Access
Right of Access
An individual's right to inspect and obtain a copy of their PHI maintained by a covered entity in a designated record set.
Look up common HIPAA acronyms and legal terminology. Search by term, full name, or keyword to find clear, plain-English definitions.
Showing 48 terms
Right of Access
An individual's right to inspect and obtain a copy of their PHI maintained by a covered entity in a designated record set.
Access Control
Technical safeguards that limit access to ePHI to only those persons or software programs granted access rights.
Accounting of Disclosures
An individual's right to receive a list of certain disclosures of their PHI made by a covered entity.
Administrative Safeguards
Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures.
Anti-Kickback Statute
A federal law prohibiting the exchange of anything of value to induce referrals for services payable by federal healthcare programs.
Audit Controls
Hardware, software, and procedural mechanisms that record and examine activity in systems containing or using ePHI.
Business Associate
A person or entity that performs functions or activities on behalf of, or provides services to, a covered entity that involve access to PHI.
Business Associate Agreement
A written contract between a covered entity and a business associate that establishes how the business associate may use and safeguard PHI.
Breach of Unsecured PHI
An impermissible use or disclosure of unsecured PHI that compromises its security or privacy, presumptively a breach unless a risk assessment shows low probability of compromise.
Breach Notification Rule
The HIPAA rule requiring covered entities to notify affected individuals, HHS, and in some cases the media following a breach of unsecured PHI.
Covered Entity
A health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically in connection with a covered transaction.
Civil Monetary Penalties
Financial penalties imposed for violations of HIPAA and other healthcare laws, assessed per violation with annual caps based on tiered culpability.
Centers for Medicare & Medicaid Services
The federal agency within HHS that administers the Medicare and Medicaid programs.
De-identified Health Information
Health information that does not identify an individual and for which there is no reasonable basis to believe it can be used to identify an individual.
Designated Record Set
A group of records maintained by or for a covered entity that contains medical and billing records and other records used to make decisions about an individual.
U.S. Department of Justice
The federal department that prosecutes healthcare fraud and enforces certain HIPAA-related laws alongside HHS.
Electronic Health Record
An electronic version of a patient's medical history maintained over time by a provider, often containing PHI subject to HIPAA.
Electronic Medical Record
A digital version of a patient's chart within a single practice, containing PHI subject to HIPAA.
Encryption
The process of converting data into a form that cannot be easily understood by unauthorized persons, an addressable safeguard under the Security Rule.
Electronic Protected Health Information
Protected health information that is created, received, maintained, or transmitted in electronic form. Governed by the HIPAA Security Rule.
Expert Determination Method
A de-identification method where a qualified statistical expert determines that the risk of re-identification is very small.
False Claims Act
A federal law imposing liability on those who knowingly submit false claims for government funds, a key HCFAC enforcement tool.
Group Health Plan
An employee welfare benefit plan providing medical care to employees or their dependents, treated as a covered entity under HIPAA.
Health Care Fraud and Abuse Control Program
A program established by HIPAA to coordinate federal efforts to investigate and prosecute healthcare fraud and abuse.
U.S. Department of Health and Human Services
The federal department responsible for administering HIPAA and protecting the health and well-being of Americans.
Health Information Exchange
The electronic sharing of healthcare-related data among organizations according to recognized standards.
Health Insurance Portability and Accountability Act
Federal law enacted in 1996 that sets national standards for the protection of individually identifiable health information and simplifies healthcare administration.
Hybrid Entity
A covered entity whose business activities include both covered and non-covered functions, which may designate certain components as healthcare components subject to HIPAA.
Integrity Control
A security standard ensuring ePHI is not altered or destroyed in an unauthorized manner.
List of Excluded Individuals/Entities
An HHS-OIG database of individuals and entities excluded from participation in federal healthcare programs.
Minimum Necessary Standard
A Privacy Rule requirement that limits uses, disclosures, and requests for PHI to the minimum amount needed to accomplish the intended purpose.
Notice of Privacy Practices (NPP)
A document describing how a covered entity may use and disclose PHI and an individual's rights regarding their information.
Office for Civil Rights
The HHS office responsible for administering and enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
Office of Inspector General
The HHS office that combats fraud, waste, and abuse in federal healthcare programs and jointly administers the HCFAC Program with the DOJ.
Organized Health Care Arrangement (OHCA)
A relationship in which participating entities hold PHI for joint use and may share it for care, payment, or operations.
Protected Health Information
Individually identifiable health information held or transmitted by a covered entity or business associate, in any form (electronic, paper, oral), that relates to health, care, or payment.
Physical Safeguards
Physical measures, policies, and procedures to protect electronic systems, equipment, and related buildings from natural and environmental hazards.
Risk Management Plan
The process of implementing measures to reduce security risks and vulnerabilities identified during the risk analysis to a reasonable and appropriate level.
Safe Harbor Method
A de-identification method under HIPAA that requires the removal of 18 specified identifiers to render data de-identified.
Sanction
An administrative penalty imposed by HHS for HIPAA violations, ranging from corrective action plans to civil monetary penalties.
Security Risk Analysis
An accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
Physician Self-Referral Law
A federal law prohibiting a physician from referring patients to an entity with which the physician has a financial relationship for designated health services.
Subcontractor
A person or entity to whom a business associate delegates a function or service that involves access to PHI; treated as a business associate under HIPAA.
Technical Safeguards
Technology and related policies and procedures that protect ePHI and control access to it.
Treatment, Payment, and Healthcare Operations
The three core activities for which covered entities may use and disclose PHI without individual authorization under the Privacy Rule.
Transmission Security
Technical safeguards that guard against unauthorized access to ePHI being transmitted over an electronic communications network, often via encryption.
Unsecured Protected Health Information
PHI that has not been rendered unusable through encryption or destruction, and is therefore subject to the Breach Notification Rule.
Workforce
Employees, volunteers, trainees, and other persons under the direct control of a covered entity or business associate, whether or not paid.