People often say HIPAA when they mean the whole framework governing health data, but HITECH is a distinct law that changed how HIPAA works in practice. Understanding the relationship matters for anyone building or running software that touches protected health information.
HIPAA established the core privacy and security rules for protected health information: who can use and disclose it, and the safeguards, administrative, physical, and technical, required to protect it. It defined covered entities, like providers and health plans, and the obligations that come with handling health data. It is the foundation.
HITECH, enacted later as part of a broader health-technology push, strengthened HIPAA in several ways. It increased enforcement and penalties, making violations far more consequential. It introduced a formal breach notification requirement, obligating notification of affected individuals and regulators when protected health information is breached. And it extended direct liability to business associates, the vendors and contractors that handle health data on behalf of covered entities.
For a technology vendor serving healthcare, HITECH's extension of direct liability to business associates is pivotal: a software company handling PHI is directly on the hook, not merely contractually. Combined with real breach-notification duties and stiffer penalties, the framework makes building health software with safeguards in the foundation, and signing proper business associate agreements, not optional.
HIPAA wrote the rules. HITECH made them bite.
This is general educational information, not specific security, compliance, or legal advice for your systems.