Skip to Content

A Summary of the Proposed HIPAA Regulations Implementing HITECH

Health Information Technology
Medical Records Collection, Retention, and Access
Privacy and Confidentiality
Security of Health Information

A Summary of the Proposed HIPAA Regulations Implementing HITECH

The Health Insurance Portability and Accountability Act of 1996 (HIPAA)1 contained a provision requiring the Secretary of the Department of Health and Human Services (HHS) to publish national standards to protect the privacy and security of individually identifiable health information.  These regulations are known as the HIPAA Privacy Rule and the HIPAA Security Rule.  In 2009, HIPAA was amended by the Health Information Technology for Economic and Clinical Health Act (HITECH), enacted as part of the American Recovery and Reinvestment Act (ARRA).2  In July 2010, HHS released a Notice of Proposed Rulemaking (NPRM or Proposed Rule) to implement the various changes to the Privacy and Security Rules required by HITECH.3  

1.) HIPAA Privacy Rule

a.)  Individually Identifiable Health Information

b.)  De-Identified Health Information

c.)  Limited Data Sets

d.)  Uses and Disclosures of PHI

e.)  Treatment, Payment, and Health Care Operations (TPO)

f.)  Public Interest Activities

g.)  Uses Requiring Individual Authorization   

h.)  Marketing

i.)  Fundraising

j.)  Sale of PHI

k.)  Limiting Uses and Disclosures to the Minimum Necessary

l.)  Business Associate Requirements

2.) HIPAA Security Rule

a.)  Entities Subject to or Affected by the Security Rule

b.)  Administrative Safeguards

c.)  Physical Safeguards

d.)  Organizational Safeguards

3.) HIPAA Enforcement

a.)  HITECH Expansion & Revised Civil Penalties

b.)  Direct Business Associate Liability

4.) HIPAA Breach Notification Provisions and Security Guidance

a.) Breach of Unsecured PHI

Current View


  • 1. Health Insurance Portability and Accountability Act of 1996 (HIPAA), Pub. L. No. 104-191, 110 Stat. 139 (1996) (codified as amended in scattered sections of 42 U.S.C.).
  • 2. ARRA, Pub. L. No. 111-5, Div. A, Title XIII, § 13404, 123 Stat. 260 (2009).
  • 3. Modifications to the HIPAA Privacy, Security, and Enforcement Rules, 75 Fed. Reg. 40,868, 40,872-73 (proposed July 14, 2010) (to be codified at 45 C.F.R. pt. 160 and 164).