Skip to content

Evidence request lists

HITECH Act

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

HITECH 2024-2025 Pipeline: NPRM Security Rule Modernisation, Reproductive Health, Information Blocking, Sectoral Application

HITECH-2024-2025-NPRM-ReproductiveHealth-Sectoral
HITECH 2024-2025 Pipeline - HIPAA Security Rule NPRM (Dec 2024), Reproductive Health, OCR Audits, Sectoral Application

HITECH 2024-2025 regulatory pipeline + sectoral application. KEY 2024-2025 INITIATIVES: (a) HIPAA SECURITY RULE NPRM (Notice of Proposed Rulemaking) issued by HHS OCR 27 December 2024 (89 FR 105672) proposing the FIRST MAJOR HIPAA Security Rule modernisation since 2013; comments closed 7 March 2025; potential Final Rule 2025-2026; proposed enhancements include (i) MULTI-FACTOR AUTHENTICATION (MFA) requirement for access to ePHI; (ii) MANDATORY ENCRYPTION of ePHI at rest + in transit (currently 'addressable' standard); (iii) NETWORK SEGMENTATION + ZERO TRUST architecture; (iv) ASSET INVENTORY + technology asset management; (v) RANSOMWARE RESPONSE PROGRAM including written ransomware response procedures; (vi) ANNUAL COMPLIANCE AUDIT + Risk Analysis update; (vii) BUSINESS ASSOCIATE compliance documentation + 24-hour breach reporting to covered entity; (viii) WORKFORCE TRAINING enhancements

Artefacts an auditor will ask for
  • NPRM readiness + comment + implementation
  • Reproductive health compliance
  • HSPP demonstrating + 12-month documentation
Where this commonly fails
  • NPRM readiness gap
  • Reproductive health compliance unclear
  • HSPP not demonstrated
HITECH-Implementation-Roles-Compliance-Audit
HITECH Implementation Roadmap, Organizational Roles, Compliance + Audit-Readiness

HITECH implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY OFFICER + COMPLIANCE OFFICER - strategic ownership + HIPAA + HITECH compliance + OCR-relations; (b) SECURITY OFFICER + CISO - HIPAA Security Rule compliance + technical safeguards + cybersecurity + 405d Safe Harbor; (c) GENERAL COUNSEL + LEGAL - statutory + regulatory interpretation + breach response coordination + state law analysis + BAA negotiation; (d) HR + WORKFORCE - training + sanctions + workforce-related HIPAA compliance + HITECH Workforce Development; (e) HEALTH INFORMATION MANAGEMENT (HIM) - PHI custodian + record retention + accounting of disclosures + access requests; (f) IT + EHR ADMINISTRATOR - EHR Certification + Meaningful Use/Promoting Interoperability + Information Blocking compliance + 2015 Edition Cures Update; (g) BUSINESS ASSOCIATE MANAGER - BAA inventory + tracking + sub-BA management + vendor risk;

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Tooling + EHR + cloud + compliance platform
  • Metrics + management review
  • Annual + Phase 3 audit-readiness
Where this commonly fails
  • Roles undefined
  • Tooling fragmented
  • Metrics gaps
  • OCR audit unprepared
HITECH-Sectoral-Hospitals-Health-Plans-Pharma-Tech
HITECH Sectoral Application: Hospitals, Health Plans, Pharma, Tech BAs, State Coordination, OCR Wall of Shame

HITECH sectoral application + OCR Wall of Shame. SECTOR ADOPTION: HITECH applies to ALL HIPAA covered entity + BAs handling PHI in US healthcare ecosystem + downstream subcontractor BAs. KEY SECTORS: (a) HEALTH PLANS - commercial + Medicare + Medicaid + Marketplace; major payers (UnitedHealth + Anthem + Aetna + CVS + Cigna + Humana + BCBS + Kaiser + many more); HITECH + 2013 Omnibus + recent OCR enforcement includes large health plan settlements (Anthem USD 16M + Premera USD 6.85M + Excellus USD 5.1M); (b) HEALTHCARE PROVIDERS - hospitals + health systems + ambulatory care + private practices + dentists + chiropractors + therapists + telehealth; HITECH MU/PI EHR adoption + Information Blocking + breach notification + OCR audits; major hospital systems include HCA + CommonSpirit + Tenet + Ascension + Trinity + Kaiser + Mayo + Cleveland Clinic + Johns Hopkins + Mass General Brigham + Geisi

Artefacts an auditor will ask for
  • Sectoral compliance per sector
  • Breach-history monitoring
  • Sectoral coordination engagement
Where this commonly fails
  • Sectoral application gaps
  • Breach monitoring weak
  • Sectoral coordination absent
HITECH-Status-Adoption-Vision-Cures-FutureRegulation
HITECH Status, Adoption Statistics, ARRA + Cures Act + 2024 NPRM Vision and Future Healthcare Cybersecurity

HITECH status + 2024-2025 vision. ADOPTION + IMPACT: HITECH catalyzed the most significant US healthcare IT transformation since the introduction of HIPAA + drove EHR adoption from ~10 percent of hospitals (2008) to ~96 percent (2019) + ~80 percent of physician practices; ARRA-funded EHR Incentive Programs disbursed ~USD 36 BILLION in incentive payments to providers + hospitals 2011-2021; substantially expanded HIPAA Privacy + Security Rule enforcement + 4-tier CMP structure + Business Associate direct liability + Breach Notification Rule. KEY ACHIEVEMENTS: (a) NEAR-UNIVERSAL EHR ADOPTION across US hospitals + ambulatory care; (b) MEANINGFUL USE / PROMOTING INTEROPERABILITY drove quality + interoperability advances; (c) BREACH NOTIFICATION RULE established transparency + accountability + ~5,000+ reportable breaches since 2010; (d) BUSINESS ASSOCIATE direct liability + BAA standardisation

Artefacts an auditor will ask for
  • Adoption + benchmarking
  • Cybersecurity + ransomware readiness
  • NPRM + Cures Act readiness
Where this commonly fails
  • Adoption monitoring weak
  • Cyber readiness gap
  • Future readiness lagging

HITECH Act: Statutory Scope, ARRA Title XIII Origin, 42 USC Chapter 156 Structure (Subtitles A-D)

HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles
HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)

HITECH Act statutory scope + structure. ENACTMENT: Title XIII of the American Recovery and Reinvestment Act of 2009 (ARRA, Public Law 111-5) signed 17 February 2009 + entered into force phased; codified at 42 USC Chapter 156 (Sections 17901-17953) + 26 USC Section 45R for tax provisions + amendments to 42 USC Section 1320d (HIPAA) + 45 CFR Parts 160 + 164. KEY STRUCTURE: 4 SUBTITLES. SUBTITLE A PROMOTION OF HEALTH IT (42 USC 17901-17915): Office of the National Coordinator for Health IT (ONC, established statutorily by Sec. 17901); HIT Standards Committee (Sec. 17903); HIT Policy Committee (Sec. 17902); ONC HIT Certification Program (Sec. 17905-17907); HIT Workforce Development (Sec. 17909); Meaningful Use criteria for EHR Incentive Programs (via CMS through Section 1903); Health Information Exchange (HIE) standards. SUBTITLE B TESTING OF HEALTH IT (42 USC 17916-17919): National Health I

Artefacts an auditor will ask for
  • Scope determination + applicability
  • Subtitle-specific compliance evidence
  • Definition + interpretation documentation
Where this commonly fails
  • Scope misunderstood
  • Subtitle applicability unclear
  • Definitions confused

HITECH Coordination with HIPAA Privacy + Security Rules (Verified Separately) + 21st Century Cures Act + ONC

HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC
HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC

HITECH coordination with HIPAA Privacy Rule + HIPAA Security Rule + 21st Century Cures Act + ONC. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - established 2000 + modified 2002 + significantly amended by HITECH 2009 + 2013 Omnibus Final Rule; governs PHI use + disclosure + individual rights; HITECH expanded application to BAs + strengthened individual rights + enforcement. HIPAA SECURITY RULE (45 CFR Part 164 Subpart C, SEPARATELY VERIFIED in this corpus) - established 2003 + significantly amended by HITECH 2009 + 2013 Omnibus + 2024 NPRM modernisation; administrative + physical + technical safeguards for ePHI; HITECH extended direct application to BAs + added Breach Notification Rule; 2024 NPRM proposed enhancements include MFA + encryption + asset inventory + ransomware response + vulnerability management. 2013 HIPAA OMNIBUS FINAL RULE (78 FR 5566): implementing HITECH Privac

Artefacts an auditor will ask for
  • Multi-rule compliance program
  • Information Blocking compliance evidence
  • TEFCA + QHIN participation
  • State + federal coordination
Where this commonly fails
  • Multi-rule coordination weak
  • Information Blocking compliance gap
  • TEFCA + QHIN not engaged
HITECH-Crosswalk-HIPAA-NIST-CSF-405d-Sectoral
HITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws

HITECH crosswalk to verified subordinate substantive rules + adjacent frameworks. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - primary substantive privacy controls; HITECH amendments operationalized via 2013 Omnibus Final Rule + ongoing OCR guidance. HIPAA SECURITY RULE (45 CFR Part 164 Subpart C, VERIFIED SEPARATELY in this corpus) - primary substantive security controls; administrative + physical + technical safeguards for ePHI; pending 2024-2025 NPRM modernisation. HITECH BREACH NOTIFICATION RULE (45 CFR Part 164 Subpart D) - breach definition + 4-factor risk assessment + individual + media + HHS notification SLA. NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 + 800-53 + 800-66 (HIPAA Security Rule Implementation Guide) - voluntary cybersecurity framework + recognized security practices; HHS 405d MAPPING crosswalks NIST CSF to HIPAA Security Rule. HHS 405d HEALTH INDUSTRY CYBERSECU

Artefacts an auditor will ask for
  • Multi-rule + framework compliance program
  • 405d Safe Harbor evidence
  • Information Blocking compliance
Where this commonly fails
  • Multi-rule compliance gaps
  • Safe Harbor not pursued
  • Information Blocking compliance unclear

HITECH Enforcement: 4-Tier Civil Monetary Penalties, State AGs, HHS OCR, Recent Settlements

HITECH-Enforcement-CMP-Tiers-StateAGs-OCR
HITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements

HITECH 4-tier CIVIL MONETARY PENALTIES (CMP) + enforcement (Section 17939; 45 CFR 160.404; inflation-adjusted annually). HHS OCR ENFORCEMENT AUTHORITY: HHS Office for Civil Rights (OCR) primary federal enforcer; tier-based CMPs per HIPAA Privacy + Security Rule + Breach Notification Rule violations. 4-TIER CMP STRUCTURE: TIER 1 - did not know (and through exercise of reasonable diligence would not have known) USD 100-50K per violation, USD 25K annual maximum per category (2009 amounts; inflation-adjusted to USD ~50K-USD ~134K cap as of 2024). TIER 2 - violation due to reasonable cause + not willful neglect USD 1K-50K per violation, USD 100K annual cap (adjusted to USD ~144K-USD ~287K cap). TIER 3 - violation due to willful neglect that was CORRECTED within 30 days USD 10K-50K per violation, USD 250K annual cap (adjusted to USD ~287K-USD ~430K cap). TIER 4 - violation due to willful negle

Artefacts an auditor will ask for
  • CMP risk assessment + compliance program
  • State AG monitoring
  • OCR audit-readiness
Where this commonly fails
  • CMP compliance gaps
  • State AG risk unaddressed
  • OCR audit unprepared

HITECH Subtitle A: ONC, HIT Standards, EHR Certification, Meaningful Use / Promoting Interoperability

HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PI
HITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability

HITECH Subtitle A - Promotion of Health Information Technology. OFFICE OF THE NATIONAL COORDINATOR FOR HEALTH IT (ONC, established statutorily by Sec. 17901): independent within HHS + responsible for HIT policy + standards + interoperability + Information Blocking + EHR Certification + Trusted Exchange Framework + Common Agreement (TEFCA); leadership by National Coordinator (typically MD or RN + tech background). HIT POLICY COMMITTEE (Sec. 17902, replaced 2017 by Health IT Advisory Committee) + HIT STANDARDS COMMITTEE (Sec. 17903): advise + recommend on policy + standards + criteria; multi-stakeholder including providers + payers + tech industry + patient advocates. ONC HIT CERTIFICATION PROGRAM (Sec. 17905-17907): voluntary EHR + Health IT module certification against ONC criteria including security + interoperability + usability + reporting; current criteria 2015 Edition Cures Update;

Artefacts an auditor will ask for
  • ONC-certified EHR adoption
  • MU/PI program participation
  • TEFCA + QHIN engagement
Where this commonly fails
  • ONC certification gaps
  • MU/PI participation absent
  • TEFCA + QHIN not engaged

HITECH Subtitle D: Breach Notification Rule, BA Direct Liability, Subcontractors

HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability
HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors

HITECH Subtitle D - Breach Notification + Business Associate (BA) direct liability. BREACH NOTIFICATION RULE (Section 17932; 45 CFR Part 164 Subpart D, Sections 164.400-414): covered entities + BAs must provide notification following discovery of a breach of UNSECURED PHI (PHI not rendered unusable/unreadable/indecipherable to unauthorized individuals via encryption per NIST or destruction). BREACH DEFINITION (45 CFR 164.402): acquisition + access + use + disclosure of PHI not permitted under HIPAA Privacy Rule which compromises security/privacy; presumed breach unless covered entity demonstrates LOW PROBABILITY OF COMPROMISE via 4-FACTOR RISK ASSESSMENT: (1) nature + extent of PHI + types of identifiers + re-identification risk; (2) unauthorized recipient identity + likelihood of re-disclosure; (3) actual acquisition + viewing of PHI; (4) extent of mitigation. EXCLUSIONS: unintentional

Artefacts an auditor will ask for
  • Breach response procedure + register
  • Notification procedures + templates
  • BAA templates + subcontractor management
Where this commonly fails
  • Breach notification weak
  • 60-day SLA missed
  • BAA not in place

HITECH Subtitle D: Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)

HITECH-SubtitleD-StrengthIndividualRights
HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)

HITECH Subtitle D - strengthened individual rights. ELECTRONIC ACCESS (Section 17937; 45 CFR 164.524): individuals have RIGHT TO ACCESS PHI in DESIGNATED RECORD SET + receive in ELECTRONIC FORMAT if maintained electronically (e.g. EHR); covered entity must respond within 30 days + 60-day extension if reasonable; reasonable fee for paper or electronic copy + electronic format must be readable + interoperable; right to designate third-party recipient + Right of Access Initiative is OCR enforcement priority. ACCOUNTING OF DISCLOSURES (Section 17935(c); 45 CFR 164.528): individuals have right to accounting of certain disclosures including TPO disclosures from EHR for 3 years (post-HITECH expansion); covered entity must respond within 60 days + provide list of disclosures + recipients + purposes. RESTRICTIONS ON DISCLOSURES TO HEALTH PLANS (Section 17935(a); 45 CFR 164.522(a)): patient has RI

Artefacts an auditor will ask for
  • Individual rights procedures
  • Electronic access + accounting
  • BAA marketing/fundraising terms
Where this commonly fails
  • Right of access weak
  • Accounting incomplete
  • Restriction not honored
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the HITECH Act framework page.