HITECH Act: Health Information Technology Policy and Impact
This paper examines the HITECH Act (Health Information Technology for Economic and Clinical Health), enacted as part of the 2009 American Recovery and Reinvestment Act. It describes how HITECH updated and strengthened the original 1996 HIPAA framework by incentivizing electronic health record (EHR) adoption, imposing stricter privacy and security requirements, and extending liability to business associates of covered entities. The paper also explores the roles of state governments and chief information officers in health information exchange planning, the functions of the HIT Policy and HIT Standards Committees, and the range of entities and populations affected by the legislation, including healthcare providers, health plans, clearinghouses, and marriage and family therapists.
- Policy Description and Overview: HITECH provisions, EHR incentives, and HIPAA privacy updates
- Role of the State in Policy Development and Implementation: State CIO roles in HIE planning and grant management
- Role of the Legislative Committee: HIT Policy and Standards Committees under ARRA
- Affected Populations and Covered Entities: Providers, health plans, BAs, and therapists governed by HITECH
- References: Cited sources supporting the policy analysis
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Clearly organized into distinct policy dimensions — description, state roles, legislative oversight, and affected populations — making a complex regulatory topic accessible.
- Grounds abstract policy language in concrete examples, such as the $250,000 minimum fine for privacy breaches and the specific federal agencies involved in HIT financing.
- Uses consistent citation of multiple scholarly and professional sources to support each section, lending credibility to the policy analysis.
Key academic technique demonstrated
The paper demonstrates effective policy explication — the ability to break down a multilayered federal statute into its functional components and trace how each component operates at different levels of governance (federal, state, and institutional). This is done without oversimplifying the regulatory detail, making it a useful model for health policy analysis writing.
Structure breakdown
The paper opens with a legislative overview of HITECH and its relationship to HIPAA, then moves outward to state-level implementation responsibilities, federal committee roles, and finally the specific entities and individuals governed by the law. Each section builds on the previous, creating a layered understanding of the policy's reach and enforcement mechanisms. The conclusion is implied through the "Affected Populations" section rather than stated as a separate concluding paragraph.
Policy Description and Overview
The HITECH Act (Health Information Technology for Economic and Clinical Health) forms part of the 2009 U.S. Recovery and Reinvestment Act (ARRA) and represents a major overhaul of the 1996 Health Insurance Portability and Accountability Act (HIPAA). Under HITECH, monetary incentives are delivered to healthcare providers and health schemes for employing electronic health records (EHRs), with the target of ensuring EHR implementation in every U.S. health facility by the year 2014. Further, HITECH adds stricter privacy rules, which include overseeing business partners for healthcare plans, clearinghouses, and providers, as well as notification requirements and additional penalties for noncompliance. The requirements take effect on different dates, further complicating the process of compliance (HITECH, 2009).
HITECH established civil financial penalties, criminal penalties, and mandatory federal reporting requirements for security breaches that cause patient privacy loss. Additionally, it provided financial support for compliance audits. The Office of Civil Rights (OCR) is responsible for handling security breach cases; more than 500 cases are reported on the OCR's website. Whereas confidentiality once dealt with the therapeutic relationship under state supervision, the concept is now associated with federal supervision and rules. This affects all written, oral, and electronic interactions between clients and marriage and family therapists (MFTs), as well as any discussions about clients (Hecker & Edwards, 2014).
Under HIPAA, health-related information cannot be divulged without acquiring patient permission or agreement, unless the release of information is necessary for administering healthcare, benefits, or payment. Moreover, healthcare providers are required to explain privacy policies to patients on a regular basis, and patients or clients must also disclose information to the U.S. Department of Health and Human Services (DHHS) when required (Horowitz, 2011). Privacy breach penalties are now harsher than ever under HITECH: companies may be fined no less than $250,000 for patient information breaches. Amit Trivedi, health program manager at Verizon's ICSA Labs, states that HITECH broadened the scope of privacy protection under HIPAA following criticisms about strict adherence to the privacy regulations. ICSA analyzes EHRs for compliance with federal rules on meaningful use. Business associates — that is, third-party cloud providers or billing companies — must abide by HIPAA privacy rules through patient information protection and reporting of any breach (Horowitz, 2011).
Role of the State in Policy Development and Implementation
HITECH posed numerous implications for states, calling for leadership in two chief areas: supervision of health information exchange (HIE) planning and execution, which encompasses applying for and managing grant funds (which may, in part, be assigned to any state-chosen agency), and managing Medicaid incentive payments to entitled recipients such as providers. State governors are responsible for appointing an agency or individual in their respective states for the purpose of receiving HIE development and execution grants. HIE execution grants can only be awarded to state-assigned entities that have a set, DHHS-approved plan; guidelines regarding minimum requirements for state plans and the procedure for applying for HIE planning grants are publicly available (Ellis, 2009).
HITECH's enactment integrated state government technology policies into health policy; state chief information officers (CIOs) have a central role to play in the development and execution of HIE. States are bringing stakeholders together, establishing a foundation for implementation plans, and carrying out resource-connected environmental scans. CIOs must establish themselves as important stakeholders in order to facilitate the creation of policies that will affect their offices. State CIOs may have direct and lasting influence over HIE in four broad fields: Design, Governance, Policy, and Funding/Sustainability. Each of these fields carries its own distinct challenges; however, the four are correlated and mutually dependent when it comes to determining their individual outcomes. This major undertaking means that state-level CIOs must address persistent critical questions that are complex and may not have readily apparent solutions (Ellis, 2009; Vinson, 2011).
The state planning phase of health information technology (HIT) following HITECH's promulgation has begun, despite wide variations in individual states' HIE/HIT planning progress. Rapidly advancing states owe their progress to pioneers who began early efforts to lay the foundation of HIT/HIE, with the aim of propelling their states to the forefront of the HIT domain. A number of states are reviewing original HIE plans and independently evaluating their HITECH grant eligibility. HITECH delegated a considerable number of new duties to states in terms of HIE supervision and HIE planning and execution grants. In the initial planning phase, state CIOs must secure a place for themselves as major stakeholders, identify strengths, and ascertain weaknesses that need to be resolved in their respective offices in relation to HIE/HIT planning. CIOs should assess their own competencies to determine their capacity to contribute to the aforementioned areas, in light of their unique enterprise perspective (Nicholls, 2010).
State CIOs have been involved in current HIT efforts in multiple ways. HITECH's enactment has discontinued some such efforts, while others may be altered or restructured to suit the new mandated frameworks and upcoming standards. State-level CIOs can participate in statewide HIE planning and help their states become eligible for grants in the following ways (Vinson, 2011; Hecker & Edwards, 2014):
Organize and participate in environmental scanning of current enterprise-wide health legacy structures that may require replacement or upgrading. Investigate the state's HIT assets to help determine which assets must be leveraged upon reaching the competitive grant stage.
Team up with organizational stakeholders and get in touch with Medicaid leaders, healthcare policy advisors, and public health counselors to state governors. Identify the HIT spokesperson as well as the individual, if any, selected as the overall state leader for HIT/HIE. State CIOs should understand the scope of participating stakeholders and determine the key parties with whom relationships need to be cultivated.
Recognize and establish contact with the various federal agencies — chiefly through the DHHS, including the Office of the National Coordinator (ONC) for HIT, the Centers for Medicare & Medicaid Services (CMS), the Agency for Healthcare Research and Quality (AHRQ), the Centers for Disease Control and Prevention (CDC), the Indian Health Service (IHS), and the Health Resources and Services Administration (HRSA) — that will finance state-level HIT. Furthermore, HIT financing streams will affect the federal Departments of Veterans Affairs, Defense, Agriculture, and Commerce, as well as the Social Security Administration (SSA) and the National Institute of Standards and Technology (NIST), with effects percolating down to states.
Detect and engage with currently available opportunities. Various state-level workgroups and agencies may be established by the state-governor-appointed HIE/HIT leader. The involvement of state CIOs in the appropriate venues is crucial (Hecker & Edwards, 2014; Vinson, 2011; Horowitz, 2011).
Create your account
Always verify citation format against your institution’s current style guide requirements.