HITECH Act
The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as part of the American Recovery and Reinvestment Act of 2009, promotes the meaningful use of health information technology. It strengthens HIPAA enforcement, establishes breach notification requirements for unsecured protected health information, increases penalties for HIPAA violations, and extends HIPAA requirements directly to business associates.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Accountability
| Code | Title |
|---|---|
| HITECH-1 | Business Associate Direct Liability |
Audit Readiness
| Code | Title |
|---|---|
| HITECH-17 | HHS Periodic Audits |
EHR Program
| Code | Title |
|---|---|
| HITECH-15 | Meaningful Use and Promoting Interoperability |
Enforcement
| Code | Title |
|---|---|
| HITECH-18 | Distribution of Civil Monetary Penalties to Harmed Individuals |
| HITECH-5 | Enhanced Civil Penalties |
| HITECH-6 | State Attorneys General Enforcement |
Incident Analysis
| Code | Title |
|---|---|
| HITECH-3 | Definition of Breach and Risk Assessment |
Incident Response
| Code | Title |
|---|---|
| HITECH-2 | Breach Notification Rule |
Patient Rights
| Code | Title |
|---|---|
| HITECH-7 | Patient Right to Electronic Access |
| HITECH-8 | Accounting of Disclosures |
| HITECH-9 | Restriction on Disclosure to Health Plans |
Security
| Code | Title |
|---|---|
| HITECH-12 | Audit Controls and EHR Logging |
| HITECH-13 | Security Risk Analysis and Management |
| HITECH-4 | Unsecured PHI Protections |
Subtitle A — Promotion of Health Information Technology
Establishment of ONC, health IT standards, and meaningful use incentives
| Code | Title |
|---|---|
| HITECH-A-01 | Office of the National Coordinator (ONC) |
| HITECH-A-02 | HIT Standards Committee |
| HITECH-A-03 | Health IT Certification |
| HITECH-A-04 | Meaningful Use Requirements |
| HITECH-A-05 | Health Information Exchange Standards |
Subtitle B — Testing of Health IT
Testing, interoperability, and research network provisions
| Code | Title |
|---|---|
| HITECH-B-01 | National Health IT Research Center |
| HITECH-B-02 | Health IT Regional Extension Centers |
| HITECH-B-03 | Interoperability Testing |
Subtitle C — Other Provisions
Workforce development, grants, and infrastructure
| Code | Title |
|---|---|
| HITECH-C-01 | Health IT Workforce Development |
| HITECH-C-02 | State Health IT Grants |
Subtitle D — Privacy and Security Provisions
Enhanced privacy and security requirements, breach notification, and enforcement
| Code | Title |
|---|---|
| HITECH-D-01 | Breach Notification Requirements |
| HITECH-D-02 | Business Associate Direct Liability |
| HITECH-D-03 | Increased Civil Monetary Penalties |
| HITECH-D-04 | State Attorney General Enforcement |
| HITECH-D-05 | Accounting of Disclosures |
| HITECH-D-06 | Minimum Necessary Standard Strengthening |
| HITECH-D-07 | Prohibition on Sale of PHI |
| HITECH-D-08 | Individual Right to Electronic Copy |
| HITECH-D-09 | Restriction on Disclosures to Health Plans |
| HITECH-D-10 | EHR Security Requirements |
Third Party
| Code | Title |
|---|---|
| HITECH-16 | Subcontractor and Downstream BA Obligations |
Use and Disclosure
| Code | Title |
|---|---|
| HITECH-10 | Marketing and Sale of PHI Limits |
| HITECH-11 | Fundraising Communications |
Workforce
| Code | Title |
|---|---|
| HITECH-14 | Workforce Training and Sanctions |
Your Compliance Coverage
If you comply with HITECH Act, you already cover:
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
13%
5 controls mapped
Compare →Azure Security Benchmark
13%
5 controls mapped
Compare →TEFCA — Trusted Exchange Framework and Common Agreement
13%
5 controls mapped
Compare →+ 515 more: Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) (13%), Wisconsin Data Privacy Act (SB 670) (13%)
See all 518 mapped frameworks ↓Maps to 518 other frameworks
Frequently Asked Questions
What is HITECH Act?
HITECH Act is a compliance framework from United States with 15 domains and 38 controls. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as part of the American Recovery and Reinvestment Act of 2009, promotes the meaningful use of health information technology. It strengthens HIPAA enforcement, establishes breach notification requirements for unsecured protected health information, increases penalties for HIPAA violations, and extends HIPAA requirements directly to business associates. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does HITECH Act have?
HITECH Act has 38 controls organised across 15 domains. The largest domains are Subtitle D — Privacy and Security Provisions (10 controls), Subtitle A — Promotion of Health Information Technology (5 controls), Enforcement (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does HITECH Act map to?
HITECH Act maps to 518 other compliance frameworks. The top mapping partners are CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (13% coverage), Azure Security Benchmark (13% coverage), TEFCA — Trusted Exchange Framework and Common Agreement (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with HITECH Act compliance?
Start your HITECH Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HITECH Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required