Back to Frameworks

HITECH Act

United States
v2009 (as amended)
7 domains
11 controls

The Health Information Technology for Economic and Clinical Health Act (HITECH Act) is a US federal statute enacted 17 February 2009 as Title XIII of the AMERICAN RECOVERY AND REINVESTMENT ACT (ARRA, Public Law 111-5, Stimulus Act). HITECH represents the most significant amendment to HIPAA since enactment. KEY PURPOSES + ACHIEVEMENTS: (a) promoting EHR adoption + Health Information Technology + Meaningful Use + interoperability across the US healthcare system; (b) substantially enhancing HIPAA Privacy Rule + HIPAA Security Rule (separately verified) enforcement with tier-based civil monetary penalties + criminal sanctions + State Attorney General enforcement authority; (c) extending HIPAA direct liability to BUSINESS ASSOCIATES + subcontractor business associates downstream; (d) establishing the HITECH BREACH NOTIFICATION RULE (45 CFR Part 164 Subpart D); (e) strengthening individual rights including electronic access + accounting of disclosures + restrictions on disclosures to health plans + prohibition on sale of PHI + tightened marketing + fundraising; (f) creating Office of the National Coordinator for Health IT (ONC) with statutory authority. STRUCTURE: 4 Subtitles - SUBTITLE A Promotion of Health Information Technology (42 USC 17901-17915); SUBTITLE B Testing of Health IT (42 USC 17916-17919); SUBTITLE C Grants/Loans/Workforce (42 USC 17921-17924); SUBTITLE D Privacy and Security Provisions (42 USC 17931-17953 - the HITECH Privacy/Security amendments). KEY SUBTITLE D PROVISIONS: (a) Section 17931 application of security provisions + penalties to BAs; (b) Section 17932 BREACH NOTIFICATION (codified at 45 CFR 164.400-414); (c) Section 17933 education on health information privacy; (d) Section 17934 application of privacy provisions + penalties to BAs; (e) Section 17935 restrictions on certain disclosures + sales of PHI; (f) Section 17936 conditions on contacts as part of health care operations; (g) Section 17937 individual access + accounting of disclosures; (h) Section 17938 conditioning compliance + enforcement; (i) Section 17939 enforcement provisions (tier-based civil monetary penalties up to USD 1.5M/year per category); (j) Section 17940 education + outreach. ENFORCEMENT: HHS Office for Civil Rights (OCR) primary enforcer + State Attorneys General authority to pursue HIPAA violations on behalf of state residents; tier-based civil monetary penalties: Tier 1 (did not know) USD 100-50K per violation, USD 25K annual max; Tier 2 (reasonable cause) USD 1K-50K per violation, USD 100K annual max; Tier 3 (willful neglect, corrected) USD 10K-50K per violation, USD 250K annual max; Tier 4 (willful neglect, uncorrected) USD 50K per violation, USD 1.5M annual max (per category; inflation-adjusted). RECENT HHS OCR ENFORCEMENT: substantial penalties including Anthem USD 16M + Premera USD 6.85M + Excellus USD 5.1M + Memorial Healthcare USD 5.5M + Advocate USD 5.55M + many other settlements + corrective action plans + audits. MEANINGFUL USE / PROMOTING INTEROPERABILITY: CMS Promoting Interoperability program (formerly Meaningful Use) for EHR Incentive Payments + later Medicare Quality Payment Program (MIPS); 3 stages + value-based care + 2018+ EHR Reporting + Promoting Interoperability + post-Cures Act + ONC USCDI + Open APIs + Information Blocking Final Rule. ONC (Office of the National Coordinator): statutory authority + HIT Standards + Certification programs + Information Blocking + Trusted Exchange Framework + Common Agreement (TEFCA) + Health Data Networks. SUBSEQUENT REGULATORY ACTIVITY: (1) 2013 HIPAA Omnibus Final Rule implementing HITECH including direct BA liability + breach notification + marketing/fundraising changes + sale of PHI; (2) 2016 21st Century Cures Act + Sec. 4002 ONC Information Blocking + HIT Advisory Committee + ONC USCDI; (3) 2020 ONC Cures Act Final Rule + Information Blocking + Open APIs + FHIR R4 implementation; (4) 2024 HHS Notice of Proposed Rulemaking on HIPAA Security Rule modernisation (NPRM December 2024) + comments closing March 2025 + potential Final Rule 2025-2026 incorporating cybersecurity best practices + MFA + encryption + asset inventory + ransomware response; (5) 2024 HHS final rule on reproductive health privacy + April 2024 enforcement effective; (6) ongoing OCR audits + enforcement priorities + ransomware + HIPAA Security Rule violations. STATUS: REFERENCED because HITECH is statutory umbrella + substantive operational controls live in HIPAA Privacy Rule + HIPAA Security Rule (45 CFR Parts 160 + 164) verified separately in this corpus + Breach Notification Rule + ONC Information Blocking + EHR Certification Programs.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

HITECH 2024-2025 Pipeline: NPRM Security Rule Modernisation, Reproductive Health, Information Blocking, Sectoral Application

4 controls
Controls in the HITECH 2024-2025 Pipeline: NPRM Security Rule Modernisation, Reproductive Health, Information Blocking, Sectoral Application domain of HITECH Act4 controls
CodeTitle
HITECH-2024-2025-NPRM-ReproductiveHealth-SectoralHITECH 2024-2025 Pipeline - HIPAA Security Rule NPRM (Dec 2024), Reproductive Health, OCR Audits, Sectoral Application
HITECH-Implementation-Roles-Compliance-AuditHITECH Implementation Roadmap, Organizational Roles, Compliance + Audit-Readiness
HITECH-Sectoral-Hospitals-Health-Plans-Pharma-TechHITECH Sectoral Application: Hospitals, Health Plans, Pharma, Tech BAs, State Coordination, OCR Wall of Shame
HITECH-Status-Adoption-Vision-Cures-FutureRegulationHITECH Status, Adoption Statistics, ARRA + Cures Act + 2024 NPRM Vision and Future Healthcare Cybersecurity

HITECH Act: Statutory Scope, ARRA Title XIII Origin, 42 USC Chapter 156 Structure (Subtitles A-D)

1 controls
Controls in the HITECH Act: Statutory Scope, ARRA Title XIII Origin, 42 USC Chapter 156 Structure (Subtitles A-D) domain of HITECH Act1 controls
CodeTitle
HITECH-Scope-ARRA-XIII-42USC-Ch156-SubtitlesHITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)

HITECH Coordination with HIPAA Privacy + Security Rules (Verified Separately) + 21st Century Cures Act + ONC

2 controls
Controls in the HITECH Coordination with HIPAA Privacy + Security Rules (Verified Separately) + 21st Century Cures Act + ONC domain of HITECH Act2 controls
CodeTitle
HITECH-Coord-HIPAA-Privacy-Security-Cures-ONCHITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
HITECH-Crosswalk-HIPAA-NIST-CSF-405d-SectoralHITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws

HITECH Enforcement: 4-Tier Civil Monetary Penalties, State AGs, HHS OCR, Recent Settlements

1 controls
Controls in the HITECH Enforcement: 4-Tier Civil Monetary Penalties, State AGs, HHS OCR, Recent Settlements domain of HITECH Act1 controls
CodeTitle
HITECH-Enforcement-CMP-Tiers-StateAGs-OCRHITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements

HITECH Subtitle A: ONC, HIT Standards, EHR Certification, Meaningful Use / Promoting Interoperability

1 controls
Controls in the HITECH Subtitle A: ONC, HIT Standards, EHR Certification, Meaningful Use / Promoting Interoperability domain of HITECH Act1 controls
CodeTitle
HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PIHITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability

HITECH Subtitle D: Breach Notification Rule, BA Direct Liability, Subcontractors

1 controls
Controls in the HITECH Subtitle D: Breach Notification Rule, BA Direct Liability, Subcontractors domain of HITECH Act1 controls
CodeTitle
HITECH-SubtitleD-Breach-Notification-BA-Direct-LiabilityHITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors

HITECH Subtitle D: Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)

1 controls
Controls in the HITECH Subtitle D: Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) domain of HITECH Act1 controls
CodeTitle
HITECH-SubtitleD-StrengthIndividualRightsHITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)

Your Compliance Coverage

If you comply with HITECH Act, you already cover:

Maps to 78 other frameworks

11 total controls
Azure Security Benchmark
5 source controls mapped|5 target controls covered
45%
Privacy Act 1988 (Australia)
4 source controls mapped|3 target controls covered
36%
Ley Orgánica de Protección de Datos Personales (LOPDP)
4 source controls mapped|2 target controls covered
36%
Law No. 172-13 on the Protection of Personal Data
4 source controls mapped|2 target controls covered
36%
India DPDP Act
4 source controls mapped|2 target controls covered
36%
APPI
4 source controls mapped|5 target controls covered
36%
Bahrain PDPL
4 source controls mapped|5 target controls covered
36%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
4 source controls mapped|3 target controls covered
36%
36%
Pakistan Personal Data Protection Bill 2023
3 source controls mapped|2 target controls covered
27%
Barbados Data Protection Act 2019
3 source controls mapped|2 target controls covered
27%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|2 target controls covered
27%
Regulation on the European Health Data Space (EHDS)
3 source controls mapped|3 target controls covered
27%
ICH E6(R3) - Good Clinical Practice
3 source controls mapped|3 target controls covered
27%
Aged Care Quality Standards (Australia)
3 source controls mapped|3 target controls covered
27%
FDA Quality Management System Regulation (QMSR)
3 source controls mapped|2 target controls covered
27%
COSO Internal Control - Integrated Framework (2013)
3 source controls mapped|2 target controls covered
27%
IEC 60601-1 - Medical Electrical Equipment Safety
3 source controls mapped|1 target controls covered
27%
Florida Digital Bill of Rights (FDBR)
3 source controls mapped|1 target controls covered
27%
OWASP Top 10:2025
3 source controls mapped|5 target controls covered
27%
OWASP DevSecOps Maturity Model (DSOMM)
3 source controls mapped|3 target controls covered
27%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|5 target controls covered
27%
BSI IT-Grundschutz
3 source controls mapped|11 target controls covered
27%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|8 target controls covered
27%
AWS Well-Architected Security Pillar
3 source controls mapped|4 target controls covered
27%
ASD Strategies to Mitigate Cyber Security Incidents
3 source controls mapped|5 target controls covered
27%
ISO/IEC 27400:2022
3 source controls mapped|3 target controls covered
27%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
2 source controls mapped|1 target controls covered
18%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
2 source controls mapped|1 target controls covered
18%
India Account Aggregator Framework (RBI)
2 source controls mapped|1 target controls covered
18%
OWASP ASVS
2 source controls mapped|5 target controls covered
18%
OWASP API Security Top 10 - 2023
2 source controls mapped|3 target controls covered
18%
MITRE D3FEND
2 source controls mapped|2 target controls covered
18%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|2 target controls covered
18%
HL7 FHIR Security Framework
2 source controls mapped|3 target controls covered
18%
ISO/IEC 27011:2024
2 source controls mapped|4 target controls covered
18%
IEC 62351 - Power Systems Communication Security
2 source controls mapped|3 target controls covered
18%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|5 target controls covered
18%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
2 source controls mapped|1 target controls covered
18%
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|3 target controls covered
18%
HKMA Cyber Resilience Assessment Framework (C-RAF)
2 source controls mapped|2 target controls covered
18%
Canada ITSG-33 - IT Security Risk Management
2 source controls mapped|1 target controls covered
18%
ISO/IEC 27010:2015
2 source controls mapped|4 target controls covered
18%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|2 target controls covered
18%
NIST SP 800-171
2 source controls mapped|2 target controls covered
18%
API 1164
2 source controls mapped|6 target controls covered
18%
FFIEC IT Examination Handbook
2 source controls mapped|4 target controls covered
18%
Annex 11 to EU GMP - Computerised Systems
2 source controls mapped|3 target controls covered
18%
APRA CPS 234
2 source controls mapped|4 target controls covered
18%
MiFID II / MiFIR
1 source controls mapped|1 target controls covered
9%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
9%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
9%
FBI CJIS Security Policy
1 source controls mapped|2 target controls covered
9%
ISO 19011
1 source controls mapped|2 target controls covered
9%
9%
ISO 31000:2018
1 source controls mapped|2 target controls covered
9%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
9%
ISO 27005
1 source controls mapped|1 target controls covered
9%
ISO 20000-1
1 source controls mapped|1 target controls covered
9%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|3 target controls covered
9%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|1 target controls covered
9%
FIDO2 / WebAuthn
1 source controls mapped|1 target controls covered
9%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|1 target controls covered
9%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|1 target controls covered
9%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
9%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
9%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
9%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|1 target controls covered
9%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
9%
ISO/IEC 30111:2019
1 source controls mapped|2 target controls covered
9%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
9%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
9%

Frequently Asked Questions

What is HITECH Act?

HITECH Act is a compliance framework from United States with 7 domains and 11 controls. The Health Information Technology for Economic and Clinical Health Act (HITECH Act) is a US federal statute enacted 17 February 2009 as Title XIII of the AMERICAN RECOVERY AND REINVESTMENT ACT (ARRA, Public Law 111-5, Stimulus Act). HITECH represents the most significant amendment to HIPAA since enactment. KEY PURPOSES + ACHIEVEMENTS: (a) promoting EHR adoption + Health Information Technology + Meaningful Use + interoperability across the US healthcare system; (b) substantially enhancing HIPAA Privacy Rule + HIPAA Security Rule (separately verified) enforcement with tier-based civil monetary penalties + criminal sanctions + State Attorney General enforcement authority; (c) extending HIPAA direct liability to BUSINESS ASSOCIATES + subcontractor business associates downstream; (d) establishing the HITECH BREACH NOTIFICATION RULE (45 CFR Part 164 Subpart D); (e) strengthening individual rights including electronic access + accounting of disclosures + restrictions on disclosures to health plans + prohibition on sale of PHI + tightened marketing + fundraising; (f) creating Office of the National Coordinator for Health IT (ONC) with statutory authority. STRUCTURE: 4 Subtitles - SUBTITLE A Promotion of Health Information Technology (42 USC 17901-17915); SUBTITLE B Testing of Health IT (42 USC 17916-17919); SUBTITLE C Grants/Loans/Workforce (42 USC 17921-17924); SUBTITLE D Privacy and Security Provisions (42 USC 17931-17953 - the HITECH Privacy/Security amendments). KEY SUBTITLE D PROVISIONS: (a) Section 17931 application of security provisions + penalties to BAs; (b) Section 17932 BREACH NOTIFICATION (codified at 45 CFR 164.400-414); (c) Section 17933 education on health information privacy; (d) Section 17934 application of privacy provisions + penalties to BAs; (e) Section 17935 restrictions on certain disclosures + sales of PHI; (f) Section 17936 conditions on contacts as part of health care operations; (g) Section 17937 individual access + accounting of disclosures; (h) Section 17938 conditioning compliance + enforcement; (i) Section 17939 enforcement provisions (tier-based civil monetary penalties up to USD 1.5M/year per category); (j) Section 17940 education + outreach. ENFORCEMENT: HHS Office for Civil Rights (OCR) primary enforcer + State Attorneys General authority to pursue HIPAA violations on behalf of state residents; tier-based civil monetary penalties: Tier 1 (did not know) USD 100-50K per violation, USD 25K annual max; Tier 2 (reasonable cause) USD 1K-50K per violation, USD 100K annual max; Tier 3 (willful neglect, corrected) USD 10K-50K per violation, USD 250K annual max; Tier 4 (willful neglect, uncorrected) USD 50K per violation, USD 1.5M annual max (per category; inflation-adjusted). RECENT HHS OCR ENFORCEMENT: substantial penalties including Anthem USD 16M + Premera USD 6.85M + Excellus USD 5.1M + Memorial Healthcare USD 5.5M + Advocate USD 5.55M + many other settlements + corrective action plans + audits. MEANINGFUL USE / PROMOTING INTEROPERABILITY: CMS Promoting Interoperability program (formerly Meaningful Use) for EHR Incentive Payments + later Medicare Quality Payment Program (MIPS); 3 stages + value-based care + 2018+ EHR Reporting + Promoting Interoperability + post-Cures Act + ONC USCDI + Open APIs + Information Blocking Final Rule. ONC (Office of the National Coordinator): statutory authority + HIT Standards + Certification programs + Information Blocking + Trusted Exchange Framework + Common Agreement (TEFCA) + Health Data Networks. SUBSEQUENT REGULATORY ACTIVITY: (1) 2013 HIPAA Omnibus Final Rule implementing HITECH including direct BA liability + breach notification + marketing/fundraising changes + sale of PHI; (2) 2016 21st Century Cures Act + Sec. 4002 ONC Information Blocking + HIT Advisory Committee + ONC USCDI; (3) 2020 ONC Cures Act Final Rule + Information Blocking + Open APIs + FHIR R4 implementation; (4) 2024 HHS Notice of Proposed Rulemaking on HIPAA Security Rule modernisation (NPRM December 2024) + comments closing March 2025 + potential Final Rule 2025-2026 incorporating cybersecurity best practices + MFA + encryption + asset inventory + ransomware response; (5) 2024 HHS final rule on reproductive health privacy + April 2024 enforcement effective; (6) ongoing OCR audits + enforcement priorities + ransomware + HIPAA Security Rule violations. STATUS: REFERENCED because HITECH is statutory umbrella + substantive operational controls live in HIPAA Privacy Rule + HIPAA Security Rule (45 CFR Parts 160 + 164) verified separately in this corpus + Breach Notification Rule + ONC Information Blocking + EHR Certification Programs. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does HITECH Act have?

HITECH Act has 11 controls organised across 7 domains. The largest domains are HITECH 2024-2025 Pipeline: NPRM Security Rule Modernisation, Reproductive Health, Information Blocking, Sectoral Application (4 controls), HITECH Coordination with HIPAA Privacy + Security Rules (Verified Separately) + 21st Century Cures Act + ONC (2 controls), HITECH Act: Statutory Scope, ARRA Title XIII Origin, 42 USC Chapter 156 Structure (Subtitles A-D) (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does HITECH Act map to?

HITECH Act maps to 78 other compliance frameworks. The top mapping partners are Azure Security Benchmark (45% coverage), Privacy Act 1988 (Australia) (36% coverage), Ley Orgánica de Protección de Datos Personales (LOPDP) (36% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with HITECH Act compliance?

Start your HITECH Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HITECH Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 11 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required