Back to HomeReference

HIPAA Glossary

Look up common HIPAA acronyms and legal terminology. Search by term, full name, or keyword to find clear, plain-English definitions.

Showing 48 terms

A

Access

Right of Access

Privacy

An individual's right to inspect and obtain a copy of their PHI maintained by a covered entity in a designated record set.

Access Control

Access Control

Security

Technical safeguards that limit access to ePHI to only those persons or software programs granted access rights.

Accounting of Disclosures

Accounting of Disclosures

Privacy

An individual's right to receive a list of certain disclosures of their PHI made by a covered entity.

Administrative Safeguards

Administrative Safeguards

Security

Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures.

AKS

Anti-Kickback Statute

Statute

A federal law prohibiting the exchange of anything of value to induce referrals for services payable by federal healthcare programs.

Audit Controls

Audit Controls

Security

Hardware, software, and procedural mechanisms that record and examine activity in systems containing or using ePHI.

B

BA

Business Associate

Privacy

A person or entity that performs functions or activities on behalf of, or provides services to, a covered entity that involve access to PHI.

BAA

Business Associate Agreement

Privacy

A written contract between a covered entity and a business associate that establishes how the business associate may use and safeguard PHI.

Breach

Breach of Unsecured PHI

Breach

An impermissible use or disclosure of unsecured PHI that compromises its security or privacy, presumptively a breach unless a risk assessment shows low probability of compromise.

Breach Notification Rule

Breach Notification Rule

Breach

The HIPAA rule requiring covered entities to notify affected individuals, HHS, and in some cases the media following a breach of unsecured PHI.

C

CE

Covered Entity

Privacy

A health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically in connection with a covered transaction.

CMP

Civil Monetary Penalties

Enforcement

Financial penalties imposed for violations of HIPAA and other healthcare laws, assessed per violation with annual caps based on tiered culpability.

CMS

Centers for Medicare & Medicaid Services

Agency

The federal agency within HHS that administers the Medicare and Medicaid programs.

D

De-identification

De-identified Health Information

Privacy

Health information that does not identify an individual and for which there is no reasonable basis to believe it can be used to identify an individual.

Designated Record Set

Designated Record Set

Privacy

A group of records maintained by or for a covered entity that contains medical and billing records and other records used to make decisions about an individual.

DOJ

U.S. Department of Justice

Agency

The federal department that prosecutes healthcare fraud and enforces certain HIPAA-related laws alongside HHS.

E

EHR

Electronic Health Record

Operations

An electronic version of a patient's medical history maintained over time by a provider, often containing PHI subject to HIPAA.

EMR

Electronic Medical Record

Operations

A digital version of a patient's chart within a single practice, containing PHI subject to HIPAA.

Encryption

Encryption

Security

The process of converting data into a form that cannot be easily understood by unauthorized persons, an addressable safeguard under the Security Rule.

ePHI

Electronic Protected Health Information

Security

Protected health information that is created, received, maintained, or transmitted in electronic form. Governed by the HIPAA Security Rule.

Expert Determination

Expert Determination Method

Privacy

A de-identification method where a qualified statistical expert determines that the risk of re-identification is very small.

F

FCA

False Claims Act

Statute

A federal law imposing liability on those who knowingly submit false claims for government funds, a key HCFAC enforcement tool.

G

Group Health Plan

Group Health Plan

Operations

An employee welfare benefit plan providing medical care to employees or their dependents, treated as a covered entity under HIPAA.

H

HCFAC

Health Care Fraud and Abuse Control Program

Statute

A program established by HIPAA to coordinate federal efforts to investigate and prosecute healthcare fraud and abuse.

HHS

U.S. Department of Health and Human Services

Agency

The federal department responsible for administering HIPAA and protecting the health and well-being of Americans.

HIE

Health Information Exchange

Operations

The electronic sharing of healthcare-related data among organizations according to recognized standards.

HIPAA

Health Insurance Portability and Accountability Act

Statute

Federal law enacted in 1996 that sets national standards for the protection of individually identifiable health information and simplifies healthcare administration.

Hybrid Entity

Hybrid Entity

Operations

A covered entity whose business activities include both covered and non-covered functions, which may designate certain components as healthcare components subject to HIPAA.

I

Integrity

Integrity Control

Security

A security standard ensuring ePHI is not altered or destroyed in an unauthorized manner.

L

LEIE

List of Excluded Individuals/Entities

Enforcement

An HHS-OIG database of individuals and entities excluded from participation in federal healthcare programs.

M

Minimum Necessary

Minimum Necessary Standard

Privacy

A Privacy Rule requirement that limits uses, disclosures, and requests for PHI to the minimum amount needed to accomplish the intended purpose.

N

Notice of Privacy Practices

Notice of Privacy Practices (NPP)

Privacy

A document describing how a covered entity may use and disclose PHI and an individual's rights regarding their information.

O

OCR

Office for Civil Rights

Agency

The HHS office responsible for administering and enforcing the HIPAA Privacy, Security, and Breach Notification Rules.

OIG

Office of Inspector General

Agency

The HHS office that combats fraud, waste, and abuse in federal healthcare programs and jointly administers the HCFAC Program with the DOJ.

Organized Health Care Arrangement

Organized Health Care Arrangement (OHCA)

Privacy

A relationship in which participating entities hold PHI for joint use and may share it for care, payment, or operations.

P

PHI

Protected Health Information

Privacy

Individually identifiable health information held or transmitted by a covered entity or business associate, in any form (electronic, paper, oral), that relates to health, care, or payment.

Physical Safeguards

Physical Safeguards

Security

Physical measures, policies, and procedures to protect electronic systems, equipment, and related buildings from natural and environmental hazards.

R

Risk Management

Risk Management Plan

Security

The process of implementing measures to reduce security risks and vulnerabilities identified during the risk analysis to a reasonable and appropriate level.

S

Safe Harbor

Safe Harbor Method

Privacy

A de-identification method under HIPAA that requires the removal of 18 specified identifiers to render data de-identified.

Sanction

Sanction

Enforcement

An administrative penalty imposed by HHS for HIPAA violations, ranging from corrective action plans to civil monetary penalties.

SRA

Security Risk Analysis

Security

An accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

Stark Law

Physician Self-Referral Law

Statute

A federal law prohibiting a physician from referring patients to an entity with which the physician has a financial relationship for designated health services.

Subcontractor

Subcontractor

Privacy

A person or entity to whom a business associate delegates a function or service that involves access to PHI; treated as a business associate under HIPAA.

T

Technical Safeguards

Technical Safeguards

Security

Technology and related policies and procedures that protect ePHI and control access to it.

TPO

Treatment, Payment, and Healthcare Operations

Privacy

The three core activities for which covered entities may use and disclose PHI without individual authorization under the Privacy Rule.

Transmission Security

Transmission Security

Security

Technical safeguards that guard against unauthorized access to ePHI being transmitted over an electronic communications network, often via encryption.

U

Unsecured PHI

Unsecured Protected Health Information

Breach

PHI that has not been rendered unusable through encryption or destruction, and is therefore subject to the Breach Notification Rule.

W

Workforce

Workforce

Operations

Employees, volunteers, trainees, and other persons under the direct control of a covered entity or business associate, whether or not paid.

Understand the Rules

Know what matters and your obligations.

Protect Health Data

Apply safeguards to keep ePHI secure.

Reduce Risk, Stay Compliant

Follow best practices and avoid penalties.

Build Trust, Improve Care

Better data security leads to better care.

HIPAA Made Simple logoSIMPLE HIPAA

Understand the rules. Protect people. Build trust. Clear, citation-backed HIPAA education for covered entities, business associates, and the workforce that keeps health data safe.

HIPAA Made Simple.

Disclaimer

This site provides general educational information about HIPAA and is not legal advice. Always consult qualified compliance counsel for your specific circumstances, and refer to the official HHS guidance and the Code of Federal Regulations.

Strong Security. Smart Compliance. Better Outcomes. | HIPAA Made Simple.

© 2026 Simple HIPAA. Educational use only.

    base44
    Edit with Base44