8.2 HITECH and Breach Notification

Key Takeaways

  • HITECH (2009, ARRA) created EHR incentive payments and made business associates directly liable for the Security Rule, certain Privacy Rule duties, and breach notice to the covered entity
  • A breach is an impermissible use or disclosure of unsecured PHI that is presumed to compromise the information unless a four-factor assessment shows a low probability of compromise
  • Unsecured PHI is PHI not rendered unusable, unreadable, or indecipherable by HHS-specified encryption or destruction; properly encrypted or destroyed PHI is in the notification safe harbor
  • Individual notice is without unreasonable delay and no later than 60 calendar days after discovery; HHS gets 500+ incidents on the same clock and fewer-than-500 incidents annually within 60 days after year-end
  • Media notice is required when a breach affects 500 or more residents of a State or jurisdiction; official HHS summary is at https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Last updated: August 2026

HITECH’s Two Jobs

The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009 as Title XIII of the American Recovery and Reinvestment Act (ARRA), did two things CIPP/US still tests as a pair. First, it funded large-scale adoption of electronic health records (EHRs). The Centers for Medicare & Medicaid Services (CMS) paid eligible professionals and hospitals that demonstrated meaningful use of certified EHR technology. That incentive program later evolved into Promoting Interoperability. The privacy point is contextual, not a dollar-memorization exercise: Congress subsidized digitization and, in the same statute, tightened the rules that apply once the records are electronic.

Second, HITECH strengthened HIPAA. Section 13401 applies the Security Rule’s administrative, physical, and technical safeguards — and its policies, procedures, and documentation requirements — to business associates in the same manner as to covered entities, and it makes business associates civilly and criminally liable for those violations. The 2013 Omnibus Final Rule implemented that direct-liability scheme, expanded who counts as a business associate (including many health information organizations, e-prescribing gateways, and personal-health-record vendors offering a record on behalf of a covered entity), and confirmed that subcontractors of business associates are themselves business associates. HITECH also created the HIPAA Breach Notification Rule (now 45 CFR 164.400–414) and instructed HHS to use stronger, tiered enforcement. Do not recite a current civil-money-penalty dollar table from memory; OCR publishes inflation-adjusted four-tier penalty ranges, and the exam cares more about who is liable and what must be notified than about this year’s per-violation ceiling.

Business Associate Direct Liability

Before HITECH, a business associate’s HIPAA duties lived almost entirely in the BAA. OCR could not walk into the vendor and assess a civil money penalty for a Security Rule failure. After HITECH and the 2013 Omnibus Rule, OCR may proceed directly against a business associate for a defined list of violations. HHS’s fact sheet is the clean inventory:

  • Failure to give HHS records, reports, and access during an investigation
  • Retaliation against someone who files a HIPAA complaint or participates in an investigation
  • Failure to comply with the Security Rule
  • Failure to notify the covered entity (or another business associate) of a breach of unsecured PHI
  • Impermissible uses and disclosures of PHI
  • Failure to provide an electronic copy of ePHI when the BAA assigns that access duty
  • Failure to apply the minimum necessary standard
  • Failure, in specified circumstances, to provide an accounting of disclosures
  • Failure to execute BAAs with subcontractors that handle PHI, and failure to address a material breach of a subcontractor BAA

Direct liability is not a blank check. OCR has said it cannot enforce the Privacy Rule’s reasonable, cost-based access-fee limit against a business associate, because HITECH did not apply that provision to business associates. If a vendor overcharges for copies, OCR’s fee-limit case runs against the covered entity that owes the individual access.

What Counts as a Breach of Unsecured PHI

The Breach Notification Rule requires notice after a breach of unsecured PHI. A breach is, generally, an acquisition, access, use, or disclosure of PHI not permitted by the Privacy Rule that compromises the security or privacy of that PHI. Since the Omnibus Rule, an impermissible use or disclosure is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment of at least four factors. The entity may skip the assessment and just notify; it may not skip both the assessment and the notice.

Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons using a technology or methodology specified in HHS guidance. That guidance names two methods: encryption that meets the Security Rule definition (an algorithmic process with a low probability of assigning meaning without the key, and the key itself not breached) consistent with National Institute of Standards and Technology (NIST) standards, and destruction (shredding or otherwise destroying hard-copy media so it cannot be reconstructed; clearing, purging, or destroying electronic media consistent with NIST SP 800-88). Redaction of paper is not destruction. If the data were properly encrypted or destroyed, the incident is inside the notification safe harbor and the Rule’s individual/HHS/media notices are not required. If the encryption key was taken with the laptop, the safe harbor fails.

Three exceptions take an incident out of the definition of breach even without a four-factor win: (1) unintentional acquisition, access, or use by a workforce member or person acting under the entity’s authority, in good faith and within scope, with no further impermissible use; (2) inadvertent disclosure from one authorized person to another authorized person at the same covered entity, business associate, or organized health care arrangement, with no further impermissible use; and (3) a good-faith belief that the unauthorized recipient could not reasonably have retained the information.

The Four-Factor Assessment

HHS’s official breach page lists the four factors that a “low probability of compromise” analysis must address:

  1. The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
  2. The unauthorized person who used the PHI or to whom the disclosure was made.
  3. Whether the PHI was actually acquired or viewed.
  4. The extent to which the risk has been mitigated.

A lost, encrypted, and remotely wiped laptop that never left a locked bag scores differently from an unencrypted spreadsheet of HIV results emailed to the wrong outside address and downloaded before recall. Ransomware is a fact-specific Security Rule incident; OCR’s ransomware guidance says encryption by an attacker is often a compromise of availability and may be a presumed breach unless the four-factor analysis (or an exception) shows otherwise. The entity that claims “not a breach” has the burden of proof and must keep the assessment.

Who Gets Notice, and When

Following a breach of unsecured PHI, the covered entity notifies affected individuals, the Secretary of HHS, and, in some cases, the media. A business associate that discovers a breach at or by the business associate notifies the covered entity without unreasonable delay and no later than 60 calendar days from discovery, identifying affected individuals and supplying the information the covered entity needs for its notices. The covered entity remains responsible for individual notice but may delegate the mailing to the business associate.

AudienceTriggerClock (from discovery)Channel / extra rules
IndividualsAny breach of unsecured PHIWithout unreasonable delay and in no case later than 60 calendar daysFirst-class mail, or email if the individual agreed; substitute notice if contact data are insufficient (web posting or media plus a 90-day toll-free number when 10 or more individuals cannot be reached)
HHS Secretary500 or more individualsWithout unreasonable delay and in no case later than 60 calendar daysElectronic report on the HHS site; posted on OCR’s public “wall of shame”
HHS SecretaryFewer than 500 individualsAnnual log, due no later than 60 days after the end of the calendar year in which the breaches were discoveredSame HHS portal; not a 60-day-from-discovery HHS filing
MediaMore than 500 residents of a State or jurisdictionWithout unreasonable delay and in no case later than 60 calendar daysNotice to prominent media outlets serving that State or jurisdiction, typically a press release; same content as the individual notice
Covered entity (from a BA)Breach at or by the business associateWithout unreasonable delay and no later than 60 calendar daysIdentity of each affected individual “to the extent possible,” plus the other individual-notice elements

Discovery is when the incident is known, or would have been known by exercising reasonable diligence — not when the legal department finishes its memo. “Without unreasonable delay” can be shorter than 60 days. Waiting until day 59 to start collecting addresses, without a law-enforcement delay, is the classic fail. Individual notices must describe, to the extent possible, what happened, the types of information involved, steps individuals should take, what the entity is doing to investigate, mitigate, and prevent recurrence, and how to contact the entity.

Scenario. On March 3 a cloud backup vendor (a business associate) learns that an unencrypted database containing 620 Texas patients’ names, dates of birth, and diagnosis codes was exposed to the open internet. The vendor must notify the hospital without unreasonable delay and within 60 days. The hospital must notify those individuals and HHS without unreasonable delay and within 60 days, and must notify prominent Texas media because 500 or more residents of that State are affected. If the same file had been encrypted to HHS guidance and the key was not taken, none of those Rule-required notices would fire.

Covered entities must maintain written breach-notification policies, train the workforce, and sanction noncompliance. Official HHS text: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html.

Exam traps

  • The 60-day figure is a ceiling, not a safe harbor for delay.
  • The 500-person HHS clock is not the same as the fewer-than-500 annual log.
  • Media notice keys off 500 or more residents of a State or jurisdiction, not 500 people scattered across the country.
  • Encryption is a notification safe harbor, not a finding that no Security Rule incident occurred.
  • A business associate’s 60-day notice runs to the covered entity, not to HHS, unless the parties have assigned individual notice and the facts independently trigger the covered entity’s Secretary or media duties.
Loading diagram...
HIPAA Breach Notification Decision Path
Test Your Knowledge

A clinic discovers on November 10 that an unencrypted spreadsheet of 80 patients’ names and account numbers was emailed to the wrong outside accountant. The four-factor assessment does not show a low probability of compromise. When must the clinic notify HHS?

A
B
C
D
Test Your Knowledge

Under the HIPAA Breach Notification Rule, an impermissible disclosure of unsecured PHI is presumed to be a breach unless the covered entity or business associate demonstrates a low probability of compromise. Which set of factors must that assessment address?

A
B
C
D
Test Your Knowledge

What did HITECH change about business associates?

A
B
C
D