How to Secure Health Care Data to Meet HITECH Act Compliance

Verfasst von
Gretchen Hellman
Gretchen Hellman
Published: Feb 1, 2010
Updated: Feb 2, 2021
2 minute read
eWeek Inhalte und Produktempfehlungen sind redaktionell unabhängig. Wir können Geld verdienen, wenn Sie auf Links zu unseren Partnern klicken. Mehr erfahren

In February 2009, President Obama signed the Health Information Technology for Economic and Clinical Health (HITECH) Act as part of his overall economic stimulus plan. The HITECH Act continues the effort of the Health Insurance Portability and Accountability Act (HIPAA) to encourage movement to electronic patient records and to deliver stricter data protection regulations for more secure patient privacy.

Among the most important of the new HITECH Act mandates is a federal breach notification requirement for stored health information that is not encrypted or otherwise made indecipherable, as well as increasing penalties for violations. Until this law was passed, only two of the 48 states with data breach notification requirements included health information as a specified data type. Now with the HITECH Act, the entire United States health industry and their business partners must quickly understand and get ready for these new data breach notification requirements.

With HITECH Act data breach disclosure requirements already in effect, the problem is imminent and unsolved. Most health organizations are currently not encrypting their patient health data stores. The HIPAA Security Rule, finalized in 2003, defines encryption as “addressable,” which required HIPAA-regulated entities to evaluate and document whether or not they were going to use encryption based on viability and organizational risk-but did not mandate encryption.

Now with the HITECH Act, thousands of healthcare-related businesses are finding themselves struggling to understand not only the HITECH Act’s breach notification requirements, but also what it means to encrypt their data. In addition to data breach notification requirements for all HIPAA-covered entities, the HITECH Act also extended HIPAA requirements beyond the traditionally covered entities of “payors, providers and clearinghouses” to include their business partners.

In light of the new demands and requirements that the HITECH Act has put on healthcare organizations, as well as the introduction of more severe penalties, organizations need to get started with a strategy immediately.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Eigentum von TechnologyAdvice. © 2026 TechnologyAdvice. Alle Rechte vorbehalten

Werbetreibenden-Offenlegung: Einige der auf dieser Website erscheinenden Produkte stammen von Unternehmen, von denen TechnologyAdvice eine Vergütung erhält. Diese Vergütung kann beeinflussen, wie und wo Produkte auf dieser Website erscheinen, einschließlich beispielsweise der Reihenfolge, in der sie erscheinen. TechnologyAdvice schließt nicht alle Unternehmen oder alle auf dem Marktplatz verfügbaren Produkttypen ein.