HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a US law that sets standards for protecting sensitive patient health information held by covered entities and their business associates.
HIPAA establishes national standards for safeguarding protected health information (PHI). Its Privacy Rule governs how PHI may be used and disclosed, while its Security Rule sets administrative, physical, and technical safeguards for electronic PHI.
Covered entities — health plans, clearinghouses, and most healthcare providers — and the business associates that handle PHI on their behalf must implement these safeguards. Business associate agreements contractually extend HIPAA obligations down the supply chain.
The Breach Notification Rule requires notifying affected individuals, and in some cases regulators and the media, when unsecured PHI is breached. Demonstrating HIPAA compliance relies on documented policies, risk analyses, and evidence that safeguards operate continuously.
Related terms
- GDPRThe General Data Protection Regulation (GDPR) is the European Union law governing the processing of personal data, granting individuals rights over their data and imposing accountability obligations on organizations.
- Vendor Risk ManagementVendor risk management (VRM) is the process of identifying, assessing, and monitoring the security and compliance risks introduced by third-party suppliers and service providers.
- Evidence CollectionEvidence collection is the process of gathering proof that compliance controls are designed and operating effectively, for use in audits and attestations.
- Risk RegisterA risk register is a centralized record of an organization's identified risks, capturing their likelihood, impact, ownership, and treatment status.