Most practices file the HITECH Act under history, as the 2009 law that paid doctors to buy an EHR. That part is finished. The incentive checks stopped years ago, and Meaningful Use now runs under a different name.
The enforcement side kept going. HITECH is why a lost laptop becomes a letter to every patient on it. It's also why your billing vendor can be fined on its own, and why HIPAA penalties top $2 million a year for one provision.
For a practice under 50 providers, HITECH comes down to three habits. Start with a risk analysis that matches the tools staff really use. Every vendor that touches PHI needs a signed BAA on file. And patient texts stay off personal phones.
This year raised the stakes again. HHS lifted every fine tier for inflation in January 2026, and regulators said their risk analysis crackdown would now cover risk management too.
The Health Information Technology for Economic and Clinical Health Act became law on February 17, 2009, as part of a federal stimulus bill. It did two jobs. It paid for the move to digital records, and it gave HIPAA sharper enforcement rules.
Starting in 2011, Medicare and Medicaid paid doctors and hospitals that showed "meaningful use" of certified electronic health records. CMS renamed the program Promoting Interoperability in 2018. Today it feeds how CMS scores clinicians and sets hospital payments.
The money worked. In 2008, fewer than 10% of hospitals had a basic EHR. By 2024, federal health IT data showed over 99% of non-federal acute care hospitals and 91% of office-based physicians on a certified EHR.
HITECH made business associates directly liable under the HIPAA Security Rule. It also created a federal breach notice duty, gave patients a right to digital copies of their records, and set four fine tiers. HHS wrote most of those changes into its 2013 Omnibus Rule.
Between 2009 and 2025, federal regulators received 7,418 reports of breaches affecting 500 or more people, per The HIPAA Journal's count. Before HITECH, no federal rule required those reports at all.
That last change matters for small offices. Controls that work, and are written down, can lower a fine or shorten an audit. Written proof has become a working part of HIPAA compliance.
HITECH gave regulators a fine ladder based on what the practice knew and how fast it fixed the problem. On January 28, 2026, HHS adjusted the amounts for inflation.
|
Tier |
What happened |
Per violation |
|---|---|---|
|
1 |
Didn't know and couldn't have known with reasonable care |
$145 to $73,011 |
|
2 |
Reasonable cause, short of willful neglect |
$1,461 to $73,011 |
|
3 |
Willful neglect, fixed within 30 days |
$14,602 to $73,011 |
|
4 |
Willful neglect, not fixed within 30 days |
$73,011 to $2,190,294 |
On paper, fines for one provision are capped at $2,190,294 a year. Since 2019, regulators have used lower yearly caps for tiers 1 through 3 under an enforcement notice.
Take an imaging center where two front desk staff text prep instructions from their own phones because the portal goes unread. No BAA covers those phones, and no log records what was sent. Then one phone goes missing.
A texting platform under a BAA, with a message log, takes the personal phone out of that chain. That's the setup behind HIPAA-compliant 2-way texting for imaging centers running on StreamlineMD.
HHS's breach notification rule covers unsecured PHI, meaning data that isn't encrypted or destroyed to HHS standards. When properly encrypted data goes missing, it's generally not a reportable breach.
|
Who |
Deadline |
When it applies |
|---|---|---|
|
Affected patients |
Without unreasonable delay, within 60 days of discovery |
Any breach of unsecured PHI |
|
Prominent local media |
Same 60-day window |
More than 500 residents of one state |
|
HHS |
Within 60 days of discovery |
500 or more people |
|
HHS |
Within 60 days after the calendar year ends |
Fewer than 500 people |
|
The practice, told by its vendor |
Without unreasonable delay, within 60 days |
A business associate finds the breach |
Patient notices go by first-class mail, or by email if the patient agreed to that. Each letter says what happened, what data was involved, what the practice is doing, and what the patient should do next.
A business associate reports to the practice. The practice then notifies patients, unless the contract hands that job to the vendor.
Most of the risk in the imaging example came from a tool nobody approved. Swapping personal phones and consumer video apps for platforms under a BAA closes that gap without adding staff.
Curogram Highlight: Encrypted Texting Under a Signed BAACurogram's 2-Way HIPAA Compliant Texting runs from your practice number and logs every message. Curogram signs a BAA before onboarding. Each client also signs a PHI acknowledgment that spells out what can and can't go by standard SMS. Clinical details move to secure messaging, where the patient verifies identity before anything opens. The platform is HIPAA compliant and SOC 2 Type II certified, and it connects with the EMR you already run. Tebra practices, for example, use 2-way HIPAA texting for Tebra to skip the portal login. The same practices can add a HIPAA-compliant telehealth platform for Tebra users for video visits on that platform. |
HITECH turned HIPAA into a rule with invoices attached. At the practice level, the work is routine. List every tool staff uses in the risk analysis. Get a BAA from every vendor that touches PHI, and pick messaging that leaves a log.
A Security Rule update proposed in January 2025 now sits on the federal agenda for July 2027. Current risk analysis cases already test many of the same controls, so there's no reason to wait for it.
Book a Curogram demo, and we'll show how HIPAA-compliant texting, forms, and video visits run under a signed BAA with a full audit trail.