The first question you have to ask is "Does HITECH (and by extension HIPAA) affect my company?" Do you store files with protected information in them? Do you move files with protected information in them? If the answer to either of those questions is YES, then you must examine the security of your organization. Make sure physical and digital access to files/data is logged and is audit-able. Make sure the files/data reside on physically and digitally secured storage (on an encrypted drive with proper ACL's on a server in a locked rack, where physical access to server is logged and audit-able). If the data is in a database, are you using column encryption on personally identifiable data (think last name, address, dob, ssn, etc.)? If you're moving the files/data, make sure that you use an encrypted/secure connection to move them, i.e. HTTPS, SFTP, FTPS, etc., and that all moves are logged and audit able.
Meet the above basics first, then worry about digging in to more detail of the actual legislation.