Definition
HITECH Act
The HITECH Act is the 2009 federal law, enacted as part of the American Recovery and Reinvestment Act, that funded EHR adoption through Medicare and Medicaid incentive payments and strengthened HIPAA privacy, security and breach notification rules.
2 min readReviewed September 14, 2026
Also known as: HITECH, Health Information Technology for Economic and Clinical Health Act, ARRA health IT provisions
Key facts
- Full name
- Health Information Technology for Economic and Clinical Health Act
- Enacted
- February 17, 2009, in Public Law 111-5 (ARRA)
- Created
- Medicare and Medicaid EHR Incentive Programs (Meaningful Use)
- HIPAA changes
- Breach notification, business associate liability, tiered penalties
- Implementing HIPAA rule
- Omnibus Final Rule, published January 2013
What is the HITECH Act?
HITECH was part of the economic stimulus law passed in early 2009. It set out to move U.S. health care from paper to electronic records and to strengthen privacy and security protections as patient data went digital.
The law wrote the Office of the National Coordinator for Health Information Technology (ONC) into statute and funded programs to help providers choose, install and use certified EHRs. ONC has since been renamed the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health IT (ASTP/ONC).
Main provisions of the HITECH Act
HITECH combined funding, program design and privacy law changes:
- EHR incentives: Medicare and Medicaid payments to eligible professionals and hospitals that demonstrated meaningful use of certified EHR technology, followed by Medicare payment reductions for those that did not.
- Certification: a statutory basis for federal certification of health IT, carried out through the ONC Health IT Certification Program.
- Adoption support: Regional Extension Centers for small practices and grants to build state health information exchange.
- Breach notification: duties to notify individuals, HHS and sometimes the media after a breach of unsecured PHI, plus an FTC breach rule for personal health record vendors.
- HIPAA enforcement: direct liability for business associates, tiered civil money penalties and enforcement authority for state attorneys general.
- Patient rights: a right to an electronic copy of health information held in an EHR.
Why the HITECH Act still matters
Many current programs and compliance duties come from HITECH:
- EHR market: incentive payments drove rapid EHR adoption among hospitals and office-based physicians in the 2010s, shaping today's developer market.
- CMS programs: the Medicare Promoting Interoperability Program and the MIPS Promoting Interoperability category are successors to Meaningful Use.
- Breach tracking: HHS posts breaches affecting 500 or more individuals on a public portal, which analysts use to track provider and vendor risk.
- Penalties: a 2021 amendment requires HHS to consider whether an entity had recognized security practices in place for the prior 12 months when deciding penalties and audit outcomes.