HIM 515 Topic 8 Regulations and Implementations
Two regulations that are usually named in one breath and do different work. Separating them is what lets you answer the hardware and infrastructure parts of this brief.
Editorial process
Last reviewed · August 25, 2026
HIPAA sets rules; HITECH changed who they reach
The two are named together so often that papers treat them as one regulation, and the specific requirements in this brief make that impossible to sustain. HIPAA established privacy and security rules for covered entities and their business associates. HITECH did three things HIPAA had not: it funded and incentivised adoption of electronic records, it extended direct liability to business associates rather than reaching them only through contract, and it created breach notification obligations with thresholds and timelines. The second of those is the answer to the vendor questions in the brief, because a software or hardware supplier handling protected health information moved from being a contractual counterparty to being directly regulated, which changes what they must build, what they must document and what they are liable for. Answering the vendor questions without that distinction is close to impossible. That single change answers two of the four required elements.
The state and federal point the brief asks for has a specific shape worth getting right: HIPAA is a floor, not a ceiling, so a state law that is more protective of privacy is not preempted and applies alongside it. That is why an organisation operating in several states cannot build one release-of-information process and use it everywhere, and it is a concrete answer to the question about organisational standards. Genetic information, mental health records, substance use treatment records and minors' consent are the areas where state variation bites hardest and where systems most often need per-state configuration. For infrastructure, keep the answer to what the security rule actually requires, namely a risk analysis and reasonable safeguards rather than a fixed technology list, since the rule is deliberately technology-neutral and papers that claim it mandates specific encryption overstate it. Overstating the rule is a common error and an easy one for a marker to catch.
Likely learning objectives
- Separate what HIPAA established from what HITECH changed.
- Explain direct business associate liability as the vendor-facing change.
- Apply the floor-not-ceiling preemption rule to multi-state operations.
- Describe the security rule as risk-based rather than prescriptive.
Assignment instructions
Read the full question
Review every instruction before using the planning guidance that follows.
Details: In a 750-1,000-word paper, explain how HIPAA and HITECH regulations impact the implementation of various health care systems. Consider impacts to and from federal, local, software vendors/users, hardware vendors/users, infrastructure, and organizational standards. Papers must address the following: Clearly define impact of HIPAA and HITECH regulations on health care systems for the future with mention to state and federal differences. Define how the regulations will modify the implementation and ongoing use of software systems that maintain patient data. Discuss the changes and impacts to software and hardware vendors. Clarify the changes and impacts to infrastructure and organizational standards. Prepare this assignment according to the guidelines found in the APA Style Guide, located in the Student Success Center. An abstract is not required. This assignment uses a rubric. Please review the rubric prior to beginning the assignment to become familiar with the expectations for successful completion. You are required to submit this assignment to Turnitin. Please refer to the directions in the Student Success Center.
What Topic 8 requires
- 01A 750-1,000 word paper in APA style with no abstract.
- 02A clear definition of the impact of HIPAA and HITECH on health care systems for the future, mentioning state and federal differences.
- 03How the regulations modify implementation and ongoing use of software systems maintaining patient data.
- 04The changes and impacts to software and hardware vendors.
- 05The changes and impacts to infrastructure and organisational standards.
- 06Submission to Turnitin.
Each regulation, then each affected party
What HIPAA established
Set out the privacy and security rules and who they cover.
What the assessor is likely looking for
Covered entities and business associates named correctly.
What HITECH changed
Cover adoption incentives, direct liability and breach notification.
What the assessor is likely looking for
Three distinct changes, not one.
Software systems
Explain the access control, audit and documentation requirements in practice.
What the assessor is likely looking for
Requirements traced to the rules.
Software and hardware vendors
Explain the move from contractual to direct regulation.
What the assessor is likely looking for
The vendor answer grounded in the statute.
State and federal differences
Apply preemption and give an area where state law is stricter.
What the assessor is likely looking for
A concrete multi-state consequence.
Infrastructure and organisational standards
Describe risk analysis and reasonable safeguards.
What the assessor is likely looking for
Risk-based framing rather than a technology list.
Where the regulatory text sits
Recommended databases
- HealthIT.gov
- NCBI Bookshelf
- CMS
- PubMed Central
Search sequence
- 1.Read the HIPAA compliance overview for the rules and covered parties.
- 2.Look up the HITECH changes specifically, rather than reading about HIPAA alone.
- 3.Find guidance on preemption and a state law that is more protective.
- 4.Check the security rule's risk analysis requirement before writing the infrastructure section.
Reference shortlist
These are authoritative starting points, not a ready-made bibliography. A qualified reviewer must confirm that each source fits the assignment and supports the claim beside which it is cited.
Health Insurance Portability and Accountability Act (HIPAA) Compliance
StatPearls, NCBI Bookshelf · 2023
HIPAA compliance, for the rules, covered entities and business associates.
Privacy, Security, and HIPAA
HealthIT.gov, Office of the National Coordinator · 2024
Privacy, security and HIPAA guidance, for the risk-based security framing.
Health IT Privacy and Security Resources for Providers
HealthIT.gov · 2024
Provider privacy and security resources, for organisational standards.
Promoting Interoperability Programs
Centers for Medicare & Medicaid Services · 2025
Interoperability programmes, for the adoption incentive strand HITECH began.
Joint Guidance on the Application of FERPA and HIPAA to Student Health Records
U.S. Department of Education and the Office for Civil Rights, U.S. Department of Health and Human Services · 2019
Joint FERPA and HIPAA guidance, as a worked example of overlapping legal regimes.
Before you submit
Common mistakes
- Treating HIPAA and HITECH as a single regulation.
- Missing direct business associate liability, which is the vendor answer.
- Assuming federal law preempts all state privacy law.
- Claiming the security rule mandates specific technologies.
- Answering the infrastructure question with generic cybersecurity advice.
Submission checklist
- Are HIPAA and HITECH distinguished by what each did?
- Is business associate liability addressed for vendors?
- Is the floor-not-ceiling rule stated and applied?
- Is the security rule described as risk-based?
- Are all four required elements covered?
Use this guide to plan and review your own work. Follow your institution's rules and read Brinevia's academic-integrity policy.
Written by
Maren Caldwell
MSN, RN, CNE
Medical-surgical nursing, pharmacology and NCLEX preparation
Maren is a registered nurse with over 15 years of clinical and educational experience in medical-surgical nursing. She writes on NCLEX preparation, patient care fundamentals, pharmacology and evidence-based practice.

Reviewed by
Dr. Tessa Redmond
DNP, RN, CNE
Evidence-based practice and clinical education
Tessa is a doctorally-prepared nurse educator. She reviews Brinevia content for clinical accuracy and alignment with current evidence-based guidelines.