Medcurity Get Compliant Now

HIPAA vs HITECH Act: What Changed & Why It Matters

Last updated: March 2026 | 9 min read

Quick Answer

The HITECH Act (2009) is not separate from HIPAA but rather an amendment that strengthened it. HITECH increased penalties from $100 per violation to $100-$50,000, established mandatory breach notification requirements, and extended compliance obligations to business associates. HITECH enforcement focuses on security and breach response, making compliance much more demanding.

Understanding HIPAA vs HITECH

Many healthcare organizations and vendors mistakenly view HIPAA and HITECH as separate laws. In reality, HITECH is a component of the American Recovery and Reinvestment Act (ARRA) passed in 2009 that amended and significantly strengthened HIPAA enforcement. Understanding the relationship between these laws is critical for compliance.

HIPAA: The Foundation (1996)

HIPAA (Health Insurance Portability and Accountability Act) established the original framework for protecting health information. It created:

• Privacy Rule: Controls use and disclosure of Protected Health Information (PHI)
• Security Rule: Establishes technical and administrative safeguards for electronic PHI
• Breach Notification Rule: Originally minimal requirements for breach reporting

HITECH: The Enforcement Amendment (2009)

HITECH stands for "Health Information Technology for Economic and Clinical Health" and was designed to accelerate the adoption of electronic health records (EHRs) while increasing privacy protections. HITECH modified HIPAA by:

• Dramatically increasing civil and criminal penalties
• Expanding breach notification requirements
• Extending liability to business associates
• Strengthening security requirements for electronic health information

How HITECH Changed HIPAA Penalties

Civil Penalties Before HITECH

Under original HIPAA, civil penalties were relatively modest:

• Minimum: $100 per violation
• Maximum: $25,000 per violation per calendar year
• Limited enforcement priority or frequency

Civil Penalties After HITECH

HITECH introduced a tiered penalty structure based on the violator's knowledge of the violation:

Tier 1 (No Knowledge): $100-$50,000 per violation
Tier 2 (Reasonable Cause): $100-$50,000 per violation
Tier 3 (Willful Neglect - Corrected): $10,000-$50,000 per violation
Tier 4 (Willful Neglect - Not Corrected): $50,000 per violation (minimum)

Criminal Penalties

HITECH also introduced criminal penalties for healthcare data theft:

• Up to $250,000 in criminal fines
• Up to 10 years imprisonment
• Applied to those who knowingly obtain, disclose, or receive PHI

Annual Maximums

Under HITECH, the annual maximum penalties for violations of the same requirement in the same calendar year are:

• $1.5 million per requirement per calendar year
• $1.5 million for all violations of the Privacy Rule per year
• $1.5 million for all violations of the Security Rule per year

HITECH Breach Notification Requirements

What Changed with Breach Notification

HITECH completely overhauled breach notification requirements by:

• Requiring notification to affected individuals without unreasonable delay (no later than 60 days)
• Mandating notification to media outlets (for breaches of 500+ residents)
• Requiring notification to the Secretary of HHS
• Establishing a "presumption of breach" requiring organizations to prove no risk of harm
• Creating public database of breaches (HHS publishes on their website)

The "Presumption of Breach" Standard

HITECH introduced a critical shift: instead of requiring proof of actual harm from a breach, there is now a "presumption of breach" that applies to unsecured PHI. Organizations must demonstrate, based on a risk assessment, that there is no reasonable basis to believe that PHI has been compromised.

This means that even if you cannot confirm that data was actually misused, you may still be required to notify affected individuals.

Breach Notification Timeline

Day 1-4: Discover and document the breach
Day 1-30: Complete risk assessment
Day 1-60: Notify affected individuals
Day 1-60: Notify media (if 500+ individuals)
Day 1-60: Notify HHS Secretary

Business Associate Liability Under HITECH

Direct Liability for Business Associates

Perhaps the most significant change HITECH made was extending HIPAA requirements directly to business associates. Before HITECH, business associates had limited HIPAA obligations and many violations were only pursued against covered entities.

Business Associate Agreement Requirements

HITECH made it mandatory for covered entities to have Business Associate Agreements (BAAs) that include specific terms:

• Permitted uses and disclosures of PHI
• Safeguard requirements for PHI
• Breach notification obligations
• Subcontractor management and BAA requirements
• Audit and access rights for the covered entity
• Termination and return/destruction of PHI clauses

Examples of Business Associates

HITECH expanded the definition to include:

• Cloud storage providers storing PHI
• EHR vendors and software providers
• Medical billing and coding companies
• IT service providers and managed service providers (MSPs)
• Data destruction and shredding services
• Transcription services

Comparison Table: Pre-HITECH vs Post-HITECH HIPAA

Aspect Pre-HITECH (1996-2009) Post-HITECH (2009+)
Civil Penalties $25,000 max per violation per year $50,000 per violation, $1.5M per requirement per year
Criminal Penalties Limited criminal provisions Up to $250,000 fines, 10 years imprisonment
Breach Notification No federal requirement; varies by state Mandatory within 60 days to individuals, media, HHS
Business Associates Limited HIPAA obligations Direct HIPAA liability; BAAs required
Enforcement Focus Minimal enforcement activity Significant enforcement by HHS OCR
Breach Threshold Not standardized "Presumption of breach" unless proven otherwise
Audits Rare Regular covered entity and business associate audits

Frequently Asked Questions

Do I need to comply with both HIPAA and HITECH?

You need to comply with HIPAA rules as amended by HITECH. They are not separate compliance regimes - HITECH is part of HIPAA enforcement. When people refer to "HIPAA compliance" today, they inherently mean compliance with the HIPAA rules as strengthened by HITECH amendments.

If my organization suffered a data breach before HITECH (pre-2009), do I still face penalties?

HITECH's increased penalties apply going forward from when it was enacted (February 2009). However, breaches that occurred before HITECH but were discovered after 2009 must be notified under HITECH's requirements. Newer HITECH enforcement focuses on incidents from 2009 onward or discovered after that date.

What qualifies as a "business associate" under HITECH?

A business associate is any person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity. This includes IT vendors, billing companies, cloud providers, transcription services, and consultants. If the vendor handles any PHI, a BAA is required. The definition is broad - when in doubt, execute a BAA.

How strict are the 60-day breach notification requirements?

Very strict. "Without unreasonable delay and no later than 60 calendar days" means HHS expects notification within this window. Missing the 60-day deadline itself constitutes a HIPAA violation on top of the original breach. Organizations should aim for notification within 30 days when possible and document all efforts to meet the deadline.

Ensure HITECH Compliance with Expert Guidance

HITECH's enhanced penalties and breach notification requirements make HIPAA compliance more critical than ever. Medcurity provides comprehensive HITECH compliance audits, breach response planning, and ongoing compliance management to protect your organization.

Schedule Your HIPAA Audit