HITECH Act
The Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted as part of the American Recovery and Reinvestment Act of 2009, and was signed into law on February 17, 2009. This Act was passed with the stated purpose of promoting the adoption and meaningful use of health information technology. Subtitle D of this Act addresses the privacy and security concerns associated with the electronic transmission of health information. Several provisions expand and increase civil and criminal enforcement of the rules under HIPAA.
Effective February 18, 2009, Section 13410(d) of the HITECH Act revised section 1176(a) of the Social Security Act by establishing:
- four categories of violations that reflect increasing levels of culpability;
- four corresponding tiers of penalty amounts that significantly increase the minimum penalty amount for each violation; and
- a maximum penalty amount of $1.5 million for all violations of an identical provision.
The HITECH Act also amended section 1176(b) of the Act by:
- striking the previous bar on the imposition of penalties if the covered entity did not know and with the exercise of reasonable diligence would not have known of the violation (such violations are now punishable under the lowest tier of penalties); and
- providing a prohibition on the imposition of penalties for any violation that is corrected within a 30-day time period, as long as the violation was not due to willful neglect.
An interim final rule, effective on November 30, 2009, sought to conform HIPAA’s enforcement regulations to the new statutory revisions effective under section 13410(d) of the HITECH Act.