9.4 HITECH Act, Breach Notification Rule & Business Associate Agreements (BAAs)
Key Takeaways
- The HITECH Act of 2009 expanded HIPAA enforcement, increased statutory penalties, and applied direct liability to Business Associates.
- A Business Associate Agreement (BAA) is legally required before a third-party vendor creates, receives, maintains, or transmits PHI for a Covered Entity.
- A breach is defined as the unauthorized acquisition, access, use, or disclosure of unencrypted PHI compromising data security or privacy.
- PHI rendered unusable, unreadable, or indecipherable through encryption meeting HHS guidance (NIST-based, such as AES-256) is exempt from breach notification under the Safe Harbor.
- Breaches affecting 500 or more individuals require immediate reporting to HHS OCR, individual written notices within 60 days, and media announcements.
HITECH Act, Breach Notification Rule & Business Associate Agreements (BAAs)
The HITECH Act Framework
Enacted as part of the American Recovery and Reinvestment Act (ARRA) of 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act transformed healthcare IT regulation. HITECH accelerated nationwide EHR adoption through Meaningful Use incentives while expanding HIPAA enforcement authority, introducing tiered Civil Monetary Penalties, and establishing direct statutory compliance obligations for Business Associates (BAs).
Business Associate Agreements (BAAs)
A Business Associate (BA) is an individual or entity—other than a workforce member—that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity for a regulated function or service.
Business Associates vs. Non-BAs
| Entity Category | Operational Examples | BAA Requirement |
|---|---|---|
| Business Associates | Cloud EHR software vendors, medical billing services, transcription contractors, IT security auditors, e-prescribing networks. | YES — BAA mandatory prior to PHI exposure. |
| Subcontractors | IT infrastructure vendors hired by a Business Associate to host or backup ePHI databases. | YES — BA must execute a BAA with its subcontractor. |
| Conduits (Exempt) | U.S. Postal Service (USPS), UPS, FedEx, internet service providers acting strictly as data conduits without routine access. | NO — Transient conduit exemption applies. |
Mandatory BAA Contractual Terms
Under HIPAA and HITECH, a Business Associate Agreement (BAA) must specify:
- Permitted and required uses and disclosures of PHI by the Business Associate.
- Mandates that the BA will not use or disclose PHI other than as permitted by contract or required by law.
- Requirements to implement Administrative, Physical, and Technical Safeguards under the HIPAA Security Rule.
- Mandatory reporting of security incidents and privacy breaches to the covered entity without unreasonable delay.
- Assurances that any subcontractors agree to the exact same restrictions and safeguards.
- Requirements to return or destroy all PHI upon contract termination.
Under HITECH, Business Associates face direct statutory liability and can be audited and fined directly by HHS OCR for HIPAA Security Rule non-compliance.
The Breach Notification Rule
The HITECH Act established the HIPAA Breach Notification Rule, requiring covered entities and business associates to issue formal notifications following a breach of unencrypted PHI.
Definition of a Breach
A breach is defined as the unauthorized acquisition, access, use, or disclosure of PHI under the Privacy Rule that compromises the security or privacy of the information.
Encryption Safe Harbor Provision
If PHI is rendered unusable, unreadable, or indecipherable to unauthorized persons using an encryption method consistent with HHS guidance — which points to NIST-validated processes such as AES-256 for data at rest — the exposure is exempt from breach notification requirements under the Safe Harbor. Two conditions matter: the encryption must meet that standard, and the decryption key must not have been compromised.
4-Factor Risk Assessment for Low Probability of Compromise
An unauthorized acquisition or disclosure of unencrypted PHI is presumed to be a breach unless the covered entity or business associate demonstrates through a documented risk assessment that there is a low probability the PHI has been compromised:
- Nature and extent of PHI involved: Types of identifiers, clinical details, and likelihood of re-identification.
- Unauthorized person who received or used the PHI: Whether the recipient is bound by HIPAA or confidentiality obligations.
- Whether PHI was actually viewed or acquired: Forensic evaluation of system logs.
- Extent of risk mitigation: Immediate remediation actions taken (e.g., obtaining a signed destruction affidavit).
Mandatory Breach Notification Protocols & Timelines
When an unencrypted PHI breach occurs, covered entities must execute strict notification workflows governed by statutory timelines:
| Notification Recipient | Breach Scope | Statutory Notification Timeline | Operational Notification Protocol |
|---|---|---|---|
| Affected Individuals | All breaches (1+ individuals) | Without unreasonable delay and no later than 60 calendar days after breach discovery. | Written notification via first-class mail (or secure email if individual opted in). Details breach event, data involved, protective steps, and facility contact details. |
| HHS OCR (Small Breaches) | Fewer than 500 individuals (< 500) | Within 60 days of the end of the calendar year in which the breach occurred. | Submitted electronically through the HHS OCR online breach reporting portal. |
| HHS OCR (Large Breaches) | 500 or more individuals (500+) | Without unreasonable delay and no later than 60 calendar days after breach discovery. | Submitted electronically simultaneously with individual notices; listed publicly on the HHS OCR online reporting wall. |
| Prominent Media Outlets | 500 or more residents of a state or jurisdiction | Without unreasonable delay and no later than 60 calendar days after breach discovery. | Formal press release issued to major media outlets in the affected jurisdiction detailing breach specifics. |
An unencrypted laptop containing 250 unencrypted patient records is stolen from a physical therapy clinic. Under the Breach Notification Rule, what is the notification requirement for HHS OCR?
A hospital suffers a cyberattack resulting in the unauthorized access of 1,200 patient records. The records were fully encrypted using AES-256 standards, and encryption keys were not compromised. How does the Breach Notification Rule apply?
Prior to the HITECH Act of 2009, how were Business Associates regulated regarding HIPAA compliance?