CIPP/US Study Guide
Chapter 8: Medical Privacy

HITECH and Breach Notification

HITECH (2009) strengthened HIPAA and created breach notification. A breach is presumed unless a risk assessment shows low probability of compromise. Individuals get notice within 60 days; breaches over 500 trigger HHS notice immediately and media notice if 500+ in one jurisdiction. Encryption avoids liability.

The HITECH Act was enacted within the American Recovery and Reinvestment Act of 2009 and provided $19 billion in incentives for electronic health records. A Breach (HITECH) is presumed unless the entity proves through a risk assessment a low probability that security or privacy was compromised - placing the burden of proof on the covered entity or business associate.

HITECH breach notification timelines and triggers
TriggerRequirement
High probability of compromiseNotify individuals within 60 days of discovery
Business associate discovers breachNotify the covered entity
Breach affects more than 500 peopleNotify HHS immediately
500 or more in the same jurisdictionNotify the media
All notice-requiring breachesReport to HHS at least annually
Encryption is the escape hatch

A breach applies only to unsecured information. A covered entity can avoid liability by encrypting the information. Separately, HITECH's Personal health record provider rule covers medical apps and wearables and is enforced by the FTC, even if the provider never seeks federal reimbursement.

Key terms - quick answers

What is “HITECH Act”?
The Health Information Technology for Economic and Clinical Health Act of 2009, enacted within ARRA, which strengthened HIPAA and funded health IT adoption.
What is “Breach (HITECH)”?
An unauthorized acquisition, access, use, or disclosure of unsecured PHI, presumed to have occurred unless a risk assessment shows low probability of compromise.
What is “Personal health record provider”?
A provider of cloud or app services storing individual health records, subject to HITECH breach rules and FTC enforcement even without seeking federal reimbursement.