This provision was intended to prevent the commercialization of patient data without patient consent.

Restrictions on Marketing

HITECH tightened restrictions on using PHI for marketing purposes, specifically requiring patient authorization for communications that involve a healthcare provider or health plan receiving remuneration from a third party for making the communication.

Meaningful Use and EHR Adoption

HITECH established the Meaningful Use program, which provided financial incentives to healthcare providers adopting and meaningfully using certified EHR technology. Through Medicare and Medicaid incentive payments totaling billions of dollars, HITECH dramatically accelerated EHR adoption across the US healthcare system. Meaningful Use has since evolved into the Promoting Interoperability program, which continues to drive health information exchange and patient access to data.

Audit and Assessment Process

HITECH compliance is assessed through the same mechanisms as HIPAA:

MechanismFrequencyScope
OCR complaint investigationTriggered by complaintsSpecific violations and related practices
OCR random auditPeriodicComprehensive HIPAA/HITECH compliance review
State AG investigationTriggered by breaches or complaintsViolations affecting state residents

OCR's compliance review process typically begins with a compliance review request, followed by document and evidence collection, on-site or desk review of compliance program documentation, and a resolution — either a finding of no violation, a corrective action plan, or a resolution agreement with financial settlement.

HITECH-mandated audit programs have reviewed covered entities and business associates across multiple cycles, with findings consistently showing that risk analysis, risk management, and access controls are the most common deficiency areas.

Costs and Timeline

Organization TypeIncremental HITECH TimelineIncremental Cost Range
Small covered entity2–3 months$15,000–$40,000
Health tech business associate3–4 months$30,000–$80,000
Large covered entity or major BA4–6 months$80,000–$150,000

These costs are incremental above basic HIPAA compliance investments and focus specifically on breach notification procedures, BA agreement updates, enhanced enforcement readiness, and state AG compliance considerations.

  • HIPAA: 90% overlap — HITECH is implemented as part of the HIPAA regulatory structure and cannot be separated from HIPAA compliance in practice. See the HIPAA guide.
  • HITRUST CSF: About 80% overlap. HITRUST CSF incorporates HITECH requirements as part of its comprehensive healthcare security framework. HITRUST certification demonstrates HITECH compliance as a component. See the HITRUST guide.
  • SOC 2: About 40% overlap, primarily in breach notification procedures and access control requirements. Technology companies subject to HITECH as business associates often seek SOC 2 certification as complementary evidence of security maturity.
  • GDPR Health: HITECH's breach notification requirements have conceptual parallels to GDPR's 72-hour breach notification obligation, though the requirements differ significantly in scope and implementation. See the GDPR Health guide.

How Automation Helps

HITECH compliance requires robust breach detection, documentation, and notification capabilities — areas where automation provides significant efficiency gains:

  • Automated security monitoring helps identify potential breaches rapidly, supporting the 60-day notification timeline
  • Breach risk assessment workflows formalize the four-factor analysis required to determine notification obligations
  • Incident tracking systems maintain a complete log of security incidents, their investigation status, and disposition
  • Business Associate inventory tools track all BA relationships, BAA status, and compliance documentation
  • Training management platforms document annual HIPAA/HITECH training for all workforce members

LowerPlane supports HITECH and HIPAA compliance programs with AI-powered evidence collection, breach tracking, and vendor risk management. Covering 50-plus frameworks at $4,000 per year (with a free tier available), rated 9.4/10 on AuditXYZ, LowerPlane gives health tech companies and covered entities a unified platform for managing healthcare regulatory compliance. For health technology company compliance, see /for/healthtech. Compare platforms at /compare/best-compliance-automation-platforms.

Frequently Asked Questions

Does HITECH create any new patient rights beyond HIPAA?

HITECH strengthened existing patient rights in two key ways. First, it required covered entities to provide patients with access to their electronic PHI in a format the patient requests, removing the covered entity's option to provide a paper alternative where electronic formats are requested. Second, it created a new right for patients to restrict disclosure of PHI to health plans where the patient pays for services out of pocket in full — covered entities must honor such requests. HITECH also required HHS to propose expanded accounting of disclosures rights (covering TPO disclosures), though that rulemaking was never finalized.

How does the HITECH breach notification timeline work?

Upon discovering a breach (or being notified of one by a business associate), a covered entity must provide individual notification within 60 days. The 60-day clock runs from the date of discovery, not the date of the breach. Business associates must notify their covered entity "without unreasonable delay" and in no case later than 60 days from their own discovery. Covered entities cannot wait for a business associate's investigation to conclude before starting their 60-day clock — the CE's timer starts when the CE discovers the breach or is notified by the BA. Large breaches (500 or more affected individuals) must also be reported to HHS and media within 60 days of discovery.

Can a business associate be fined directly by OCR under HITECH?

Yes. HITECH made business associates directly liable for civil monetary penalties for violations of HIPAA provisions applicable to them, including Security Rule violations, breach notification failures, and impermissible uses and disclosures. OCR has exercised this authority in numerous enforcement actions. Notable examples include settlements with a transcription vendor, multiple EHR companies, and cloud service providers that experienced data breaches or demonstrated systemic compliance failures. Business associates cannot shield themselves from OCR enforcement by pointing to their covered entity customer.

What is the difference between a security incident and a breach under HITECH?

A "security incident" is the broader term under HIPAA/HITECH — it means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations. A "breach" is a specific subset of security incidents: an impermissible use or disclosure of unsecured PHI that compromises its security or privacy, unless the four-factor risk assessment demonstrates low probability of compromise. Not every security incident is a breach requiring notification. Many impermissible accesses to PHI — such as a misdirected fax to a wrong number that is immediately returned — can be assessed to not constitute reportable breaches. Organizations need clear procedures for triaging security incidents, conducting breach risk assessments, and documenting the analysis.

How does HITECH's tiered penalty structure affect compliance strategy?

The tiered penalty structure creates a meaningful distinction between good-faith compliance failures and willful neglect. Organizations that conduct regular risk analyses, implement documented compliance programs, train their workforce, and respond appropriately to identified issues are positioned in Tier 1 (did not know) or at most Tier 2 (reasonable cause) if violations occur despite their efforts. Organizations that ignore HIPAA requirements, fail to conduct risk analyses, or continue practices after being put on notice of compliance problems face Tier 3 or 4 penalties — and the difference between Tier 1 and Tier 4 is up to $1.85 million per violation category per year. The business case for proactive compliance investment is compellingly supported by this penalty structure.

Request a HITECH consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

HIPAAHigh90%
HITRUST CSFHigh80%

Related frameworks

Get matched with a HITECH auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.