← All HIPAA Flashcard Decks

HITECH Act and Technology Requirements Flashcards

36 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 HITECH Act and Technology Requirements flashcards as text
  1. What does the HITECH Act stand for and when was it enacted?

    Answer: Health Information Technology for Economic and Clinical Health, 2009

    HITECH stands for Health Information Technology for Economic and Clinical Health Act, enacted as part of the American Recovery and Reinvestment Act of 2009.

  2. How did the HITECH Act change HIPAA's enforcement penalties for covered entities?

    Answer: HITECH created a tiered penalty structure based on culpability with maximum penalties up to $1.9 million per violation category per year

    HITECH created a four-tier penalty structure based on the degree of culpability, dramatically increasing maximum penalties from $100 per violation to up to $50,000 per violation.

  3. Under the HITECH Act, who became directly subject to HIPAA's Security Rule obligations for the first time?

    Answer: Business associates, including EHR vendors and IT contractors handling PHI

    HITECH extended direct HIPAA Security Rule compliance obligations to business associates, making them directly liable for violations rather than just contractually liable through BAAs.

  4. What is the 'Breach Notification Rule' that HITECH established for unsecured PHI?

    Answer: A mandate requiring notification to affected individuals, HHS, and potentially media when unsecured PHI is breached

    HITECH's Breach Notification Rule requires mandatory notification to individuals, HHS, and potentially media when unsecured PHI is breached, within specific timeframes.

  5. What technology 'safe harbor' did HITECH create for breached PHI?

    Answer: Encrypting PHI using NIST-approved methods, which renders a breach presumptively non-reportable

    HITECH created a safe harbor from breach notification for PHI encrypted using NIST-approved standards — encrypted data breached is presumptively not a reportable breach.

  6. Under HITECH, what is the maximum daily penalty cap for violations of the same type in a single calendar year?

    Answer: $1,900,000

    HITECH capped annual civil monetary penalties at $1.9 million per violation category per calendar year (adjusted for inflation by HHS).

  7. What did HITECH require regarding state attorneys general and HIPAA enforcement?

    Answer: HITECH authorized state attorneys general to bring civil actions for HIPAA violations affecting state residents

    HITECH gave state attorneys general independent authority to bring civil suits for HIPAA violations affecting their residents, creating a second enforcement track beyond federal OCR.

  8. How did HITECH change the HIPAA requirement for accounting of disclosures when EHRs are used?

    Answer: HITECH required covered entities using EHRs to account for treatment, payment, and operations disclosures upon request

    HITECH expanded accounting of disclosures to include treatment, payment, and operations disclosures made through EHRs when patients request this information.

  9. What was the purpose of HITECH's 'Meaningful Use' program as it relates to health technology?

    Answer: To create financial incentives for providers adopting certified EHR technology and demonstrating its effective use

    Meaningful Use created Medicare and Medicaid financial incentives for providers adopting and meaningfully using certified EHR technology that met specific security and interoperability criteria.

  10. Under HITECH, what minimum security standard applies to PHI transmitted via email?

    Answer: PHI in email must be encrypted using NIST-approved encryption to receive the breach notification safe harbor

    HITECH's breach safe harbor requires NIST-approved encryption for PHI in email; unencrypted PHI emails that are intercepted constitute reportable breaches.

  11. How did HITECH affect the civil money penalty ranges for Business Associates under HIPAA?

    Answer: HITECH made business associates directly subject to the same civil money penalty tiers as covered entities

    HITECH subjected business associates to the same four-tier civil money penalty structure as covered entities, enabling OCR to directly fine BAs for HIPAA Security Rule violations.

  12. What is the HITECH requirement regarding the 'right to restrict' PHI disclosures?

    Answer: If a patient pays out-of-pocket in full for a service, they may restrict disclosure of that service to their health plan

    HITECH strengthened the right to restrict by requiring covered entities to honor requests to restrict disclosure to health plans when the patient pays in full out-of-pocket.

  13. What technology requirement did HITECH add for HIPAA regarding notification when ePHI is accessed by employees?

    Answer: System capability to generate audit reports of which employees accessed which patient records, available to patients upon request

    HITECH required EHR systems to include audit capabilities allowing generation of reports showing employee access to patient records, available to patients requesting accounting of disclosures.

  14. Under HITECH, what additional breach notification obligation applies when a breach affects 500 or more individuals in a single state?

    Answer: Prominent media outlets serving the affected state or jurisdiction must be notified

    HITECH requires notification to prominent media outlets in states where 500 or more residents are affected by a breach, in addition to individual and HHS notifications.

  15. How did HITECH change the HIPAA authorization requirements for using PHI in marketing?

    Answer: HITECH prohibited the use of PHI for marketing without individual authorization, with limited exceptions for face-to-face communications

    HITECH strengthened marketing restrictions by prohibiting the sale or use of PHI for marketing communications without authorization, limiting exceptions to face-to-face communications.

  16. What did HITECH add regarding individual access rights to electronic PHI?

    Answer: HITECH required covered entities to provide individuals with electronic copies of their ePHI if the individual requests it and a designated record set is maintained electronically

    HITECH required covered entities maintaining PHI in an EHR to provide patients with electronic copies upon request, a right not clearly established under original HIPAA.

  17. What specific technology standard did HITECH reference for acceptable encryption of PHI to qualify for the breach notification safe harbor?

    Answer: NIST Special Publication guidelines for valid encryption methods

    HITECH referenced NIST Special Publication guidance (specifically NIST SP 800-111 and related publications) to define what constitutes acceptable encryption for the breach safe harbor.

  18. How did HITECH change the prohibition on 'selling' PHI?

    Answer: HITECH prohibited the sale of PHI without individual authorization, with limited exceptions

    HITECH explicitly prohibited the sale of PHI without individual authorization, clarifying that selling PHI — even for research — requires authorization unless specific exceptions apply.

  19. Under HITECH, what requirement was added for notifying individuals when their PHI was accessed by their employer through a health plan?

    Answer: Health plans must notify individuals when their PHI is requested by their employer

    HITECH strengthened protections against employer access to PHI through health plan arrangements, requiring notification to individuals of such requests.

  20. What was the significance of HITECH's creation of a 'tiered' penalty structure rather than a flat per-violation fee?

    Answer: It calibrates penalties to the degree of culpability, creating stronger deterrence for negligent behavior while allowing proportionality for unknowing violations

    The tiered structure creates proportional deterrence — smaller penalties for genuinely unknowing violations, maximum penalties for willful neglect — incentivizing organizations to invest in compliance.