HITECH Act and HIPAA Security Rule Training Requirements

A focused look at HITECH's breach notification and enforcement changes, and the HIPAA Security Rule's specific safeguard training requirements.

Learnsignal Education Team
8 min read
Updated

Most healthcare organizations already run general HIPAA awareness training — the kind that covers privacy basics, patient rights, and the minimum necessary standard. That training matters, but it rarely goes deep enough on two things compliance officers get tested on the hardest: what actually changed when the HITECH Act amended HIPAA in 2009, and what the HIPAA Security Rule specifically requires an organization to do, safeguard by safeguard, to protect electronic protected health information (ePHI). This guide is deliberately narrower and more technical than a general HIPAA overview — it's built for the compliance officers, IT security leads, and privacy staff who need to train their teams on breach notification, enforcement exposure, business associate liability, and the administrative, physical, and technical safeguards the Security Rule actually names.

If you're looking for foundational HIPAA privacy training, start with our HIPAA training requirements guide. If your focus is broader healthcare cybersecurity risk management, see healthcare cybersecurity and data protection training. This post picks up where both leave off: the specific statutory and regulatory mechanics of HITECH and the Security Rule.

What the HITECH Act Actually Changed

The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009 as part of the American Recovery and Reinvestment Act, didn't rewrite HIPAA from scratch — it closed several enforcement gaps that had made the original law relatively toothless. Three changes matter most for compliance training:

  • Business associates became directly liable. Before HITECH, a business associate's HIPAA obligations were purely contractual, running through its agreement with a covered entity. HITECH made business associates directly liable for their own compliance, subject to the same civil and, in some cases, criminal penalties as covered entities. The 2013 Omnibus Rule extended this further to subcontractors of business associates.
  • A formal breach notification rule was created. Before HITECH, there was no federal requirement to notify patients when their health information was breached. HITECH created that obligation from scratch.
  • State attorneys general gained enforcement authority. HITECH allows state AGs to bring civil actions on behalf of state residents harmed by HIPAA violations, in addition to HHS Office for Civil Rights (OCR) enforcement.

The Breach Notification Rule

HITECH's breach notification requirements are precise about timing and scope, which makes them a natural focus for training:

  • A covered entity must notify affected individuals without unreasonable delay, and no later than 60 days after discovering a breach of unsecured PHI.
  • If a breach affects 500 or more individuals, the covered entity must also notify HHS and prominent media outlets serving the affected area — on the same 60-day timeline.
  • Breaches affecting fewer than 500 individuals still must be reported to HHS, but this can be done in an annual log rather than immediately.
  • Business associates that discover a breach must notify the covered entity without unreasonable delay, so the covered entity's own 60-day clock can start.

A key structural point worth training staff on: the burden of proof shifted. Rather than HHS having to prove a breach caused harm, a covered entity or business associate that experiences an impermissible use or disclosure of PHI is presumed to have a reportable breach unless it can demonstrate, through a documented risk assessment, a low probability that the information was compromised.

Enforcement Tiers and Penalty Exposure

HITECH replaced HIPAA's original flat, low-dollar penalty structure with a four-tier civil monetary penalty framework tied to the organization's level of culpability. In broad terms:

  • Tier 1 — lack of knowledge: the organization did not know, and reasonably could not have known, of the violation.
  • Tier 2 — reasonable cause: the violation was not due to willful neglect, but the organization should have been aware of the risk.
  • Tier 3 — willful neglect, corrected: the violation involved willful neglect, but was corrected within 30 days of discovery.
  • Tier 4 — willful neglect, uncorrected: the violation involved willful neglect and was not corrected within 30 days.

Per-violation penalties within these tiers, and the annual cap for repeated violations of the same provision, are adjusted for inflation on a regular basis, with Tier 4 penalties for uncorrected willful neglect currently running into the low millions of dollars annually for the most serious, repeated violations. Because these figures change, training materials should point staff to the current HHS penalty table rather than hard-coding a dollar amount that will go stale.

The HIPAA Security Rule: Safeguards, Not Just Policies

Where HITECH changed enforcement, the Security Rule (45 CFR Part 164, Subpart C) is the regulation that actually tells covered entities and business associates what to do to protect ePHI. It organizes requirements into three categories, and training needs to map to all three — not just the policy documents most staff associate with "HIPAA training.":

  • Administrative safeguards: a documented security management process including risk analysis and risk management, an assigned security official, workforce security and access authorization procedures, a formal security awareness and training program (covering security reminders, protection against malicious software, login monitoring, and password management), security incident response procedures, and a contingency plan covering data backup, disaster recovery, and emergency-mode operations.
  • Physical safeguards: facility access controls, workstation use and security policies, and device and media controls governing how hardware and storage media containing ePHI are disposed of, reused, tracked, and backed up.
  • Technical safeguards: access controls (unique user IDs, emergency access procedures, automatic logoff, and encryption), audit controls that record activity in systems containing ePHI, integrity controls to prevent improper alteration or destruction of data, authentication procedures to verify a person's identity, and transmission security to protect ePHI moving across a network.

A detail worth emphasizing in training: many Security Rule specifications are labeled "addressable" rather than "required." Addressable does not mean optional — it means the organization must assess whether the specification is a reasonable and appropriate safeguard, implement it if so, or document an equivalent alternative and the reasoning if not. Staff often misunderstand "addressable" as "skip this," which is exactly the kind of gap a targeted training module should close.

A Rule in Motion: The Proposed 2025 Security Rule Overhaul

HHS published a Notice of Proposed Rulemaking in January 2025 proposing the most significant overhaul of the Security Rule since it was written. As of this writing, the rule remains proposed, not final, with the public comment period closed and a finalization timeline extending into 2027. The proposal would eliminate the "addressable" category altogether, making encryption of ePHI at rest and in transit mandatory, require multi-factor authentication for systems accessing ePHI, mandate documented risk assessments on a defined annual cycle, and add explicit requirements for vulnerability scanning, penetration testing, and a current technology asset inventory. Training programs should flag this as a proposed rule to watch rather than a current requirement, while noting that many of its provisions reflect practices OCR already expects as reasonable and appropriate under the existing "addressable" standard.

What This Training Should Cover

  • The specific difference HITECH made to business associate liability, with real examples relevant to the organization's own vendor relationships
  • Breach notification timelines and the risk-assessment process used to determine whether an incident is a reportable breach
  • How the four-tier penalty structure maps to culpability, so staff understand why "we didn't know" is not a complete defense
  • Each of the three Security Rule safeguard categories, with role-specific detail — IT staff need the technical safeguards in depth, facilities staff need the physical safeguards, and managers need the administrative safeguards
  • What "addressable" actually means in practice, and how the organization documents its addressable-specification decisions
  • Status of the proposed 2025 Security Rule update, so security and compliance teams aren't caught flat-footed if and when it finalizes

This kind of training works best as a distinct module rather than folded into general privacy awareness — it's aimed at a different audience with different day-to-day responsibilities. Pairing it with the organization's wider approach to building a culture of compliance in healthcare, and delivering it through trackable CPD courses, gives compliance officers a documented record that IT, security, and privacy staff received training specific to their roles — not just a generic HIPAA refresher.

FAQ

Is this the same as general HIPAA training?

No. General HIPAA training typically covers the Privacy Rule — patient rights, permitted disclosures, minimum necessary use. This training is specific to the HITECH Act's enforcement changes and the HIPAA Security Rule's technical requirements for protecting electronic PHI, which is a distinct body of obligations aimed largely at IT, security, and compliance staff.

Do business associates need this training too?

Yes, arguably more urgently. Since HITECH made business associates directly liable for HIPAA compliance, vendors handling ePHI on a covered entity's behalf need their own Security Rule training program, not just a signed business associate agreement.

What counts as "unsecured" PHI for breach notification purposes?

PHI is considered secured, and generally exempt from breach notification obligations, only if it has been rendered unusable, unreadable, or indecipherable through an approved method such as encryption meeting HHS-specified standards. Unencrypted ePHI on a lost laptop or stolen device is a textbook reportable breach scenario.

Has the 2025 proposed Security Rule update taken effect?

Not as of this writing. It remains a proposed rule, with finalization pushed out to 2027 on the federal government's regulatory agenda. Organizations should monitor it but should not treat its provisions as current legal requirements yet.

HITECH and the Security Rule together form the enforcement backbone behind every ePHI breach headline. Training that treats them as distinct from general privacy training — with their own timelines, tiers, and technical safeguards — gives compliance and IT teams the specific knowledge they need when an incident actually happens.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View Pricing