HITECH Act
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
HITECH 2024-2025 Pipeline: NPRM Security Rule Modernisation, Reproductive Health, Information Blocking, Sectoral Application
HITECH 2024-2025 regulatory pipeline + sectoral application. KEY 2024-2025 INITIATIVES: (a) HIPAA SECURITY RULE NPRM (Notice of Proposed Rulemaking) issued by HHS OCR 27 December 2024 (89 FR 105672) proposing the FIRST MAJOR HIPAA Security Rule modernisation since 2013; comments closed 7 March 2025; potential Final Rule 2025-2026; proposed enhancements include (i) MULTI-FACTOR AUTHENTICATION (MFA) requirement for access to ePHI; (ii) MANDATORY ENCRYPTION of ePHI at rest + in transit (currently 'addressable' standard); (iii) NETWORK SEGMENTATION + ZERO TRUST architecture; (iv) ASSET INVENTORY + technology asset management; (v) RANSOMWARE RESPONSE PROGRAM including written ransomware response procedures; (vi) ANNUAL COMPLIANCE AUDIT + Risk Analysis update; (vii) BUSINESS ASSOCIATE compliance documentation + 24-hour breach reporting to covered entity; (viii) WORKFORCE TRAINING enhancements
- NPRM readiness + comment + implementation
- Reproductive health compliance
- HSPP demonstrating + 12-month documentation
- NPRM readiness gap
- Reproductive health compliance unclear
- HSPP not demonstrated
HITECH implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY OFFICER + COMPLIANCE OFFICER - strategic ownership + HIPAA + HITECH compliance + OCR-relations; (b) SECURITY OFFICER + CISO - HIPAA Security Rule compliance + technical safeguards + cybersecurity + 405d Safe Harbor; (c) GENERAL COUNSEL + LEGAL - statutory + regulatory interpretation + breach response coordination + state law analysis + BAA negotiation; (d) HR + WORKFORCE - training + sanctions + workforce-related HIPAA compliance + HITECH Workforce Development; (e) HEALTH INFORMATION MANAGEMENT (HIM) - PHI custodian + record retention + accounting of disclosures + access requests; (f) IT + EHR ADMINISTRATOR - EHR Certification + Meaningful Use/Promoting Interoperability + Information Blocking compliance + 2015 Edition Cures Update; (g) BUSINESS ASSOCIATE MANAGER - BAA inventory + tracking + sub-BA management + vendor risk;
- Role inventory + RACI
- Tooling + EHR + cloud + compliance platform
- Metrics + management review
- Annual + Phase 3 audit-readiness
- Roles undefined
- Tooling fragmented
- Metrics gaps
- OCR audit unprepared
HITECH sectoral application + OCR Wall of Shame. SECTOR ADOPTION: HITECH applies to ALL HIPAA covered entity + BAs handling PHI in US healthcare ecosystem + downstream subcontractor BAs. KEY SECTORS: (a) HEALTH PLANS - commercial + Medicare + Medicaid + Marketplace; major payers (UnitedHealth + Anthem + Aetna + CVS + Cigna + Humana + BCBS + Kaiser + many more); HITECH + 2013 Omnibus + recent OCR enforcement includes large health plan settlements (Anthem USD 16M + Premera USD 6.85M + Excellus USD 5.1M); (b) HEALTHCARE PROVIDERS - hospitals + health systems + ambulatory care + private practices + dentists + chiropractors + therapists + telehealth; HITECH MU/PI EHR adoption + Information Blocking + breach notification + OCR audits; major hospital systems include HCA + CommonSpirit + Tenet + Ascension + Trinity + Kaiser + Mayo + Cleveland Clinic + Johns Hopkins + Mass General Brigham + Geisi
- Sectoral compliance per sector
- Breach-history monitoring
- Sectoral coordination engagement
- Sectoral application gaps
- Breach monitoring weak
- Sectoral coordination absent
HITECH status + 2024-2025 vision. ADOPTION + IMPACT: HITECH catalyzed the most significant US healthcare IT transformation since the introduction of HIPAA + drove EHR adoption from ~10 percent of hospitals (2008) to ~96 percent (2019) + ~80 percent of physician practices; ARRA-funded EHR Incentive Programs disbursed ~USD 36 BILLION in incentive payments to providers + hospitals 2011-2021; substantially expanded HIPAA Privacy + Security Rule enforcement + 4-tier CMP structure + Business Associate direct liability + Breach Notification Rule. KEY ACHIEVEMENTS: (a) NEAR-UNIVERSAL EHR ADOPTION across US hospitals + ambulatory care; (b) MEANINGFUL USE / PROMOTING INTEROPERABILITY drove quality + interoperability advances; (c) BREACH NOTIFICATION RULE established transparency + accountability + ~5,000+ reportable breaches since 2010; (d) BUSINESS ASSOCIATE direct liability + BAA standardisation
- Adoption + benchmarking
- Cybersecurity + ransomware readiness
- NPRM + Cures Act readiness
- Adoption monitoring weak
- Cyber readiness gap
- Future readiness lagging
HITECH Act: Statutory Scope, ARRA Title XIII Origin, 42 USC Chapter 156 Structure (Subtitles A-D)
HITECH Act statutory scope + structure. ENACTMENT: Title XIII of the American Recovery and Reinvestment Act of 2009 (ARRA, Public Law 111-5) signed 17 February 2009 + entered into force phased; codified at 42 USC Chapter 156 (Sections 17901-17953) + 26 USC Section 45R for tax provisions + amendments to 42 USC Section 1320d (HIPAA) + 45 CFR Parts 160 + 164. KEY STRUCTURE: 4 SUBTITLES. SUBTITLE A PROMOTION OF HEALTH IT (42 USC 17901-17915): Office of the National Coordinator for Health IT (ONC, established statutorily by Sec. 17901); HIT Standards Committee (Sec. 17903); HIT Policy Committee (Sec. 17902); ONC HIT Certification Program (Sec. 17905-17907); HIT Workforce Development (Sec. 17909); Meaningful Use criteria for EHR Incentive Programs (via CMS through Section 1903); Health Information Exchange (HIE) standards. SUBTITLE B TESTING OF HEALTH IT (42 USC 17916-17919): National Health I
- Scope determination + applicability
- Subtitle-specific compliance evidence
- Definition + interpretation documentation
- Scope misunderstood
- Subtitle applicability unclear
- Definitions confused
HITECH Coordination with HIPAA Privacy + Security Rules (Verified Separately) + 21st Century Cures Act + ONC
HITECH coordination with HIPAA Privacy Rule + HIPAA Security Rule + 21st Century Cures Act + ONC. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - established 2000 + modified 2002 + significantly amended by HITECH 2009 + 2013 Omnibus Final Rule; governs PHI use + disclosure + individual rights; HITECH expanded application to BAs + strengthened individual rights + enforcement. HIPAA SECURITY RULE (45 CFR Part 164 Subpart C, SEPARATELY VERIFIED in this corpus) - established 2003 + significantly amended by HITECH 2009 + 2013 Omnibus + 2024 NPRM modernisation; administrative + physical + technical safeguards for ePHI; HITECH extended direct application to BAs + added Breach Notification Rule; 2024 NPRM proposed enhancements include MFA + encryption + asset inventory + ransomware response + vulnerability management. 2013 HIPAA OMNIBUS FINAL RULE (78 FR 5566): implementing HITECH Privac
- Multi-rule compliance program
- Information Blocking compliance evidence
- TEFCA + QHIN participation
- State + federal coordination
- Multi-rule coordination weak
- Information Blocking compliance gap
- TEFCA + QHIN not engaged
HITECH crosswalk to verified subordinate substantive rules + adjacent frameworks. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - primary substantive privacy controls; HITECH amendments operationalized via 2013 Omnibus Final Rule + ongoing OCR guidance. HIPAA SECURITY RULE (45 CFR Part 164 Subpart C, VERIFIED SEPARATELY in this corpus) - primary substantive security controls; administrative + physical + technical safeguards for ePHI; pending 2024-2025 NPRM modernisation. HITECH BREACH NOTIFICATION RULE (45 CFR Part 164 Subpart D) - breach definition + 4-factor risk assessment + individual + media + HHS notification SLA. NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 + 800-53 + 800-66 (HIPAA Security Rule Implementation Guide) - voluntary cybersecurity framework + recognized security practices; HHS 405d MAPPING crosswalks NIST CSF to HIPAA Security Rule. HHS 405d HEALTH INDUSTRY CYBERSECU
- Multi-rule + framework compliance program
- 405d Safe Harbor evidence
- Information Blocking compliance
- Multi-rule compliance gaps
- Safe Harbor not pursued
- Information Blocking compliance unclear
HITECH Enforcement: 4-Tier Civil Monetary Penalties, State AGs, HHS OCR, Recent Settlements
HITECH 4-tier CIVIL MONETARY PENALTIES (CMP) + enforcement (Section 17939; 45 CFR 160.404; inflation-adjusted annually). HHS OCR ENFORCEMENT AUTHORITY: HHS Office for Civil Rights (OCR) primary federal enforcer; tier-based CMPs per HIPAA Privacy + Security Rule + Breach Notification Rule violations. 4-TIER CMP STRUCTURE: TIER 1 - did not know (and through exercise of reasonable diligence would not have known) USD 100-50K per violation, USD 25K annual maximum per category (2009 amounts; inflation-adjusted to USD ~50K-USD ~134K cap as of 2024). TIER 2 - violation due to reasonable cause + not willful neglect USD 1K-50K per violation, USD 100K annual cap (adjusted to USD ~144K-USD ~287K cap). TIER 3 - violation due to willful neglect that was CORRECTED within 30 days USD 10K-50K per violation, USD 250K annual cap (adjusted to USD ~287K-USD ~430K cap). TIER 4 - violation due to willful negle
- CMP risk assessment + compliance program
- State AG monitoring
- OCR audit-readiness
- CMP compliance gaps
- State AG risk unaddressed
- OCR audit unprepared
HITECH Subtitle A: ONC, HIT Standards, EHR Certification, Meaningful Use / Promoting Interoperability
HITECH Subtitle A - Promotion of Health Information Technology. OFFICE OF THE NATIONAL COORDINATOR FOR HEALTH IT (ONC, established statutorily by Sec. 17901): independent within HHS + responsible for HIT policy + standards + interoperability + Information Blocking + EHR Certification + Trusted Exchange Framework + Common Agreement (TEFCA); leadership by National Coordinator (typically MD or RN + tech background). HIT POLICY COMMITTEE (Sec. 17902, replaced 2017 by Health IT Advisory Committee) + HIT STANDARDS COMMITTEE (Sec. 17903): advise + recommend on policy + standards + criteria; multi-stakeholder including providers + payers + tech industry + patient advocates. ONC HIT CERTIFICATION PROGRAM (Sec. 17905-17907): voluntary EHR + Health IT module certification against ONC criteria including security + interoperability + usability + reporting; current criteria 2015 Edition Cures Update;
- ONC-certified EHR adoption
- MU/PI program participation
- TEFCA + QHIN engagement
- ONC certification gaps
- MU/PI participation absent
- TEFCA + QHIN not engaged
HITECH Subtitle D: Breach Notification Rule, BA Direct Liability, Subcontractors
HITECH Subtitle D - Breach Notification + Business Associate (BA) direct liability. BREACH NOTIFICATION RULE (Section 17932; 45 CFR Part 164 Subpart D, Sections 164.400-414): covered entities + BAs must provide notification following discovery of a breach of UNSECURED PHI (PHI not rendered unusable/unreadable/indecipherable to unauthorized individuals via encryption per NIST or destruction). BREACH DEFINITION (45 CFR 164.402): acquisition + access + use + disclosure of PHI not permitted under HIPAA Privacy Rule which compromises security/privacy; presumed breach unless covered entity demonstrates LOW PROBABILITY OF COMPROMISE via 4-FACTOR RISK ASSESSMENT: (1) nature + extent of PHI + types of identifiers + re-identification risk; (2) unauthorized recipient identity + likelihood of re-disclosure; (3) actual acquisition + viewing of PHI; (4) extent of mitigation. EXCLUSIONS: unintentional
- Breach response procedure + register
- Notification procedures + templates
- BAA templates + subcontractor management
- Breach notification weak
- 60-day SLA missed
- BAA not in place
HITECH Subtitle D: Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)
HITECH Subtitle D - strengthened individual rights. ELECTRONIC ACCESS (Section 17937; 45 CFR 164.524): individuals have RIGHT TO ACCESS PHI in DESIGNATED RECORD SET + receive in ELECTRONIC FORMAT if maintained electronically (e.g. EHR); covered entity must respond within 30 days + 60-day extension if reasonable; reasonable fee for paper or electronic copy + electronic format must be readable + interoperable; right to designate third-party recipient + Right of Access Initiative is OCR enforcement priority. ACCOUNTING OF DISCLOSURES (Section 17935(c); 45 CFR 164.528): individuals have right to accounting of certain disclosures including TPO disclosures from EHR for 3 years (post-HITECH expansion); covered entity must respond within 60 days + provide list of disclosures + recipients + purposes. RESTRICTIONS ON DISCLOSURES TO HEALTH PLANS (Section 17935(a); 45 CFR 164.522(a)): patient has RI
- Individual rights procedures
- Electronic access + accounting
- BAA marketing/fundraising terms
- Right of access weak
- Accounting incomplete
- Restriction not honored
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the HITECH Act framework page.