HITECH Act Compliance Assessment

Evaluate your compliance with the Health Information Technology for Economic and Clinical Health Act

HealthcareBiotechResearch15 minutes15 questions

1. Breach Notification

Do you have a breach notification policy that complies with HITECH requirements?*

HITECH requires notification of breaches affecting 500+ individuals within 60 days

Have you trained staff on breach detection and reporting procedures?*

Do you maintain a breach log with risk assessments for all incidents?*

2. Business Associate Agreements

Are all Business Associate Agreements (BAAs) updated to meet HITECH standards?*

HITECH expanded BA liability and required specific contract provisions

Do your BAAs include provisions for breach notification from BAs to you?*

Have you verified that subcontractors have BAAs in place?*

3. Enforcement & Penalties

Are you aware of the tiered penalty structure under HITECH ($100 - $50,000 per violation)?*

Do you have cyber liability insurance that covers HITECH penalties?*

4. Electronic Health Records

If you use EHR systems, are they certified under the ONC Health IT Certification Program?

Do you participate in meaningful use reporting for Medicare/Medicaid incentives?

5. Privacy & Security

Have you conducted a Security Risk Analysis (SRA) in the past 12 months?*

Required under HIPAA Security Rule, emphasized by HITECH enforcement

Do you encrypt ePHI at rest and in transit?*

Are patients able to request electronic copies of their health information?*

HITECH strengthened patient rights to access their data

Do you have audit controls in place to track access to ePHI?*

Have you appointed a Privacy Officer and Security Officer?*

Please answer all required questions to see your results