If your company does business with a health care provider, or if your company is a subcontractor to a company that does business with a health care provider, it may be subject to the HITECH Act (the Health Information Technology for Economic and Clinical Health Act).
HITECH was created in 2009 to stimulate the adoption of electronic health records and supporting technology. An additional purpose of the HITECH Act was to require business associates of health care providers to implement adequate safeguards to protect electronic health records under their control.
One way in which HITECH attempts to ensure compliance by business associates is by making the weighty penalties available under HIPAA (the Health Insurance Portability and Accountability Act) directly applicable to them.
What is a business associate under the HITECH Act?
According to the HITECH Act, a business associate may include any business that creates, receives, maintains or transmits protected health information (PHI). A few examples of types of companies that may constitute business associates under this broad definition are banks, law firms, actuaries, accountants, consultants, data aggregation companies, claims clearinghouses, billing firms, health information exchanges, software companies, video conference providers, and data providers.
Requirements for business associates under the HITECH Act.
The HITECH Act includes a long list of required and addressable standards that business associates must implement in order to be HIPAA-compliant. These standards include:
- administrative safeguards (such as security policies and training);
- physical safeguards (such as device and media controls); and
- technical safeguards (such as audit controls and transmission security).
The HITECH Act also requires business associates to implement policies for providing notice of any breach that has, or is reasonably believed to have, resulted in an unauthorized disclosure of PHI.
Depending on the extent of the breach, the business associate may be required to provide notice to the affected victims, the contracted health care organization, the U.S. Department of Health and Human Service (HHS) and the media.
To ensure compliance with HIPAA and HITECH privacy and security requirements, the HITECH Act authorizes HHS to conduct audits of business associates.
Penalties for failing to comply with the HITECH Act.
Violations of the HITECH Act can result in significant monetary fines and criminal penalties. Civil fines for noncompliance can be up to $250,000 per violation, with repeat or uncorrected violations incurring fines as high as $1.5 million.
Criminal penalties may be imposed against those business associates that intentionally disclose PHI and can include fines of up to $250,000 and prison terms of up to 10 years.
Possible mitigation under the HITECH Act.
The type or severity of penalty imposed under the HITECH Act can vary based on the measures taken by the business associate to prevent the unauthorized disclosure of PHI. Business associates can mitigate potential civil and criminal penalties by conducting thorough analyses of the requirements of the HITECH Act and tailoring their privacy and security policies and procedures to comply with these requirements.
Search Blog
Follow Us
Recent Posts
- Federal Court Strikes Down the DOL’s Increased Salary Thresholds for Executive, Administrative, Professional, And Highly Compensated Employee Overtime Exemptions
- Breaking News: FinCEN Postpones Beneficial Ownership Reporting Deadlines for Companies Impacted by Recent Major Storms
- What You Need to Know About the U.S. Department of Transportation’s Build America TIFIA Loan
- Breaking News: Federal Judge Blocks Nationwide Implementation of the FTC’s New Rule Banning Noncompete Agreements
- September 4th is Almost Here: How Employers Can Prepare for the Upcoming Effective Date of the FTC’s Non-Compete Rule
- Florida’s New Statutory Home Warranty: What Home Builders Need to Know
- Orange County Proposes Temporary Suspension Ordinance on New Development Applications
- Raising the Roof: The U.S. Department of Labor Announces Rule Raising Salary Thresholds for Overtime Exemptions
- New Guidelines Anticipated Following HHS’s Health Cybersecurity Concept Paper
- SECURE 2.0 and Protecting Your Designated Beneficiaries
Popular Categories
- Employment and Labor
- Litigation (Labor & Employment)
- Department of Labor
- Salary
- Construction
- Business of Real Estate
- Landlord-Tenant
- Construction Litigation
- Real Estate Law
- Competition
- Cybersecurity
- Intellectual Property
- Appeals
- Construction
- Public Private Partnership
- Litigation
- Contracts
- Trusts and Estates
- Data Security
- Development/Land Use
- Business
- Supreme Court
- Privacy
- Technology
- IP Litigation
- Litigation (Appellate)
- Patents
- Public Finance
- Business
- Regulatory Compliance
- Florida Government Contracts
- Foreclosures
- Trademark
- Health Care
- Contracting
- Financial Institutions
- Compliance
- Estate planning
- International Dispute Resolution
- Property Tax
- Florida Public Contracts
- Government Contracting
- Government Contracts
- Government
- Conveyances
- Lease
- Appellate Blog
- Patent Office
- Insurance
- Wealth planning
- Federal Government Contracting
- Florida Bid Protests
- Public Contracts
- Infringement
- Cyber fraud
- Proposal Writing
- Public Bidding
- GAO
- International Arbitration and Litigation
- Bid Protest
- Arbitration
- Americans with Disabilities Act
- International
- Restrictive Covenants
- Grant Writing
- Copyright
- Promissory Notes
- Title
- Small Business
- Florida Procurement
- Public procurement
- Consumer Privacy
- PTAB
- General Liability
- Technology
- International Arbitration
- Liens
- Liens and encumbrances
- Creditor's Rights
- Bidding
- Attorneys' Fees
- Inter Partes Review
- Power Generation
- Consumer Protection
- Regulation
- Contracting
- Government Vendor
- State Government Contracts
- Venue
- Ad Valorem Assessments
- Florida Administrative Law
- Attorneys' Fees
- Florida Rules of Appellate Procedure
- Bankruptcy
- Florida Public Procurement
- Russia-Related Arbitration
- Mortgages
- Record on Appeal
- FINRA
- Eviction
- Rehearing
- Loan guaranties
- Patents - Assignor Estoppel
- Statute of limitations
- Statute of repose
- Dispute Resolution
- Liens
- Maritime
- Damages
- Briefing
- Patents - Obviousness
- Request for Proposal
- Commercial Brokerage
- Trade Secrets
- Bid Writing
- Florida Bidding Strategies
- Renewal
- Attorneys' Fees
- Florida County Lands
- Florida Economic Incentive Packages
- Jury Instructions
- Stay
- Certiorari
- Design Professionals
- Forum Selection
- email hacking
- Offers of Judgment
- Prevailing Party
- Settlements
- Assignment of Contract
- Assignment of Proceeds
- Designer Liability
- Lis Pendens
- Appellate Jurisdiction - Deadlines
- Banking
- Evidence
- Evidence
- Expert
- Expert Science
- Federal Rules of Appellate Procedure
- Finality
- Fintech
- Marketing/Advertising
- Preservation
- Unlicensed Contracting
- Federal Supply Schedule
- Florida Public Records Law
- Mootness
- Socio-Economic Programs
- Sunshine Law
- Veteran Owned Business
- Homestead
- Partnerships and LLCs
- Standing
Editors
- Of Counsel
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Associate
- Partner
- Partner
- Associate
- Partner
- Partner
- Partner
- Partner
- Senior Associate
- Partner
- Associate
- Partner
- Senior Associate
- Partner
- Associate
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Partner
- Of Counsel
- Senior Associate
- Partner
- Associate
- Partner
- Partner
- Associate
- Partner
- Partner
- Partner
Archives
- November 2024
- October 2024
- September 2024
- August 2024
- June 2024
- May 2024
- February 2024
- November 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- October 2019
- August 2019
- July 2019
- May 2019
- April 2019
- March 2019
- February 2019
- January 2019
- December 2018
- November 2018
- October 2018
- September 2018
- August 2018
- July 2018
- June 2018
- May 2018
- April 2018
- March 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- August 2016
- July 2016
- June 2016
- May 2016
- April 2016
- March 2016