The HITECH Act is a federal law, signed on February 17, 2009, as part of the American Recovery and Reinvestment Act, that pushed the U.S. healthcare system onto electronic health records and gave HIPAA’s privacy and security rules real financial and criminal consequences for the first time.1Department of Health and Human Services. HITECH Act Enforcement Interim Final Rule Its full name is the Health Information Technology for Economic and Clinical Health Act. In practice, it did four big things: it paid providers to adopt digital records, it required organizations to tell patients when their data is breached, it raised the penalties for HIPAA violations dramatically, and it extended federal liability to the vendors who handle patient information on a hospital’s or insurer’s behalf.
The Push to Electronic Health Records
The centerpiece of the law was a program to replace paper charts with certified electronic health records (EHRs). Congress authorized the Medicare and Medicaid EHR Incentive Programs, which paid clinicians and hospitals to adopt digital systems and prove they were using them in ways that actually improved care.2Department of Health and Human Services. Appendix A – Medicare and Medicaid EHR Incentive Programs
The benchmarks, originally called “Meaningful Use,” were concrete. Providers had to show their systems could handle electronic prescribing, maintain current medication lists, exchange clinical summaries, and track quality measures. The requirements grew stricter in stages. Starting in 2015, providers who failed to meet them saw reductions in their Medicare reimbursement rates, not just missed bonuses.2Department of Health and Human Services. Appendix A – Medicare and Medicaid EHR Incentive Programs That combination of carrot and stick is why nearly every hospital and most physician practices now run on digital systems.3Centers for Medicare and Medicaid Services. Promoting Interoperability Programs
Stronger Patient Rights Over Health Records
HIPAA already gave patients the right to their records on paper. HITECH made that right meaningful in the digital era. If a provider stores your records electronically and you request an electronic copy, the provider has to deliver one. The law also caps what you can be charged. HHS guidance lets providers charge a flat fee of no more than $6.50 per request, or calculate actual labor and supply costs, but they cannot add search fees, administrative overhead, or third-party copy charges on top.4U.S. Department of Health and Human Services. $6.50 Flat Rate Option is Not a Cap on Fees
The Act also expanded your right to find out who has looked at your records. Earlier HIPAA rules covered only disclosures made outside routine treatment, payment, and healthcare operations. HITECH extended the accounting requirement to disclosures made through an EHR even for those routine purposes, which matters because electronic systems share records far more often than paper ever did.
Limits on Marketing and Selling Your Health Data
Covered entities now need your written authorization before using your health information for marketing, defined broadly as anything encouraging you to buy or use a product or service. Face-to-face conversations with your provider and small promotional gifts of nominal value are exempt. Most other commercial outreach requires your explicit consent first.
HITECH also restricted the outright sale of protected health information. A covered entity or business associate generally cannot take payment in exchange for your data without your written authorization. Narrow exceptions exist for public health activities, treatment purposes, and transferring records as part of a merger, but the default rule is that your health data is not for sale without your permission.
Breach Notification
The move to digital records created an obvious new risk: single incidents that expose thousands or millions of records at once. HITECH created the Breach Notification Rule, which requires covered entities and their business associates to notify affected individuals when unsecured protected health information is exposed.5U.S. Department of Health and Human Services. Breach Notification Rule
The notice has to go out without unreasonable delay and no later than 60 calendar days after the breach is discovered.6eCFR. 45 CFR 164.404 – Notification to Individuals It must describe what happened, what types of information were involved, what you can do to protect yourself, and what the organization is doing about it.5U.S. Department of Health and Human Services. Breach Notification Rule
Reporting obligations scale with size. Breaches affecting 500 or more people require immediate notice to the Secretary of Health and Human Services and to prominent media outlets in the affected area. Breaches involving fewer than 500 individuals are reported to HHS on an annual basis.7U.S. Department of Health and Human Services. HITECH Breach Notification Interim Final Rule
The Encryption Safe Harbor
There is one significant carve-out. If the breached data was properly encrypted or destroyed according to HHS guidance, it counts as “secured” and no notification is required. Encrypted data that an attacker cannot actually read does not put patients at risk. The safe harbor disappears if the attacker obtains both the encrypted data and the decryption keys.5U.S. Department of Health and Human Services. Breach Notification Rule
Civil Penalties
HITECH replaced HIPAA’s old, easily-absorbed fines with a four-tier structure based on the violator’s level of fault. The amounts adjust for inflation each year. As of 2026:8Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
- Did not know: the organization was unaware of the violation and could not reasonably have caught it. Fines run from $145 to $73,011 per violation, with an annual cap of $2,190,294 for identical violations.
- Reasonable cause: not willful neglect, but not something the organization was powerless to prevent. Penalties range from $1,461 to $73,011 per violation, same $2,190,294 annual cap.
- Willful neglect, corrected: conscious disregard that was fixed within 30 days of discovery. Minimum jumps to $14,602 per violation, maximum of $73,011, same annual cap.
- Willful neglect, not corrected: the organization knew and did not fix it. Every violation carries a minimum of $73,011, and the annual cap of $2,190,294 is also the maximum per violation.
Those numbers compound. A single compliance failure that affects multiple patients can generate separate penalties for each one, and the annual cap applies per violation type, so an organization that commits several different kinds of violations faces a separate cap for each.
Criminal Penalties
Federal law also imposes criminal penalties on anyone who knowingly obtains or discloses individually identifiable health information in violation of HIPAA. Punishment scales with intent:9Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information
- Basic violation: up to $50,000 in fines and one year in prison.
- False pretenses: if the information was obtained through deception, up to $100,000 and five years.
- Commercial or malicious intent: if the goal was to sell the data, gain a personal advantage, or cause harm, up to $250,000 and ten years.
Criminal cases are handled by the Department of Justice rather than HHS, and they are less common than civil actions. They do happen, particularly when employees snoop through patient records or sell data on the side.
Who Enforces the Law
The Office for Civil Rights (OCR) within HHS is the primary federal enforcer of HIPAA privacy and security rules. OCR investigates complaints, conducts compliance reviews, and imposes civil penalties.10U.S. Department of Health and Human Services. HIPAA Compliance and Enforcement HITECH also required OCR to run a periodic audit program that proactively checks whether organizations are following the rules, rather than waiting for a complaint or breach to trigger scrutiny.
The Act also gave State Attorneys General authority to bring civil actions in federal court on behalf of state residents whose data has been mishandled.11U.S. Department of Health and Human Services. State Attorneys General Before HITECH, HIPAA enforcement was exclusively federal. A state AG can now sue independently, without waiting for OCR to act.
Vendors and Contractors Are Directly Liable
Before HITECH, HIPAA reached only “covered entities”: healthcare providers, health plans, and clearinghouses. Outside vendors that handled patient data on their behalf, such as billing companies, IT service providers, cloud hosts, and analytics firms, were bound only by their private contracts. If a billing company caused a breach, the hospital could face penalties while the billing company itself had no direct federal liability.
HITECH ended that arrangement. Business associates are now directly subject to the HIPAA Security Rule and key provisions of the Privacy Rule, and they face the same civil and criminal penalties as the hospitals and insurers they serve. HHS formalized this through the 2013 Omnibus Rule, which also expanded the definition of “business associate” to cover any entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity.12U.S. Department of Health and Human Services. Business Associates
The chain of accountability keeps going. If a business associate hires subcontractors who handle patient data, those subcontractors are covered too. The business associate has to sign a written agreement with each subcontractor imposing the same privacy and security obligations, and if a subcontractor develops a pattern of violations, the business associate must take reasonable steps to fix the problem or end the relationship.13U.S. Department of Health and Human Services. Direct Liability of Business Associates An IT vendor that stores patient records in the cloud faces the same compliance expectations as the hospital that generated them, and OCR does not distinguish between the two when a breach investigation begins.