Definition

HITECH Act

The HITECH Act is the 2009 federal law, enacted as part of the American Recovery and Reinvestment Act, that funded EHR adoption through Medicare and Medicaid incentive payments and strengthened HIPAA privacy, security and breach notification rules.

2 min readReviewed September 14, 2026

Also known as: HITECH, Health Information Technology for Economic and Clinical Health Act, ARRA health IT provisions

Key facts

Full name
Health Information Technology for Economic and Clinical Health Act
Enacted
February 17, 2009, in Public Law 111-5 (ARRA)
Created
Medicare and Medicaid EHR Incentive Programs (Meaningful Use)
HIPAA changes
Breach notification, business associate liability, tiered penalties
Implementing HIPAA rule
Omnibus Final Rule, published January 2013

What is the HITECH Act?

HITECH was part of the economic stimulus law passed in early 2009. It set out to move U.S. health care from paper to electronic records and to strengthen privacy and security protections as patient data went digital.

The law wrote the Office of the National Coordinator for Health Information Technology (ONC) into statute and funded programs to help providers choose, install and use certified EHRs. ONC has since been renamed the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health IT (ASTP/ONC).

Main provisions of the HITECH Act

HITECH combined funding, program design and privacy law changes:

  • EHR incentives: Medicare and Medicaid payments to eligible professionals and hospitals that demonstrated meaningful use of certified EHR technology, followed by Medicare payment reductions for those that did not.
  • Certification: a statutory basis for federal certification of health IT, carried out through the ONC Health IT Certification Program.
  • Adoption support: Regional Extension Centers for small practices and grants to build state health information exchange.
  • Breach notification: duties to notify individuals, HHS and sometimes the media after a breach of unsecured PHI, plus an FTC breach rule for personal health record vendors.
  • HIPAA enforcement: direct liability for business associates, tiered civil money penalties and enforcement authority for state attorneys general.
  • Patient rights: a right to an electronic copy of health information held in an EHR.

Why the HITECH Act still matters

Many current programs and compliance duties come from HITECH:

  • EHR market: incentive payments drove rapid EHR adoption among hospitals and office-based physicians in the 2010s, shaping today's developer market.
  • CMS programs: the Medicare Promoting Interoperability Program and the MIPS Promoting Interoperability category are successors to Meaningful Use.
  • Breach tracking: HHS posts breaches affecting 500 or more individuals on a public portal, which analysts use to track provider and vendor risk.
  • Penalties: a 2021 amendment requires HHS to consider whether an entity had recognized security practices in place for the prior 12 months when deciding penalties and audit outcomes.

Sources

All glossary terms