HITECH-2024-2025-NPRM-ReproductiveHealth-Sectoral | HITECH 2024-2025 Pipeline - HIPAA Security Rule NPRM (Dec 2024), Reproductive Health, OCR Audits, Sectoral Application | 0 |
HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC | HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC | 51 |
HITECH-Crosswalk-HIPAA-NIST-CSF-405d-Sectoral | HITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws | 0 |
HITECH-Enforcement-CMP-Tiers-StateAGs-OCR | HITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements | 7 |
HITECH-Implementation-Roles-Compliance-Audit | HITECH Implementation Roadmap, Organizational Roles, Compliance + Audit-Readiness | 0 |
HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles | HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D) | 18 |
HITECH-Sectoral-Hospitals-Health-Plans-Pharma-Tech | HITECH Sectoral Application: Hospitals, Health Plans, Pharma, Tech BAs, State Coordination, OCR Wall of Shame | 0 |
HITECH-Status-Adoption-Vision-Cures-FutureRegulation | HITECH Status, Adoption Statistics, ARRA + Cures Act + 2024 NPRM Vision and Future Healthcare Cybersecurity | 0 |
HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PI | HITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability | 18 |
HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability | HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors | 44 |
HITECH-SubtitleD-StrengthIndividualRights | HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) | 19 |
13400 | Section 13400: definitions | 0 |
13401 | Section 13401: HIPAA Security Rule safeguards and penalties apply directly to business associates | 0 |
13402a | Section 13402(a) to (c): notify every individual whose unsecured PHI was breached; breaches deemed discovered when known or reasonably knowable | 0 |
13402b | Section 13402(b): a business associate notifies the covered entity of a breach and identifies each affected individual | 0 |
13402d | Section 13402(d) and (g): notify without unreasonable delay and within 60 calendar days of discovery, with the burden of proof on the notifier; delay only at law enforcement reques | 0 |
13402e | Section 13402(e): methods of notice: written notice to individuals, substitute notice, media notice above 500 residents of a state, notice to the Secretary and the public breach li | 0 |
13402f | Section 13402(f): content of the notice | 0 |
13403 | Section 13403: HHS regional privacy advisors and a national education initiative on uses of health information | 0 |
13404 | Section 13404: HIPAA Privacy Rule use and disclosure limits and penalties apply directly to business associates | 0 |
13405a | Section 13405(a): honour a requested restriction on disclosure to a health plan where the patient paid out of pocket in full | 0 |
13405b | Section 13405(b): limit uses, disclosures and requests to the limited data set or the minimum necessary, determined by the discloser | 0 |
13405c | Section 13405(c): accounting of disclosures for treatment, payment and operations made through an electronic health record | 0 |
13405d | Section 13405(d): no sale of protected health information without an authorization that states whether it may be resold | 0 |
13405e | Section 13405(e): electronic access to an electronic health record, transmission to a designated third party, and a fee capped at labour cost | 0 |
13406a | Section 13406(a): marketing communications paid for by a third party are not health care operations without an authorization | 0 |
13406b | Section 13406(b): every written fundraising communication must offer a clear and conspicuous opt-out, treated as a revocation of authorization | 0 |
13407 | Section 13407: breach notification by vendors of personal health records and other non-HIPAA entities to individuals and the FTC | 0 |
13408 | Section 13408: health information exchanges, e-prescribing gateways and PHR vendors serving covered entities are business associates and must have contracts | 0 |
13409 | Section 13409: criminal penalties reach any person, including an employee, who obtains or discloses protected health information without authorization | 0 |
13410a | Section 13410(a) and (b): willful neglect violations must be penalised and complaints indicating willful neglect must be formally investigated | 0 |
13410c | Section 13410(c): civil money penalties and settlements go to OCR for enforcement, with a methodology to share them with harmed individuals | 0 |
13410d | Section 13410(d): four tiers of civil money penalties by culpability, with annual caps | 0 |
13410e | Section 13410(e): state attorneys general may sue for HIPAA violations affecting their residents | 0 |
13411 | Section 13411: periodic HHS audits of covered entities and business associates | 0 |
13412 | Section 13412 (added by Public Law 116-321, 2021): recognized security practices in place for the prior twelve months are considered in fines, audits and settlements | 0 |
A | Subtitle A: Office of the National Coordinator, standards, certification and the health IT infrastructure (PHSA Title XXX, sections 3000 to 3018) | 0 |
IV | Title IV: Medicare and Medicaid health information technology incentives (meaningful use) | 0 |
PART1 | Part 1: improved privacy and security provisions | 0 |
PART2 | Part 2 (sections 13421 to 13424): relationship to other laws, regulatory references, effective date, reports and studies | 0 |
XIII | Title XIII of the American Recovery and Reinvestment Act of 2009: the HITECH Act and its structure | 0 |