Skip to the main content.

5 min read

Everything You Need to Know About the HITECH Act

Everything You Need to Know About the HITECH Act
💡The HITECH Act is a 2009 law that got doctors to switch to digital health records and gave HIPAA real teeth. It made vendors own their data security, set deadlines for breach notices, and created four fine tiers that now reach $73,011 per violation.

A 2021 update lets regulators go easier on practices with a full year of good security habits. For most practices, the work is a current risk analysis, signed BAAs, and patient texts that are logged and locked down.

Most practices file the HITECH Act under history, as the 2009 law that paid doctors to buy an EHR. That part is finished. The incentive checks stopped years ago, and Meaningful Use now runs under a different name.

The enforcement side kept going. HITECH is why a lost laptop becomes a letter to every patient on it. It's also why your billing vendor can be fined on its own, and why HIPAA penalties top $2 million a year for one provision.

For a practice under 50 providers, HITECH comes down to three habits. Start with a risk analysis that matches the tools staff really use. Every vendor that touches PHI needs a signed BAA on file. And patient texts stay off personal phones.

This year raised the stakes again. HHS lifted every fine tier for inflation in January 2026, and regulators said their risk analysis crackdown would now cover risk management too.

What is the HITECH Act?

The Health Information Technology for Economic and Clinical Health Act became law on February 17, 2009, as part of a federal stimulus bill. It did two jobs. It paid for the move to digital records, and it gave HIPAA sharper enforcement rules.

The Incentive Side

Starting in 2011, Medicare and Medicaid paid doctors and hospitals that showed "meaningful use" of certified electronic health records. CMS renamed the program Promoting Interoperability in 2018. Today it feeds how CMS scores clinicians and sets hospital payments.

The money worked. In 2008, fewer than 10% of hospitals had a basic EHR. By 2024, federal health IT data showed over 99% of non-federal acute care hospitals and 91% of office-based physicians on a certified EHR.

The Enforcement Side

HITECH made business associates directly liable under the HIPAA Security Rule. It also created a federal breach notice duty, gave patients a right to digital copies of their records, and set four fine tiers. HHS wrote most of those changes into its 2013 Omnibus Rule.

Why is the HITECH Act important?

Between 2009 and 2025, federal regulators received 7,418 reports of breaches affecting 500 or more people, per The HIPAA Journal's count. Before HITECH, no federal rule required those reports at all.

What It Changed for a Small Practice

  • Vendors answer for their own security. A billing company, cloud host, or texting tool that handles PHI is a business associate, and it needs a signed business associate agreement.
  • Patients can request electronic records, and regulators have backed that right with more than 50 penalties since 2019.
  • Enforcement is steady. In 2025, the HHS Office for Civil Rights closed 21 cases with fines and collected $8,330,066.
  • Good security now earns credit. A 2021 amendment requires regulators to weigh recognized security practices, such as the NIST Cybersecurity Framework, that were in place for the prior 12 months.

That last change matters for small offices. Controls that work, and are written down, can lower a fine or shorten an audit. Written proof has become a working part of HIPAA compliance.

Infographic comparing lost staff phone outcomes: personal phone vs. encrypted platformHow Does the HITECH Act Help Enforce HIPAA?

HITECH gave regulators a fine ladder based on what the practice knew and how fast it fixed the problem. On January 28, 2026, HHS adjusted the amounts for inflation.

HITECH Act Penalties in 2026

Tier

What happened

Per violation

1

Didn't know and couldn't have known with reasonable care

$145 to $73,011

2

Reasonable cause, short of willful neglect

$1,461 to $73,011

3

Willful neglect, fixed within 30 days

$14,602 to $73,011

4

Willful neglect, not fixed within 30 days

$73,011 to $2,190,294

 

On paper, fines for one provision are capped at $2,190,294 a year. Since 2019, regulators have used lower yearly caps for tiers 1 through 3 under an enforcement notice.

A Worked Example: Texts From a Personal Phone

Take an imaging center where two front desk staff text prep instructions from their own phones because the portal goes unread. No BAA covers those phones, and no log records what was sent. Then one phone goes missing.

  1. Unless a written assessment shows a low chance the PHI was exposed, the loss counts as a breach. With no log, that case is hard to make.
  2. Every patient whose name and scan type sat in those threads gets written notice within 60 days of discovery.
  3. If more than 500 residents of one state are involved, local media must be told in the same window, and so must HHS.
  4. Next, regulators ask for the risk analysis. If managers knew about the texting and let it run, the case can land in the willful neglect tiers.

A texting platform under a BAA, with a message log, takes the personal phone out of that chain. That's the setup behind HIPAA-compliant 2-way texting for imaging centers running on StreamlineMD.

The HIPAA Breach Notification Rule

HHS's breach notification rule covers unsecured PHI, meaning data that isn't encrypted or destroyed to HHS standards. When properly encrypted data goes missing, it's generally not a reportable breach.

Who Gets Told, and When

Who

Deadline

When it applies

Affected patients

Without unreasonable delay, within 60 days of discovery

Any breach of unsecured PHI

Prominent local media

Same 60-day window

More than 500 residents of one state

HHS

Within 60 days of discovery

500 or more people

HHS

Within 60 days after the calendar year ends

Fewer than 500 people

The practice, told by its vendor

Without unreasonable delay, within 60 days

A business associate finds the breach


Patient notices go by first-class mail, or by email if the patient agreed to that. Each letter says what happened, what data was involved, what the practice is doing, and what the patient should do next.

A business associate reports to the practice. The practice then notifies patients, unless the contract hands that job to the vendor.

A HITECH and HIPAA-compliant Platform Simplifies the Task of Protecting PHI

Most of the risk in the imaging example came from a tool nobody approved. Swapping personal phones and consumer video apps for platforms under a BAA closes that gap without adding staff.

Three Questions to Ask Any Messaging Vendor

  • Will you sign a BAA before we send a single patient message?
  • Where does the message log live, and who on our team can read it?
  • When we remove a staff member's access, what happens to the threads on their device?

 

Curogram Highlight: Encrypted Texting Under a Signed BAA

Curogram's 2-Way HIPAA Compliant Texting runs from your practice number and logs every message. Curogram signs a BAA before onboarding. Each client also signs a PHI acknowledgment that spells out what can and can't go by standard SMS.

Clinical details move to secure messaging, where the patient verifies identity before anything opens. The platform is HIPAA compliant and SOC 2 Type II certified, and it connects with the EMR you already run.

Tebra practices, for example, use 2-way HIPAA texting for Tebra to skip the portal login. The same practices can add a HIPAA-compliant telehealth platform for Tebra users for video visits on that platform.

 

Conclusion: Keep HITECH Compliance Routine

HITECH turned HIPAA into a rule with invoices attached. At the practice level, the work is routine. List every tool staff uses in the risk analysis. Get a BAA from every vendor that touches PHI, and pick messaging that leaves a log.

A Security Rule update proposed in January 2025 now sits on the federal agenda for July 2027. Current risk analysis cases already test many of the same controls, so there's no reason to wait for it.

Book a Curogram demo, and we'll show how HIPAA-compliant texting, forms, and video visits run under a signed BAA with a full audit trail.

 

Frequently Asked Questions

How does the HITECH Act affect a small medical practice today?
It sets the fine tiers regulators use, requires breach notices within 60 days, and makes vendors own their security. Day-to-day, that means a current risk analysis, signed BAAs, and patient texts that leave a log.
Why can a business associate be fined directly under HITECH?
HITECH applied the HIPAA Security Rule, and parts of the Privacy Rule, straight to business associates. A billing firm or texting vendor that mishandles PHI can be fined on its own, apart from the practice.
What counts as unsecured PHI under the breach notification rule?
It's PHI that isn't encrypted or destroyed to HHS standards. If a lost phone held properly encrypted data, the loss generally isn't a reportable breach. Good encryption can spare a practice the whole notice process.
How do recognized security practices lower HITECH penalties?
Since a 2021 update, regulators must check whether a practice followed a known security standard, like the NIST framework, for the past 12 months. If it did, and can show proof, fines can drop and audits can end sooner.
Why do HIPAA penalty amounts differ from one website to the next?
HHS raises the amounts each year for inflation, most recently in January 2026. Regulators also use lower yearly caps for three of the four tiers, set in 2019. So old posts and the official table rarely match.

 

Understanding HIPAA Violation Consequences

1 min read

Understanding HIPAA Violation Consequences

💡HIPAA violation consequences arrive in four forms: civil fines, criminal charges, a corrective action plan, and the business damage that follows....

Read More
Q&A: What Is a HIPAA Risk Assessment?

1 min read

Q&A: What Is a HIPAA Risk Assessment?

Ensuring that patients' sensitive medical information stays safe is something that every medical practice must take seriously, which is why...

Read More
AI and HIPAA: Navigating Security and Privacy With Conversational AI

1 min read

AI and HIPAA: Navigating Security and Privacy With Conversational AI

💡 HIPAA compliance for conversational AI means applying the Security Rule's administrative, physical, and technical safeguards to any chatbot,...

Read More