HIPAA vs HITECH Act: What Changed & Why It Matters
Quick Answer
The HITECH Act (2009) is not separate from HIPAA but rather an amendment that strengthened it. HITECH increased penalties from $100 per violation to $100-$50,000, established mandatory breach notification requirements, and extended compliance obligations to business associates. HITECH enforcement focuses on security and breach response, making compliance much more demanding.
Understanding HIPAA vs HITECH
Many healthcare organizations and vendors mistakenly view HIPAA and HITECH as separate laws. In reality, HITECH is a component of the American Recovery and Reinvestment Act (ARRA) passed in 2009 that amended and significantly strengthened HIPAA enforcement. Understanding the relationship between these laws is critical for compliance.
HIPAA: The Foundation (1996)
HIPAA (Health Insurance Portability and Accountability Act) established the original framework for protecting health information. It created:
HITECH: The Enforcement Amendment (2009)
HITECH stands for "Health Information Technology for Economic and Clinical Health" and was designed to accelerate the adoption of electronic health records (EHRs) while increasing privacy protections. HITECH modified HIPAA by:
How HITECH Changed HIPAA Penalties
Civil Penalties Before HITECH
Under original HIPAA, civil penalties were relatively modest:
Civil Penalties After HITECH
HITECH introduced a tiered penalty structure based on the violator's knowledge of the violation:
Tier 2 (Reasonable Cause): $100-$50,000 per violation
Tier 3 (Willful Neglect - Corrected): $10,000-$50,000 per violation
Tier 4 (Willful Neglect - Not Corrected): $50,000 per violation (minimum)
Criminal Penalties
HITECH also introduced criminal penalties for healthcare data theft:
Annual Maximums
Under HITECH, the annual maximum penalties for violations of the same requirement in the same calendar year are:
HITECH Breach Notification Requirements
What Changed with Breach Notification
HITECH completely overhauled breach notification requirements by:
The "Presumption of Breach" Standard
HITECH introduced a critical shift: instead of requiring proof of actual harm from a breach, there is now a "presumption of breach" that applies to unsecured PHI. Organizations must demonstrate, based on a risk assessment, that there is no reasonable basis to believe that PHI has been compromised.
This means that even if you cannot confirm that data was actually misused, you may still be required to notify affected individuals.
Breach Notification Timeline
Day 1-4: Discover and document the breach
Day 1-30: Complete risk assessment
Day 1-60: Notify affected individuals
Day 1-60: Notify media (if 500+ individuals)
Day 1-60: Notify HHS Secretary
Business Associate Liability Under HITECH
Direct Liability for Business Associates
Perhaps the most significant change HITECH made was extending HIPAA requirements directly to business associates. Before HITECH, business associates had limited HIPAA obligations and many violations were only pursued against covered entities.
Business Associate Agreement Requirements
HITECH made it mandatory for covered entities to have Business Associate Agreements (BAAs) that include specific terms:
Examples of Business Associates
HITECH expanded the definition to include:
Comparison Table: Pre-HITECH vs Post-HITECH HIPAA
| Aspect | Pre-HITECH (1996-2009) | Post-HITECH (2009+) |
|---|---|---|
| Civil Penalties | $25,000 max per violation per year | $50,000 per violation, $1.5M per requirement per year |
| Criminal Penalties | Limited criminal provisions | Up to $250,000 fines, 10 years imprisonment |
| Breach Notification | No federal requirement; varies by state | Mandatory within 60 days to individuals, media, HHS |
| Business Associates | Limited HIPAA obligations | Direct HIPAA liability; BAAs required |
| Enforcement Focus | Minimal enforcement activity | Significant enforcement by HHS OCR |
| Breach Threshold | Not standardized | "Presumption of breach" unless proven otherwise |
| Audits | Rare | Regular covered entity and business associate audits |
Frequently Asked Questions
Do I need to comply with both HIPAA and HITECH?
You need to comply with HIPAA rules as amended by HITECH. They are not separate compliance regimes - HITECH is part of HIPAA enforcement. When people refer to "HIPAA compliance" today, they inherently mean compliance with the HIPAA rules as strengthened by HITECH amendments.
If my organization suffered a data breach before HITECH (pre-2009), do I still face penalties?
HITECH's increased penalties apply going forward from when it was enacted (February 2009). However, breaches that occurred before HITECH but were discovered after 2009 must be notified under HITECH's requirements. Newer HITECH enforcement focuses on incidents from 2009 onward or discovered after that date.
What qualifies as a "business associate" under HITECH?
A business associate is any person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity. This includes IT vendors, billing companies, cloud providers, transcription services, and consultants. If the vendor handles any PHI, a BAA is required. The definition is broad - when in doubt, execute a BAA.
How strict are the 60-day breach notification requirements?
Very strict. "Without unreasonable delay and no later than 60 calendar days" means HHS expects notification within this window. Missing the 60-day deadline itself constitutes a HIPAA violation on top of the original breach. Organizations should aim for notification within 30 days when possible and document all efforts to meet the deadline.
Ensure HITECH Compliance with Expert Guidance
HITECH's enhanced penalties and breach notification requirements make HIPAA compliance more critical than ever. Medcurity provides comprehensive HITECH compliance audits, breach response planning, and ongoing compliance management to protect your organization.
Schedule Your HIPAA Audit