• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » HITECH Outsourcing

HITECH Outsourcing

Definition

HITECH Outsourcing

HITECH outsourcing concerns how the 2009 US health technology act changed the outsourced handling of health data. It made business associates directly liable under the security rule, so a provider’s duties stopped being merely contractual and became statutory ones.

Before HITECH, a provider’s obligations came from its contract.

Break the security rule and you had breached an agreement with your client. The regulator’s enforcement powers reached the covered entity — and the provider answered to that entity rather than to the government.

HITECH changed the addressee. The same rules now apply to the business associate directly, which means a provider can be enforced against in its own right.

Key takeaways

  • HITECH was enacted in February 2009 as part of Public Law 111-5.
  • Core security rule sections apply to business associates as they do to covered entities.
  • A business associate must notify the covered entity of a breach within 60 calendar days.
  • The change converted contractual duties into direct statutory liability for providers.

How it works

The operative provision is short. It states that sections 164.308, 164.310, 164.312, and 164.316 of title 45, Code of Federal Regulations, shall apply to a business associate of a covered entity in the same manner that such sections apply to the covered entity.

Those four sections are the administrative, physical and technical safeguards plus the documentation requirements. They are the working core of the security rule.

The act was enacted on 17 February 2009 as part of Public Law 111-5. It sits on top of the Health Insurance Portability and Accountability Act of 1996, whose national standards it extends rather than replaces.

Breach notification is the second change buyers feel. A business associate must notify the covered entity following discovery of a breach of unsecured protected health information, and in no case later than 60 calendar days after discovery.

Sixty days is the outer limit, not a target. The notification must identify each individual whose information was accessed, acquired, used or disclosed — which requires the provider to have logging good enough to establish that.

What changedBefore HITECHAfter HITECH
Source of provider dutyThe contractThe statute directly
Who enforces against providerThe covered entityThe regulator too
Safeguard sectionsApplied via agreementApply directly
Breach notificationContractual termRegulatory deadline
Subcontractor positionAmbiguousBrought inside the regime

The last row matters offshore — a subcontractor handling records is inside the regime whether or not anyone remembered to paper the relationship.

Examples

The practical effect of direct liability shows up in how providers behave rather than in what contracts say. Each case below was settled by reading the document rather than trusting the badge.

A BPO provider handling claims data now carries its own exposure. That reshapes how healthcare information management outsourcing contracts allocate indemnities.

An offshore team discovers a misconfigured share on day one of an investigation. The 60-day clock started at discovery, not at the point the client was eventually told.

A provider cannot say which records were exposed because its logging was thin. The notification duty requires identifying affected individuals, so poor logging becomes a compliance failure.

A covered entity’s healthcare compliance officer begins auditing its providers rather than trusting attestations, which is the sensible response to shared liability.

Related terms

Health data regulation layers one act on another, and the roles around it are distinct from both. Every term below gets one sense, and the overlapping sense is named somewhere else.

FAQ

What did HITECH change for outsourcing providers?

It applied core security rule sections to business associates directly, so their obligations became statutory rather than purely contractual.

When was HITECH enacted?

On 17 February 2009, as part of Public Law 111-5. It extends the 1996 health privacy law rather than replacing it.

What is the breach notification deadline?

A business associate must notify the covered entity without unreasonable delay and in no case later than 60 calendar days after discovering a breach.

Does the clock start at discovery or at confirmation?

At discovery. Investigating what happened does not pause the deadline, which is why detection and logging quality matter.

Are subcontractors covered?

Yes. Subcontractors handling protected health information sit inside the regime and must be bound to the same restrictions.

Does HITECH apply to offshore providers?

Yes, where they act as business associates. The obligations attach to the role, not to the country the work is performed in.

Review verified partners in the Outsource Accelerator directory and confirm who notifies whom, and inside what deadline.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image