The HITECH Act: What Your Practice Must Actually Do
A billing clerk clicks a link in a fake payer portal email on a Tuesday. By Thursday your IT contractor confirms that the mailbox was accessed by someone outside the practice, and that mailbox held roughly 1,900 patient statements. From that Thursday, you have 60 calendar days to notify every one of those patients, and the same 60 days to file with HHS. That clock, the letter you have to send, and the penalty tier you land in if you miss it all trace back to one law: the HITECH Act.
This article is the operator's version. Not the legislative history — the deadlines, the role assignments, and the documents that hold up when the Office for Civil Rights asks you to produce them.
What the HITECH Act Changed and Why It Lands on Your Desk
The Health Information Technology for Economic and Clinical Health Act passed in 2009 as part of the American Recovery and Reinvestment Act. Most people remember it for the EHR incentive payments, which eventually became the Promoting Interoperability program. Those dollars are gone. The compliance obligations are not.
Four HITECH changes still shape your daily operations:
- Mandatory breach notification. Before HITECH, there was no federal HIPAA requirement to tell patients when their information leaked.
- Direct liability for business associates. Your vendors can be penalized by OCR without you being the enforcement target.
- Tiered civil money penalties tied to culpability. "We didn't know" and "we knew and didn't fix it" now produce very different numbers.
- State attorneys general enforcement. A second set of regulators with subpoena power over the same conduct.
The 2013 Omnibus Rule implemented most of it into the regulations you actually cite — 45 CFR Parts 160 and 164. When you write a policy, you cite the CFR. When someone asks why the rule exists, the answer is the HITECH Act.
How Long Do You Have to Report a Breach Under the HITECH Act?
Sixty calendar days from discovery to notify affected individuals in writing. Discovery means the first day any workforce member other than the person who caused it knew, or reasonably should have known, that a breach occurred — not the day your attorney finished the analysis.
The rest of the schedule:
- 500 or more individuals affected: notify HHS through the OCR breach portal within 60 days of discovery, and notify prominent media outlets serving the state or jurisdiction within the same 60 days.
- Fewer than 500 individuals: log the incident and report it to HHS within 60 days after the end of the calendar year in which it was discovered. Breaches you discovered in 2025 are due by March 1, 2026.
- Business associate to covered entity: no later than 60 days from the BA's discovery. Most well-drafted agreements shorten this to 5 to 15 days, because the BA's 60 days and your 60 days run from the same discovery date.
- Substitute notice: required when you have insufficient or out-of-date contact information for 10 or more individuals — website posting for 90 days or major print/broadcast media, plus a toll-free number active for at least 90 days.
Read the specifics against the HHS Breach Notification Rule guidance before you draft a single letter. The content requirements for the notice are prescriptive: what happened, what types of information were involved, what patients should do, what you're doing, and how to reach you.
The presumption you have to overcome
Any impermissible use or disclosure of unsecured PHI is presumed to be a reportable breach. You only avoid notification if you document a low probability of compromise using the four-factor risk assessment: the nature and extent of the PHI involved, who the unauthorized recipient was, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated.
Write that assessment down every time, even for the fax that went to the wrong dentist. A one-page memo with the four factors, the date of discovery, the decision, and the signature of your privacy officer is the single most requested document in low-level OCR inquiries. "We decided it wasn't a breach" with no memo is indistinguishable from "we never looked."
Note the word unsecured. PHI encrypted to HHS-specified standards, or properly destroyed, falls outside the notification requirement entirely. Full-disk encryption on every laptop and workstation is the cheapest breach-avoidance control you will ever buy.
Business Associate Liability Under the HITECH Act Is Direct — and It Runs Both Ways
Before HITECH, your vendors were bound only by contract to you. Now the Security Rule, the breach notification requirements, and many Privacy Rule provisions apply to business associates directly. OCR can and does open cases against them.
That does not reduce your obligation. You still must have an executed agreement in place before you disclose PHI, and "we're a large vendor, we're HIPAA compliant" in a sales deck is not an agreement. Practical failures I see repeatedly:
- A transcription service or answering service onboarded by the office manager with no agreement at all.
- An IT managed service provider with a master services agreement and no BAA, on the theory that they "don't look at patient data." Persistent access to systems containing PHI makes them a business associate.
- An agreement signed in 2012 that still references pre-Omnibus language and never got updated for breach notification timing.
- Subcontractors — the vendor's offshore developers, the cloud host — with no downstream agreement, which HITECH also requires.
Build the list before you build the paperwork. Pull your accounts payable ledger for the last 24 months and flag every vendor that creates, receives, maintains, or transmits PHI on your behalf. Then close the gaps. If you need to paper a vendor quickly, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you have eleven vendors to onboard this quarter and no outside counsel budget.
Assign an owner. Someone specific — usually the privacy officer — should hold a vendor register with columns for vendor name, service, PHI touched, agreement execution date, agreement expiration or review date, and the notification window in the contract. Review it quarterly. That register is the first document a regulator asks for after a vendor-caused breach.
The Four Penalty Tiers and the Security Practices Credit
The HITECH Act replaced a flat penalty structure with four culpability tiers:
- No knowledge — you did not know and would not have known by exercising reasonable diligence.
- Reasonable cause — you knew or should have known, but there was no willful neglect.
- Willful neglect, corrected within 30 days.
- Willful neglect, not corrected.
Statutory minimums and maximums per violation climb steeply across the tiers, and HHS adjusts the dollar figures for inflation each year through a Federal Register notice — check the current published amounts rather than relying on a number you saw in a slide deck three years ago. The structural point for operators is simpler: the difference between tier 2 and tier 4 is documentation and corrective action, both of which are inside your control. A findable risk analysis, a dated remediation plan, and evidence you executed it move you down the ladder.
In January 2021, Congress amended the HITECH Act to require HHS to consider whether a regulated entity had recognized security practices in place for the previous 12 months when calculating penalties, resolving audits, and setting the length of corrective action plans. Recognized security practices means the NIST Cybersecurity Framework, the Section 405(d) Health Industry Cybersecurity Practices, or other programs recognized by statute.
This is a mitigation lever most small practices leave unpulled. Adopt one framework by name in a board- or owner-signed resolution, map your safeguards to it, and keep 12 months of evidence — training rosters, phishing test results, patch logs, access reviews. The HHS 405(d) program publishes practice-sized guidance, and the NIST Cybersecurity Framework is free. Neither one certifies you; HHS does not endorse or certify any product or program. What they give you is a defensible answer to "what were you doing before this happened."
Patient Rights the HITECH Act Added to Your Front Desk Workflow
Electronic copies and the 30-day access clock
HITECH strengthened the right of access: if you maintain PHI electronically, patients can require an electronic copy in the form and format they request if it's readily producible. You have 30 days from receipt of the request, with one 30-day extension permitted if you notify the patient in writing of the reason and the new date.
Fees are limited to a reasonable, cost-based charge. Right-of-access cases have been the most frequently enforced area of OCR's small-dollar settlement work for years — you can browse resolutions and breach filings on the OCR breach portal. Log every request with a received date, a fulfilled date, and the requester's chosen format. A records request log is cheap insurance.
The out-of-pocket restriction request
If a patient pays in full out of pocket and asks you not to disclose that service to their health plan, you must comply. This is not discretionary. Your front desk needs a script, a form, and a way to flag the encounter in the practice management system so the claim does not go out automatically. Train on it; audit it twice a year.
Two things still not in effect
HITECH called for an accounting of disclosures for treatment, payment, and operations made through an EHR, and for a methodology to share a percentage of collected penalties with harmed individuals. Neither has been finalized. Don't build policy around them — but don't tell your board they were repealed either.
Audits, State AGs, and What Is Pending Right Now
Section 13411 of the HITECH Act requires HHS to conduct periodic audits of covered entities and business associates. OCR has run audit phases and reports to Congress annually on compliance and enforcement. Treat an audit request as a documentation exercise, because that is what it is: policies, the risk analysis, the risk management plan, training records, the BAA inventory.
State attorneys general can also bring HIPAA actions under HITECH, and many states layer their own breach notification statutes with shorter deadlines on top of the federal 60 days. Know your state's timeline. The tighter clock governs your calendar.
Also on the horizon: OCR proposed significant Security Rule amendments in January 2025 — specifying mandatory asset inventories, network mapping, encryption expectations, and compliance verification for business associates. As of this writing the rule is not final. Watch it, and note that most of what's proposed is something a well-run practice should already be able to produce.
Your Next 90 Days
- Weeks 1–2: Name your privacy officer and security officer in writing, with dates. Pull the AP ledger and build the vendor register.
- Weeks 3–6: Execute or refresh every missing business associate agreement. Confirm each one specifies a breach notification window shorter than 60 days.
- Weeks 5–8: Complete or update your Security Rule risk analysis, and write a dated risk management plan with owners for each finding.
- Weeks 7–10: Adopt a recognized security practices framework by name and start the 12-month evidence file.
- Weeks 9–12: Run a tabletop breach exercise against the 60-day clock. Draft the notification letter template now, while nothing is on fire.
The HITECH Act does not reward good intentions. It rewards dated documents with names on them.
If your vendor paperwork is the gap — and for most practices it is — start there: build a signature-ready business associate agreement for each vendor on your register this week. If the risk analysis and policy set are also thin, automated HIPAA risk analysis and policy generation will get you a defensible baseline faster than a blank Word document will. Either way, put a date on it and file it where you can find it in eleven minutes, not eleven days.