HITECH Act
HITECH Coordination with HIPAA Privacy + Security Rules (Verified Separately) + 21st Century Cures Act + ONC

HITECH Act HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC: HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC

HITECH coordination with HIPAA Privacy Rule + HIPAA Security Rule + 21st Century Cures Act + ONC. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - established 2000 + modified 2002 + significantly amended by HITECH 2009 + 2013 Omnibus Final Rule; governs PHI use + disclosure + individual rights; HITECH expanded application to BAs + strengthened individual rights + enforcement. HIPAA SECURITY RULE (45 CFR Part 164 Subpart C, SEPARATELY VERIFIED in this corpus) - established 2003 + significantly amended by HITECH 2009 + 2013 Omnibus + 2024 NPRM modernisation; administrative + physical + technical safeguards for ePHI; HITECH extended direct application to BAs + added Breach Notification Rule; 2024 NPRM proposed enhancements include MFA + encryption + asset inventory + ransomware response + vulnerability management. 2013 HIPAA OMNIBUS FINAL RULE (78 FR 5566): implementing HITECH Privacy/Security amendments + Genetic Information Nondiscrimination Act (GINA) + breach notification + BA direct liability + marketing/fundraising changes + sale of PHI; effective 23 March 2013 + compliance 23 September 2013. 21st CENTURY CURES ACT (Public Law 114-255 of 13 December 2016): Section 4002 directing ONC + HHS to implement INFORMATION BLOCKING + interoperability + USCDI + Open APIs; Information Blocking Final Rule (ONC) effective phased + Cures Act Final Rule 2020. ONC INFORMATION BLOCKING FINAL RULE (85 FR 25642 of 1 May 2020): defines + prohibits Information Blocking by actors (HIT developers + HIE/HIN + healthcare providers) + 8 exceptions (preventing harm + privacy + security + infeasibility + Health IT performance + content + manner + fees + licensing); penalties USD 1M per violation for HIT developers + HIE/HIN actors (administered by HHS OIG); ASTP Information Blocking Disincentives Final Rule (2024) for healthcare providers (different penalties + reductions in Medicare reimbursement). ONC CERTIFICATION PROGRAM + 2015 EDITION CURES UPDATE: continued evolution of EHR + Health IT module certification criteria including USCDI + FHIR + interoperability + security + Information Blocking compliance. USCDI (United States Core Data for Interoperability) v1-v4+: standardised health data elements + classes + ongoing semiannual updates. TEFCA (Trusted Exchange Framework and Common Agreement, 2022): voluntary network-of-networks framework for nationwide interoperable HIE; QHINs operationalising. STATE PRIVACY LAWS COORDINATION: state-specific health privacy laws (e.g. NY State Information Security Breach Notification + CMIA California + others) coordinate with HITECH/HIPAA; preemption analysis case-by-case.

What else in your programme already covers this

This control maps to 155 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 7 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • 3.10 Encrypt Sensitive Data in Transit
  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

OWASP ASVS · 5 controls

ISO/IEC 27011:2024 · 4 controls

OWASP Top 10:2025 · 4 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

API 1164 · 3 controls

  • 62351-14 Cyber security event logging
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management

ISO/IEC 27010:2015 · 3 controls

  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-3 Secondary Use - Health Data for Research and Innovation
  • EHDSREG-5 Cross-Border Health Data Flows

APPI · 2 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 2 controls

  • CA-10 Selects and Develops Control Activities
  • CA-12 Deploys Through Policies and Procedures
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • QMSR-820.10 Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10)
  • QMSR-ISO13485-Sec7_DesignControls Product realization - Design and Development controls (ISO 13485:2016 Section 7.3)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • FDBR-704 Exemptions (§501.704)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

India DPDP Act · 2 controls

MITRE D3FEND · 2 controls

  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TEFCAREC-2 Privacy, Security, Minimum Necessary
  • ASD37-17 TLS encryption between email servers (Limited)

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO/IEC 27400:2022 · 1 control

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism

NIST SP 800-171 · 1 control

  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in HITECH Coordination with HIPAA Privacy + Security Rules (Verified Separately) + 21st Century Cures Act + ONC

Query this from an agent

The graph holds this control, the 155 it maps to, and the evidence behind each claim, over MCP and REST.