HIPAA HITECH Act and Technology Requirements — Questions and Answers
Question 1: What does the HITECH Act stand for and when was it enacted?
- Health Information Technology for Enhanced Clinical Health, 2011
- Health Information Technology for Economic and Clinical Health, 2009 (Correct answer)
- Healthcare Information Technology Enforcement and Compliance Health, 2010
- Health Information Technical Exchange and Clinical Health, 2008
Correct answer: Health Information Technology for Economic and Clinical Health, 2009
HITECH stands for Health Information Technology for Economic and Clinical Health Act, enacted as part of the American Recovery and Reinvestment Act of 2009.
The Health Information Technology for Economic and Clinical Health (HITECH) Act was signed into law on February 17, 2009, as Title XIII of the American Recovery and Reinvestment Act (ARRA) — the stimulus package passed during the 2008-2009 financial crisis. HITECH had two main objectives: (1) promote the adoption and meaningful use of health information technology (particularly EHRs) through financial incentives; and (2) strengthen HIPAA's privacy and security provisions. It allocated approximately $27 billion over 10 years for health IT adoption incentives.
Question 2: How did the HITECH Act change HIPAA's enforcement penalties for covered entities?
- HITECH reduced penalties to encourage voluntary compliance
- HITECH created a tiered penalty structure based on culpability with maximum penalties up to $1.9 million per violation category per year (Correct answer)
- HITECH made all HIPAA violations criminal offenses
- HITECH replaced civil penalties with mandatory corrective action plans only
Correct answer: HITECH created a tiered penalty structure based on culpability with maximum penalties up to $1.9 million per violation category per year
HITECH created a four-tier penalty structure based on the degree of culpability, dramatically increasing maximum penalties from $100 per violation to up to $50,000 per violation.
Before HITECH, HIPAA civil penalties were capped at $100 per violation with a $25,000 annual cap per violation type — widely criticized as insufficient deterrence. HITECH created four tiers based on culpability: (1) Unknowing violation: $100-$50,000 per violation; (2) Reasonable cause: $1,000-$50,000; (3) Willful neglect, corrected: $10,000-$50,000; (4) Willful neglect, not corrected: $50,000 minimum. Annual caps per violation category are up to $1.9 million. OCR has assessed penalties exceeding $3 million in single actions. HHS periodically adjusts these amounts for inflation.
Question 3: Under the HITECH Act, who became directly subject to HIPAA's Security Rule obligations for the first time?
- State health departments
- Business associates, including EHR vendors and IT contractors handling PHI (Correct answer)
- Individual physicians in private practice
- Health insurance exchanges
Correct answer: Business associates, including EHR vendors and IT contractors handling PHI
HITECH extended direct HIPAA Security Rule compliance obligations to business associates, making them directly liable for violations rather than just contractually liable through BAAs.
Prior to HITECH, business associates (vendors, contractors handling PHI) were only bound by HIPAA through their Business Associate Agreements with covered entities. If a business associate violated HIPAA, the covered entity bore the enforcement risk, not the BA directly. HITECH fundamentally changed this by making business associates directly subject to HIPAA's Security Rule provisions (and selected Privacy Rule provisions). OCR can now directly audit and penalize business associates. The 2013 Omnibus Rule further implemented this change, extending many Privacy Rule provisions to BAs as well.
Question 4: What is the 'Breach Notification Rule' that HITECH established for unsecured PHI?
- A requirement to report all security incidents to law enforcement within 24 hours
- A mandate requiring notification to affected individuals, HHS, and potentially media when unsecured PHI is breached (Correct answer)
- A rule allowing covered entities to self-insure against breach costs
- Voluntary reporting guidance for organizations discovering potential HIPAA violations
Correct answer: A mandate requiring notification to affected individuals, HHS, and potentially media when unsecured PHI is breached
HITECH's Breach Notification Rule requires mandatory notification to individuals, HHS, and potentially media when unsecured PHI is breached, within specific timeframes.
HITECH added the Breach Notification Rule (codified at 45 CFR Part 164, Subpart D). When unsecured PHI is breached, covered entities must: notify affected individuals without unreasonable delay (max 60 days); notify HHS (immediately for 500+ affected, annually for smaller breaches); notify prominent media for breaches affecting 500+ in a state. Business associates must notify covered entities promptly. 'Unsecured' means PHI not rendered unreadable/indecipherable through approved methods (encryption to NIST standards; physical destruction). Encrypted PHI breaches are presumed safe harbors.
Question 5: What technology 'safe harbor' did HITECH create for breached PHI?
- Using any password protection on electronic files containing PHI
- Encrypting PHI using NIST-approved methods, which renders a breach presumptively non-reportable (Correct answer)
- Storing all PHI on US-based servers
- Using two-factor authentication for all PHI access
Correct answer: Encrypting PHI using NIST-approved methods, which renders a breach presumptively non-reportable
HITECH created a safe harbor from breach notification for PHI encrypted using NIST-approved standards — encrypted data breached is presumptively not a reportable breach.
HITECH's breach notification rules include a significant safe harbor: if PHI is rendered 'unreadable, unusable, or indecipherable to unauthorized individuals' through methods specified in HHS guidance, a breach of that data is presumptively not a reportable breach. HHS guidance (based on NIST SP 800-111) specifies valid encryption algorithms (AES-256 being the current standard). This safe harbor applies to both data at rest and in transit. The practical implication is that organizations encrypting PHI are largely protected from breach notification obligations and the associated reputational, financial, and regulatory consequences.
Question 6: Under HITECH, what is the maximum daily penalty cap for violations of the same type in a single calendar year?
- $100,000
- $500,000
- $1,000,000
- $1,900,000 (Correct answer)
Correct answer: $1,900,000
HITECH capped annual civil monetary penalties at $1.9 million per violation category per calendar year (adjusted for inflation by HHS).
HITECH set the annual cap at $1.5 million per violation category per calendar year, subsequently adjusted for inflation to approximately $1.9 million. This cap applies per violation 'of an identical requirement or prohibition.' Importantly, an organization can face multiple $1.9 million caps simultaneously if they have violated multiple provisions — for example, failing to provide patient access AND failing to implement risk analysis AND failing to train workforce could theoretically result in three separate annual caps applied. The largest OCR settlements have exceeded $5 million, often involving multiple violation categories.
Question 7: What did HITECH require regarding state attorneys general and HIPAA enforcement?
- HITECH removed state authority over health information privacy
- HITECH authorized state attorneys general to bring civil actions for HIPAA violations affecting state residents (Correct answer)
- States were prohibited from enacting stricter privacy laws after HITECH
- Only the federal government retained enforcement authority under HITECH
Correct answer: HITECH authorized state attorneys general to bring civil actions for HIPAA violations affecting state residents
HITECH gave state attorneys general independent authority to bring civil suits for HIPAA violations affecting their residents, creating a second enforcement track beyond federal OCR.
HITECH added 42 U.S.C. §1320d-5(d), authorizing state attorneys general to file civil lawsuits in federal district courts on behalf of state residents harmed by HIPAA violations. States can seek actual damages and up to $25,000 per violation per year. Several states (Connecticut, Massachusetts, Indiana) have pursued HIPAA enforcement actions against covered entities. States may also have their own, stricter health privacy laws (California's CMIA, Texas Health & Safety Code) — HIPAA preempts only state laws that are less protective, not those providing greater protections.
Question 8: How did HITECH change the HIPAA requirement for accounting of disclosures when EHRs are used?
- HITECH eliminated the accounting of disclosures requirement
- HITECH required covered entities using EHRs to account for treatment, payment, and operations disclosures upon request (Correct answer)
- HITECH limited accounting to only third-party disclosures outside the covered entity
- No changes to accounting of disclosures were made by HITECH
Correct answer: HITECH required covered entities using EHRs to account for treatment, payment, and operations disclosures upon request
HITECH expanded accounting of disclosures to include treatment, payment, and operations disclosures made through EHRs when patients request this information.
Under the original HIPAA Privacy Rule, accounting of disclosures (45 CFR §164.528) excluded disclosures for treatment, payment, and operations (TPO) — the most common reasons for disclosure. HITECH §13405(c) changed this for organizations using EHRs: patients may request an accounting of all disclosures including TPO made through EHR systems, going back 3 years (vs. 6 years for non-EHR disclosures). This provision was controversial and its implementation was delayed multiple times. As of 2023, HHS issued updated rules reflecting this HITECH requirement, though full implementation remains phased.
Question 9: What was the purpose of HITECH's 'Meaningful Use' program as it relates to health technology?
- To mandate specific EHR software vendors for all healthcare providers
- To create financial incentives for providers adopting certified EHR technology and demonstrating its effective use (Correct answer)
- To eliminate paper records within 5 years
- To subsidize cybersecurity programs for small practices only
Correct answer: To create financial incentives for providers adopting certified EHR technology and demonstrating its effective use
Meaningful Use created Medicare and Medicaid financial incentives for providers adopting and meaningfully using certified EHR technology that met specific security and interoperability criteria.
HITECH allocated $27 billion for Medicare and Medicaid EHR Incentive Programs (Meaningful Use). Eligible providers and hospitals could receive up to $44,000 (Medicare) or $63,750 (Medicaid) for demonstrating meaningful use of certified EHR technology through three stages: basic data capture (Stage 1), improved clinical processes (Stage 2), and improved outcomes (Stage 3). The stick: providers failing to achieve Meaningful Use faced Medicare/Medicaid payment reductions starting in 2015. The program was renamed 'Promoting Interoperability' in 2018, with renewed focus on EHR interoperability and patient access.
Question 10: Under HITECH, what minimum security standard applies to PHI transmitted via email?
- Standard email without additional security is acceptable for PHI transmission
- PHI in email must be encrypted using NIST-approved encryption to receive the breach notification safe harbor (Correct answer)
- Email can never be used for PHI regardless of encryption
- Only encrypted email to other covered entities is permitted
Correct answer: PHI in email must be encrypted using NIST-approved encryption to receive the breach notification safe harbor
HITECH's breach safe harbor requires NIST-approved encryption for PHI in email; unencrypted PHI emails that are intercepted constitute reportable breaches.
HITECH's breach notification safe harbor (reflected in HHS guidance) applies when PHI is encrypted per NIST standards. For email, this means using transport layer encryption (TLS) for email in transit AND file-level or message-level encryption for email at rest (if stored on email servers). Most standard email systems use TLS for transit, but this may not be sufficient for all threat models. Best practices for healthcare PHI email include: end-to-end encryption, secure email gateways, and patient portal messaging as alternatives. If an unencrypted email containing PHI is intercepted or accessed by unauthorized parties, it is a reportable breach.
Question 11: How did HITECH affect the civil money penalty ranges for Business Associates under HIPAA?
- Business associates cannot be subject to civil money penalties, only breach notification requirements
- HITECH made business associates directly subject to the same civil money penalty tiers as covered entities (Correct answer)
- Business associate penalties are capped at one-tenth of covered entity penalties
- Only criminal penalties, not civil penalties, apply to business associates
Correct answer: HITECH made business associates directly subject to the same civil money penalty tiers as covered entities
HITECH subjected business associates to the same four-tier civil money penalty structure as covered entities, enabling OCR to directly fine BAs for HIPAA Security Rule violations.
HITECH §13401 directly applied HIPAA Security Rule requirements to business associates, and §13404 made Security Rule administrative safeguards directly applicable to BAs. The 2013 Omnibus Rule codified this, establishing that BAs are directly liable for the same Security Rule standards as covered entities and subject to the same civil money penalty tiers. OCR has directly investigated and penalized business associates — for example, the $650,000 settlement with Business Associate Cottage Health in 2018. This fundamentally changed the risk calculus for companies handling healthcare data.
Question 12: What is the HITECH requirement regarding the 'right to restrict' PHI disclosures?
- HITECH eliminated the right to restrict as too burdensome
- If a patient pays out-of-pocket in full for a service, they may restrict disclosure of that service to their health plan (Correct answer)
- Restrictions can only be requested on paper records, not EHR data
- The right to restrict only applies to disclosures to employers
Correct answer: If a patient pays out-of-pocket in full for a service, they may restrict disclosure of that service to their health plan
HITECH strengthened the right to restrict by requiring covered entities to honor requests to restrict disclosure to health plans when the patient pays in full out-of-pocket.
Under original HIPAA, covered entities could deny requests to restrict disclosures for treatment, payment, and operations. HITECH §13405(a) created a mandatory exception: if a patient pays out-of-pocket in full for a specific healthcare item or service, the covered entity must restrict disclosure of that item/service to the patient's health plan. This is particularly relevant for patients seeking treatment they don't want their insurer to know about (e.g., mental health services, reproductive health, substance abuse). The restriction must be honored even for EHR-based disclosures, which creates technical implementation challenges.
Question 13: What technology requirement did HITECH add for HIPAA regarding notification when ePHI is accessed by employees?
- Automatic notification to patients when employees access their records
- System capability to generate audit reports of which employees accessed which patient records, available to patients upon request (Correct answer)
- Notification to OCR within 24 hours of any employee accessing PHI
- Real-time notification to supervisors of all PHI access
Correct answer: System capability to generate audit reports of which employees accessed which patient records, available to patients upon request
HITECH required EHR systems to include audit capabilities allowing generation of reports showing employee access to patient records, available to patients requesting accounting of disclosures.
HITECH §13405(c) combined with its accounting of disclosures expansion means that patients may request to know which workforce members accessed their EHR records. EHR systems certified under Meaningful Use must include audit report functionality capable of generating this information. While the specific mechanism for patient access to this information is still being implemented through HHS regulations, the underlying technology requirement is clear: EHRs must maintain sufficiently detailed audit logs to support employee-level access reporting. This requirement has significant implications for organizational transparency and workforce accountability.
Question 14: Under HITECH, what additional breach notification obligation applies when a breach affects 500 or more individuals in a single state?
- The state's insurance commissioner must be notified
- Prominent media outlets serving the affected state or jurisdiction must be notified (Correct answer)
- The breach must be disclosed at a public press conference
- Notification must be published in the Federal Register
Correct answer: Prominent media outlets serving the affected state or jurisdiction must be notified
HITECH requires notification to prominent media outlets in states where 500 or more residents are affected by a breach, in addition to individual and HHS notifications.
45 CFR §164.406 requires media notification when a breach affects 500 or more residents of a state or jurisdiction. The notice must be provided to prominent media outlets (major TV stations, newspapers) serving the affected area without unreasonable delay and no later than 60 days after discovery. This requirement means significant healthcare data breaches become public news, creating reputational damage beyond regulatory penalties. 'Prominent' is not precisely defined but generally means major broadcast media or newspapers with wide circulation. Some organizations preemptively issue press releases to control the narrative.
Question 15: How did HITECH change the HIPAA authorization requirements for using PHI in marketing?
- HITECH eliminated all authorization requirements for marketing PHI
- HITECH prohibited the use of PHI for marketing without individual authorization, with limited exceptions for face-to-face communications (Correct answer)
- HITECH allowed health insurers unrestricted use of PHI for wellness marketing
- No changes to marketing authorization requirements were made by HITECH
Correct answer: HITECH prohibited the use of PHI for marketing without individual authorization, with limited exceptions for face-to-face communications
HITECH strengthened marketing restrictions by prohibiting the sale or use of PHI for marketing communications without authorization, limiting exceptions to face-to-face communications.
HITECH §13406 significantly restricted marketing uses of PHI. Under original HIPAA, 'marketing' excluded communications about a covered entity's own services and treatment recommendations. HITECH limited exceptions further: subsidized (paid) communications promoting a third party's products or services now require authorization even if they appear as care recommendations. Health plans cannot use PHI for marketing if receiving payment from third parties. Communications from the covered entity about treatment alternatives or health-related products must meet strict criteria. The 2013 Omnibus Rule clarified that financial remuneration triggers the authorization requirement for what would otherwise be permitted health communications.
Question 16: What did HITECH add regarding individual access rights to electronic PHI?
- HITECH eliminated the right to electronic copies of PHI as too burdensome for providers
- HITECH required covered entities to provide individuals with electronic copies of their ePHI if the individual requests it and a designated record set is maintained electronically (Correct answer)
- Electronic access is limited to records less than 3 years old
- Patients can only access ePHI through the covered entity's patient portal
Correct answer: HITECH required covered entities to provide individuals with electronic copies of their ePHI if the individual requests it and a designated record set is maintained electronically
HITECH required covered entities maintaining PHI in an EHR to provide patients with electronic copies upon request, a right not clearly established under original HIPAA.
HITECH §13405(e) required that if a covered entity uses an EHR to maintain a designated record set, the individual has the right to obtain an electronic copy of PHI in the form requested, if readily producible, or in a standard electronic format. This was later reinforced by the 21st Century Cures Act and ONC interoperability rules requiring API-based patient access. The 2020 HHS updates to the access rule require electronic delivery capabilities and prohibit information blocking. Fees for electronic copies must be reasonable and cost-based — the marginal cost of electronic production, not the cost of paper copies.
Question 17: What specific technology standard did HITECH reference for acceptable encryption of PHI to qualify for the breach notification safe harbor?
- Any commercial encryption product available in the market
- NIST Special Publication guidelines for valid encryption methods (Correct answer)
- DES encryption at minimum
- TLS 1.0 or higher for all PHI transmissions
Correct answer: NIST Special Publication guidelines for valid encryption methods
HITECH referenced NIST Special Publication guidance (specifically NIST SP 800-111 and related publications) to define what constitutes acceptable encryption for the breach safe harbor.
HITECH directed HHS to issue guidance specifying encryption and destruction technologies that would render PHI unreadable, unusable, and indecipherable for breach safe harbor purposes. HHS guidance references NIST SP 800-111 (for data at rest) and FIPS 140-2 validated modules. Acceptable encryption includes AES with 128-bit or longer keys for data at rest. For data in motion, NIST SP 800-52 guidelines apply (TLS 1.2 or higher currently recommended, with 1.0/1.1 deprecated). Simply having encryption enabled is insufficient — the encryption must comply with these NIST standards to qualify for safe harbor treatment.
Question 18: How did HITECH change the prohibition on 'selling' PHI?
- HITECH created a market for PHI sales with regulatory oversight
- HITECH prohibited the sale of PHI without individual authorization, with limited exceptions (Correct answer)
- HITECH only prohibited selling PHI to foreign entities
- Selling PHI was already prohibited before HITECH and no change was made
Correct answer: HITECH prohibited the sale of PHI without individual authorization, with limited exceptions
HITECH explicitly prohibited the sale of PHI without individual authorization, clarifying that selling PHI — even for research — requires authorization unless specific exceptions apply.
HITECH §13405(d) explicitly prohibited covered entities and business associates from receiving remuneration in exchange for PHI without individual authorization, unless specific exceptions apply. Exceptions include: public health activities, research with appropriate authorization or waiver, treatment and payment operations, and services provided to the covered entity. This provision directly targeted data broker activities and commercial health data marketplaces. The 2013 Omnibus Rule codified this at 45 CFR §164.502(a)(5)(ii). Organizations must be vigilant that analytics partnerships, research collaborations, and data sharing arrangements don't inadvertently constitute prohibited PHI sales.
Question 19: Under HITECH, what requirement was added for notifying individuals when their PHI was accessed by their employer through a health plan?
- Employers were given broader access to employee PHI through health plans
- Health plans must notify individuals when their PHI is requested by their employer (Correct answer)
- Employers can access employee PHI without restriction for workplace wellness programs
- No changes to employer access restrictions were made by HITECH
Correct answer: Health plans must notify individuals when their PHI is requested by their employer
HITECH strengthened protections against employer access to PHI through health plan arrangements, requiring notification to individuals of such requests.
HITECH §13405(b) prohibited health plans from disclosing PHI to employers (as sponsors of group health plans) in ways not expressly permitted, and reinforced notification requirements. Under 45 CFR §164.504(f), group health plans have specific restrictions on disclosing PHI to plan sponsors (employers). Employers may only receive summary health information for plan administration or enrollment/disenrollment purposes unless they amend the plan to include additional privacy protections. Employees must be notified in the Notice of Privacy Practices of any employer access limitations. HITECH tightened enforcement of these provisions.
Question 20: What was the significance of HITECH's creation of a 'tiered' penalty structure rather than a flat per-violation fee?
- It reduced penalties for all organizations to encourage self-reporting
- It calibrates penalties to the degree of culpability, creating stronger deterrence for negligent behavior while allowing proportionality for unknowing violations (Correct answer)
- It only affected penalties for small organizations
- The tiered structure was designed to generate more government revenue
Correct answer: It calibrates penalties to the degree of culpability, creating stronger deterrence for negligent behavior while allowing proportionality for unknowing violations
The tiered structure creates proportional deterrence — smaller penalties for genuinely unknowing violations, maximum penalties for willful neglect — incentivizing organizations to invest in compliance.
Pre-HITECH's flat $100 per violation fee (max $25,000/year) provided minimal deterrence for large organizations. HITECH's four tiers recognize that violations range from genuine unknowing mistakes to deliberate disregard. Tier 4 (willful neglect not corrected: minimum $50,000) creates powerful deterrence for organizations that know they are non-compliant but don't fix it. Tier 1 (unknowing: $100-$50,000) allows proportional treatment of organizations that had reasonable compliance programs but still had a violation. This structure incentivizes investment in compliance programs — demonstrating reasonable cause or unknowing violation significantly limits potential penalties.
Question 21: How does HITECH's requirement for reporting breaches to HHS work for smaller breaches affecting fewer than 500 individuals?
- Breaches affecting fewer than 500 individuals do not need to be reported to HHS
- Covered entities must log smaller breaches and submit an annual summary to HHS no later than 60 days after each calendar year (Correct answer)
- Small breaches must be reported to HHS within 30 days
- Only breaches affecting 250 or more individuals require HHS reporting
Correct answer: Covered entities must log smaller breaches and submit an annual summary to HHS no later than 60 days after each calendar year
For breaches affecting fewer than 500 individuals, HITECH requires covered entities to maintain a log and report to HHS annually, not immediately.
45 CFR §164.408(c) establishes that for breaches affecting fewer than 500 individuals, covered entities must maintain a log of all such breaches and submit the log to HHS no later than 60 days after the end of each calendar year. This is in contrast to the immediate (within 60 days of discovery) HHS reporting requirement for breaches affecting 500 or more. All these smaller breaches appear on the HHS 'Wall of Shame' (the public breach portal) after annual submission. Covered entities must still notify affected individuals within 60 days regardless of breach size. The annual log must include all required elements of breach notification.
Question 22: Under HITECH, what technology requirement did HHS add for covered entities to establish policies regarding workforce member misconduct?
- HITECH required all workforce members to pass annual polygraph tests
- HITECH required covered entities to have sanction policies for workforce members who access or disclose PHI inappropriately, with enhanced enforcement mechanisms (Correct answer)
- No new workforce technology policies were required by HITECH
- HITECH only required policies for clinical staff
Correct answer: HITECH required covered entities to have sanction policies for workforce members who access or disclose PHI inappropriately, with enhanced enforcement mechanisms
HITECH strengthened HIPAA's sanction policy requirements and gave OCR authority to mandate corrective action plans including workforce compliance programs.
HITECH enhanced HIPAA's workforce compliance requirements by: increasing OCR enforcement authority, mandating corrective action plans (CAPs) in resolution agreements, and requiring compliance programs as part of settlements. When OCR investigates violations, standard corrective action plans include: comprehensive risk analysis, updated policies and procedures, workforce training programs, and regular monitoring and reporting. HITECH also required HHS to conduct periodic audits of covered entities and BAs, with audit protocols specifically examining workforce training and sanction policies. This created accountability for organizations that had compliant-looking policies but didn't actually implement or enforce them.
Question 23: What aspect of mobile device use does HITECH most directly impact for covered entities?
- HITECH prohibits all mobile device use for PHI access
- HITECH's encryption safe harbor incentivizes encrypting all mobile devices that store or access ePHI (Correct answer)
- Mobile devices are exempt from HIPAA under HITECH provisions
- HITECH requires all employees to use government-issued mobile devices
Correct answer: HITECH's encryption safe harbor incentivizes encrypting all mobile devices that store or access ePHI
HITECH's encryption safe harbor creates a strong financial incentive to encrypt mobile devices — unencrypted lost/stolen devices containing PHI trigger breach notification obligations.
HITECH's breach notification safe harbor (and its substantial penalties for reportable breaches) has made mobile device encryption a de facto requirement for covered entities. Lost or stolen mobile devices containing unencrypted PHI are among the most common reportable HIPAA breaches. When a device is encrypted to NIST standards, loss or theft is not a reportable breach. Without encryption, losing a device triggers notification to patients, HHS, and potentially media — plus potential penalty of up to $1.9 million. Mobile Device Management (MDM) solutions that enforce encryption, enable remote wipe, and require PINs are now standard healthcare IT.
Question 24: How did HITECH change obligations for Business Associates regarding breach discovery and notification?
- Business associates have no independent breach notification obligations
- Business associates must notify covered entities of breaches within 60 days of discovery, and may be held directly liable for breach-related penalties (Correct answer)
- Business associates must notify patients directly within 24 hours of discovering a breach
- HITECH eliminated the need for business associates to report breaches
Correct answer: Business associates must notify covered entities of breaches within 60 days of discovery, and may be held directly liable for breach-related penalties
HITECH made business associates directly responsible for breach discovery and notification to covered entities, with direct liability for delays or failures.
45 CFR §164.410 requires business associates to notify covered entities of breaches 'without unreasonable delay and in no case later than 60 days following discovery of a breach.' In practice, BAAs typically require faster notification (24-72 hours) to give covered entities enough time to fulfill their own 60-day notification obligation. HITECH made business associates directly liable for failure to notify covered entities — OCR can penalize the BA directly. The BA must provide the covered entity with all information needed for the notification, to the extent available. If the BA's delay causes the covered entity to miss the 60-day deadline, both entities may face penalties.
Question 25: What was HITECH's impact on the use of PHI for research purposes?
- HITECH completely prohibited all use of PHI for research
- HITECH maintained research exceptions but required BAAs with research institutions handling PHI and strengthened accounting of disclosures for research uses (Correct answer)
- Research uses of PHI were expanded and de-regulated under HITECH
- HITECH created a separate research exemption outside HIPAA's scope
Correct answer: HITECH maintained research exceptions but required BAAs with research institutions handling PHI and strengthened accounting of disclosures for research uses
HITECH maintained research exceptions under HIPAA but subjected research-related business associates to direct HIPAA obligations and strengthened accountability requirements.
HITECH did not fundamentally alter research exceptions under HIPAA (waivers of authorization through IRBs, limited data sets, de-identified data). However, by making business associates directly subject to HIPAA, HITECH brought research institutions and data repositories handling PHI under direct HIPAA compliance obligations. Research-related PHI flows must now comply with both HIPAA (privacy) and the Common Rule (human subjects research). HITECH's expanded accounting of disclosures also means research uses of PHI are potentially subject to patient inquiry. BAAs with academic medical centers, research CROs, and analytics firms became enforceable HIPAA contracts rather than merely contractual protections.
Question 26: Which provision of HITECH most directly addressed the problem of 'willful neglect' of HIPAA compliance that was prevalent before its enactment?
- The Meaningful Use incentive program
- The mandatory investigation of willful neglect complaints and imposition of civil money penalties for willful neglect not corrected (Correct answer)
- The extension of HIPAA to business associates
- The breach notification safe harbor for encrypted data
Correct answer: The mandatory investigation of willful neglect complaints and imposition of civil money penalties for willful neglect not corrected
HITECH mandated that OCR investigate potential willful neglect violations and imposed minimum penalties of $10,000-$50,000 per violation for willful neglect, with no discretion to waive penalties.
Before HITECH, OCR had broad discretion not to impose civil money penalties — and rarely used them. Organizations could essentially choose not to comply with HIPAA with limited practical risk. HITECH §13410(a) required HHS to formally investigate complaints indicating willful neglect of HIPAA compliance and mandated imposition of civil money penalties for willful neglect. OCR cannot waive penalties for willful neglect not corrected. This provision, combined with the dramatically increased penalty tiers, fundamentally changed the HIPAA enforcement landscape from essentially voluntary to a regime with real financial consequences for non-compliance.
Question 27: Which HITECH provision specifically addressed the problem of organizations that lacked proper safeguards but had never been investigated by HHS?
- The Meaningful Use program
- The mandate for HHS to conduct periodic audits of covered entities and business associates (Correct answer)
- The enhanced penalty structure for repeat violations
- The state attorney general enforcement provision
Correct answer: The mandate for HHS to conduct periodic audits of covered entities and business associates
HITECH directed HHS to conduct regular compliance audits, creating proactive oversight rather than relying solely on complaint-driven enforcement.
HITECH §13411 mandated that the HHS Secretary conduct periodic audits of covered entities and business associates to ensure compliance with HIPAA Privacy and Security Rules. This created the OCR HIPAA Audit Program, which began pilot audits in 2011-2012, Phase 1 audits in 2012, and Phase 2 audits in 2016-2017. Audit protocols examine dozens of compliance criteria across Privacy Rule, Security Rule, and Breach Notification Rule requirements. Audits are random — organizations don't need a complaint filed against them to be audited. This shifted HIPAA compliance from a 'react to complaints' model to a 'demonstrate ongoing compliance' model.
Question 28: Under HITECH, what is the maximum penalty per violation for 'willful neglect' that is NOT corrected within 30 days of discovery?
- $10,000 per violation
- $25,000 per violation
- $50,000 per violation (Correct answer)
- $100,000 per violation
Correct answer: $50,000 per violation
Willful neglect not corrected within 30 days carries a minimum penalty of $50,000 per violation under HITECH's tier 4 penalty structure.
HITECH's four penalty tiers (now codified at 45 CFR §160.404) for tier 4 (willful neglect — not corrected): minimum $50,000 per violation, maximum $50,000 per violation, with the annual cap at approximately $1.9 million per violation category. The 30-day correction window is significant: organizations that discover they have been willfully neglecting HIPAA and immediately take corrective action may qualify for Tier 3 (willful neglect — corrected: $10,000-$50,000 per violation). This creates a regulatory incentive for self-discovery and prompt remediation. Note that 'willful neglect' means conscious, intentional failure or reckless indifference to the obligation to comply.
Question 29: HITECH required that HHS allocate a percentage of HIPAA civil money penalties to harmed individuals. What was this provision designed to accomplish?
- It was designed to fund the HHS audit program
- It acknowledged that HIPAA violations cause real harm to individuals and created a mechanism to potentially compensate them (Correct answer)
- The provision was never implemented due to administrative complexity
- It redirected penalties from the federal treasury to state governments
Correct answer: It acknowledged that HIPAA violations cause real harm to individuals and created a mechanism to potentially compensate them
HITECH directed HHS to establish a methodology for distributing portions of CMPs and settlements to harmed individuals, recognizing that PHI breaches cause real damage.
HITECH §13410(c)(3) directed HHS to establish a methodology for distributing a percentage of civil money penalties and settlement proceeds to individuals harmed by HIPAA violations. This was a significant shift from HIPAA's original framework, which directed all penalties to the federal general fund. While implementation has been slow and the amount available per victim from large settlements remains modest, the provision acknowledged that privacy violations cause real harm — emotional distress, financial harm from identity theft, discrimination — that individuals should receive some compensation for. This aligns HIPAA enforcement more closely with a victim-compensation model.
Question 30: Under HITECH, what is the requirement for covered entities regarding notification when PHI is acquired or viewed without authorization?
- Notification is only required if PHI is definitely viewed, not just accessed
- Covered entities must provide notification when unsecured PHI is acquired or viewed following the presumption of breach analysis (Correct answer)
- Notification is only triggered if an unauthorized person removes PHI from the facility
- Only electronic access requires notification; paper record unauthorized viewing does not
Correct answer: Covered entities must provide notification when unsecured PHI is acquired or viewed following the presumption of breach analysis
HITECH's breach notification applies when unsecured PHI is accessed, acquired, used, or disclosed without authorization — including viewing — unless the four-factor risk analysis shows low probability of compromise.
HITECH's breach definition (45 CFR §164.402) includes 'acquisition, access, use, or disclosure of protected health information' without authorization. This explicitly includes mere viewing — if an unauthorized person views a screen containing PHI or is briefly exposed to information not intended for them, that is an unauthorized access. However, the four-factor risk assessment may determine the probability of harm is low (e.g., an employee who accidentally sees PHI on a colleague's screen and immediately looks away, with no indication the information was retained or used). The assessment still must be documented. HITECH created a presumption of breach; the covered entity must demonstrate low risk to overcome that presumption.
Question 31: What specific provision of HITECH addressed the use of PHI for fundraising activities by covered entities?
- HITECH prohibited all fundraising contact with patients
- HITECH required that fundraising communications include a clear opt-out mechanism and limited the PHI that could be used for fundraising without authorization (Correct answer)
- HITECH had no provisions regarding fundraising use of PHI
- HITECH required explicit opt-in consent before any fundraising contact with patients
Correct answer: HITECH required that fundraising communications include a clear opt-out mechanism and limited the PHI that could be used for fundraising without authorization
HITECH restricted PHI use for fundraising and required clear opt-out mechanisms in fundraising communications, limiting the information covered entities could use without authorization.
HITECH §13406(b) modified HIPAA's fundraising provisions, limiting the PHI covered entities could use for fundraising to: department of service, treating physician, outcome information, and health insurance status. It required that fundraising communications include a clear and conspicuous opportunity to opt out of future communications. Patients who opt out must be honored — no further fundraising contact. The 2013 Omnibus Rule codified these changes at 45 CFR §164.514(f). Hospital foundations that use PHI for donor development programs must ensure their processes comply with these restrictions and maintain opt-out records.
Question 32: Under HITECH, what happened to the period for which an accounting of disclosures must be maintained when an EHR is used?
- The accounting period was extended from 6 years to 10 years for EHR disclosures
- The accounting period was shortened to 3 years (from 6) for disclosures made through EHR systems (Correct answer)
- No change to the accounting period was made by HITECH
- HITECH eliminated the accounting requirement for EHR-based disclosures
Correct answer: The accounting period was shortened to 3 years (from 6) for disclosures made through EHR systems
For EHR-based treatment, payment, and operations disclosures, HITECH reduced the accounting look-back period to 3 years from the standard 6-year period.
HITECH §13405(c) created a modified accounting requirement for EHR disclosures: if a covered entity uses an EHR, patients may request an accounting of disclosures for treatment, payment, and operations (TPO) purposes, which were previously exempt. However, the look-back period for these EHR-based TPO disclosures is 3 years (not the standard 6 years). This acknowledges the practical limitation — requiring 6-year accounting of all EHR-based TPO disclosures would be operationally burdensome. For non-EHR systems and for non-TPO disclosures, the 6-year standard applies. Implementation of this provision has been delayed through regulatory action, with HHS still working on the implementing regulations.
Question 33: What HITECH requirement specifically addressed text messaging and other new communication technologies used by healthcare providers?
- HITECH banned text messaging for all PHI communications
- HITECH's encryption and security requirements implicitly apply to any technology used to transmit ePHI, including text messages (Correct answer)
- Text messaging was exempted from HIPAA under HITECH's innovation provisions
- Only secure messaging platforms approved by HHS may be used for clinical communications
Correct answer: HITECH's encryption and security requirements implicitly apply to any technology used to transmit ePHI, including text messages
HITECH's security requirements apply to all electronic PHI regardless of the technology used — including text messages, which are generally not HIPAA-compliant without additional security measures.
HITECH's strengthening of HIPAA's Security Rule and the breach notification encryption safe harbor effectively requires that all electronic PHI transmissions use appropriate security measures. Standard SMS text messages sent through cellular carriers are not encrypted and are not HIPAA-compliant for transmitting PHI. If a provider texts a patient's diagnosis to a colleague via standard SMS and the message is intercepted, it is a breach of unsecured PHI with no safe harbor. Compliant alternatives include: HIPAA-compliant secure messaging platforms (TigerConnect, Imprivata Cortext), encrypted email with BAA, patient portal messaging. Many healthcare organizations have implemented secure messaging policies specifically addressing this issue.
Question 34: Under HITECH, what minimum standard applies to the format in which covered entities must provide individuals with electronic copies of their PHI?
- All electronic PHI must be provided in PDF format only
- The covered entity must provide ePHI in the form and format requested if readily producible; otherwise in a readable electronic form (Correct answer)
- Electronic copies are only required in the EHR's native format
- No format requirements exist — any electronic format satisfies the requirement
Correct answer: The covered entity must provide ePHI in the form and format requested if readily producible; otherwise in a readable electronic form
HITECH requires covered entities to provide electronic PHI in the format requested if readily producible, or a readable electronic alternative — not just whatever is most convenient for the provider.
HITECH §13405(e) requires covered entities using EHRs to provide individuals with electronic copies of their PHI 'in the electronic form and format requested by the individual, if it is readily producible in such form and format; or, if not, in a readable electronic form and format as agreed to by the covered entity and the individual.' This provision was strengthened by the 2020 HHS right of access updates, which established that covered entities must provide electronic PHI in commonly used formats (PDF, C-CDA, etc.) and that format availability must be disclosed. Refusing to provide commonly available formats simply to avoid work violates this requirement.
Question 35: How did HITECH change HIPAA's approach to the 'harm' threshold for breach notification?
- HITECH added a significant harm threshold — only breaches causing actual harm require notification
- HITECH eliminated the harm threshold, replacing it with a presumption that all unauthorized PHI access is a breach unless a risk assessment shows low probability of harm (Correct answer)
- HITECH required proof of identity theft before notification obligations arise
- No change to the harm threshold was made by HITECH
Correct answer: HITECH eliminated the harm threshold, replacing it with a presumption that all unauthorized PHI access is a breach unless a risk assessment shows low probability of harm
HITECH replaced a subjective harm threshold with a presumption of breach, requiring notification unless a four-factor risk assessment demonstrates low probability that PHI was compromised.
An early version of the breach notification rule included a 'significant harm' threshold — only breaches posing significant risk of financial, reputational, or other harm required notification. This was criticized as too subjective. The final HITECH implementing regulations replaced this with a presumption of breach: all unauthorized acquisition, access, use, or disclosure of unsecured PHI is presumed to be a reportable breach UNLESS the covered entity can demonstrate through a four-factor risk assessment that there is low probability that PHI was compromised. The four factors: nature/extent of PHI; who accessed it; whether PHI was actually acquired or viewed; and extent to which risk was mitigated. If low probability cannot be established, notification is required.
Question 36: What is the relationship between HITECH's Meaningful Use incentives and HIPAA Security Rule compliance?
- Meaningful Use participation exempts covered entities from HIPAA Security Rule requirements
- Meaningful Use Stage 1 and 2 required security risk analysis as a core objective, making HIPAA Security compliance a condition of receiving incentive payments (Correct answer)
- Security Rule compliance is entirely separate from Meaningful Use qualification
- Meaningful Use only addresses privacy, not security requirements
Correct answer: Meaningful Use Stage 1 and 2 required security risk analysis as a core objective, making HIPAA Security compliance a condition of receiving incentive payments
Meaningful Use's core measures included conducting a security risk analysis per HIPAA's Security Rule, directly tying HIPAA security compliance to federal incentive payment qualification.
CMS's Meaningful Use rules included security risk analysis (per HIPAA §164.308(a)(1)) as a required core objective across all three stages. To receive Medicare/Medicaid EHR incentive payments, providers had to attest that they conducted or reviewed a security risk analysis and addressed identified deficiencies. This linkage was deliberate: HITECH used financial incentives to drive both EHR adoption and concurrent HIPAA security compliance. OIG audits found widespread false attestations — providers claiming security risk analyses they had not conducted. When CMS discovered false attestations, it sought repayment of incentive payments plus potential False Claims Act liability, creating significant enforcement actions specifically targeting the security risk analysis requirement.
What does the HITECH Act stand for and when was it enacted?