United States (federal)

HITECH Act

41 controls. 72 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

41 controls 72 frameworks share controls with it United States (federal) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

HITECH Act (ARRA Title XIII) Evidence & Implementation Kit

41 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
HITECH-2024-2025-NPRM-ReproductiveHealth-SectoralHITECH 2024-2025 Pipeline - HIPAA Security Rule NPRM (Dec 2024), Reproductive Health, OCR Audits, Sectoral Application0
HITECH-Coord-HIPAA-Privacy-Security-Cures-ONCHITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC51
HITECH-Crosswalk-HIPAA-NIST-CSF-405d-SectoralHITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws0
HITECH-Enforcement-CMP-Tiers-StateAGs-OCRHITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements7
HITECH-Implementation-Roles-Compliance-AuditHITECH Implementation Roadmap, Organizational Roles, Compliance + Audit-Readiness0
HITECH-Scope-ARRA-XIII-42USC-Ch156-SubtitlesHITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)18
HITECH-Sectoral-Hospitals-Health-Plans-Pharma-TechHITECH Sectoral Application: Hospitals, Health Plans, Pharma, Tech BAs, State Coordination, OCR Wall of Shame0
HITECH-Status-Adoption-Vision-Cures-FutureRegulationHITECH Status, Adoption Statistics, ARRA + Cures Act + 2024 NPRM Vision and Future Healthcare Cybersecurity0
HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PIHITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability18
HITECH-SubtitleD-Breach-Notification-BA-Direct-LiabilityHITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors44
HITECH-SubtitleD-StrengthIndividualRightsHITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)19
13400Section 13400: definitions0
13401Section 13401: HIPAA Security Rule safeguards and penalties apply directly to business associates0
13402aSection 13402(a) to (c): notify every individual whose unsecured PHI was breached; breaches deemed discovered when known or reasonably knowable0
13402bSection 13402(b): a business associate notifies the covered entity of a breach and identifies each affected individual0
13402dSection 13402(d) and (g): notify without unreasonable delay and within 60 calendar days of discovery, with the burden of proof on the notifier; delay only at law enforcement reques0
13402eSection 13402(e): methods of notice: written notice to individuals, substitute notice, media notice above 500 residents of a state, notice to the Secretary and the public breach li0
13402fSection 13402(f): content of the notice0
13403Section 13403: HHS regional privacy advisors and a national education initiative on uses of health information0
13404Section 13404: HIPAA Privacy Rule use and disclosure limits and penalties apply directly to business associates0
13405aSection 13405(a): honour a requested restriction on disclosure to a health plan where the patient paid out of pocket in full0
13405bSection 13405(b): limit uses, disclosures and requests to the limited data set or the minimum necessary, determined by the discloser0
13405cSection 13405(c): accounting of disclosures for treatment, payment and operations made through an electronic health record0
13405dSection 13405(d): no sale of protected health information without an authorization that states whether it may be resold0
13405eSection 13405(e): electronic access to an electronic health record, transmission to a designated third party, and a fee capped at labour cost0
13406aSection 13406(a): marketing communications paid for by a third party are not health care operations without an authorization0
13406bSection 13406(b): every written fundraising communication must offer a clear and conspicuous opt-out, treated as a revocation of authorization0
13407Section 13407: breach notification by vendors of personal health records and other non-HIPAA entities to individuals and the FTC0
13408Section 13408: health information exchanges, e-prescribing gateways and PHR vendors serving covered entities are business associates and must have contracts0
13409Section 13409: criminal penalties reach any person, including an employee, who obtains or discloses protected health information without authorization0
13410aSection 13410(a) and (b): willful neglect violations must be penalised and complaints indicating willful neglect must be formally investigated0
13410cSection 13410(c): civil money penalties and settlements go to OCR for enforcement, with a methodology to share them with harmed individuals0
13410dSection 13410(d): four tiers of civil money penalties by culpability, with annual caps0
13410eSection 13410(e): state attorneys general may sue for HIPAA violations affecting their residents0
13411Section 13411: periodic HHS audits of covered entities and business associates0
13412Section 13412 (added by Public Law 116-321, 2021): recognized security practices in place for the prior twelve months are considered in fines, audits and settlements0
ASubtitle A: Office of the National Coordinator, standards, certification and the health IT infrastructure (PHSA Title XXX, sections 3000 to 3018)0
IVTitle IV: Medicare and Medicaid health information technology incentives (meaningful use)0
PART1Part 1: improved privacy and security provisions0
PART2Part 2 (sections 13421 to 13424): relationship to other laws, regulatory references, effective date, reports and studies0
XIIITitle XIII of the American Recovery and Reinvestment Act of 2009: the HITECH Act and its structure0

Tell me when HITECH Act files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Role inventory + RACI
  • Metrics + management review
  • Annual cycle documentation
  • Role inventory + RACI + DPO designation
  • Operational controls + tooling investment
  • Reporting process + content index
  • Tooling + EHR + cloud + compliance platform
  • Annual + Phase 3 audit-readiness
  • Tooling adoption + vendor list
  • Sectoral application evidence

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for HITECH Act, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition