CompyMax

HIPAA glossary

The terms that come up constantly, defined in language an office manager can use, each with the citation so you can check it rather than take our word for it.

Last reviewed against the current regulation text.

Protected health information

Also called: PHI

Individually identifiable health information held or transmitted by a covered entity or business associate, in any form.

The identifiable part matters more than the clinical part. A list of names that reveals those people are patients of a particular practice is protected health information even with no diagnosis attached, which is why a customer list in an accounting package or a segment in a marketing tool can be a problem.

Source: 45 CFR 160.103

See also: Covered entity, Business associate, De-identification

Covered entity

A health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with certain transactions.

Most clinics, dental practices and behavioural health providers are covered entities. If you are handling health information on behalf of one of them rather than being one yourself, you are probably a business associate instead, and different obligations follow.

Source: 45 CFR 160.103

See also: Business associate, Protected health information

Business associate

A person or organization that creates, receives, maintains or transmits protected health information on behalf of a covered entity.

Billing and coding companies, healthcare software vendors, IT providers with access to systems holding patient data, transcription services and answering services are typically business associates. The threshold is lower than people expect: persistent administrative access to a system containing patient information generally counts, even if you never deliberately look at it.

Source: 45 CFR 160.103

See also: Business associate agreement, Subcontractor, Covered entity

Business associate agreement

Also called: BAA

A written contract between a covered entity and a business associate, required before the business associate may handle protected health information on its behalf.

The agreement commits the business associate to safeguard the information, to limit how it is used and disclosed, and to report breaches. Signing one is a prerequisite rather than a finish line — it allocates responsibility, it does not perform any of the work. The obligation also flows downhill to subcontractors.

Source: 45 CFR 164.502(e), 164.504(e)

See also: Business associate, Subcontractor

Subcontractor

A vendor that a business associate uses to help deliver its service, where that vendor also handles protected health information.

A billing company's clearinghouse, cloud storage provider and offshore coding partner are all subcontractors. Each needs its own agreement with the business associate, which is the link most commonly missing when a hospital client audits a vendor's supply chain.

Source: 45 CFR 160.103, 164.502(e)(1)(ii)

See also: Business associate, Business associate agreement

HIPAA Security Rule

The set of standards governing how electronic protected health information must be safeguarded, organized into administrative, physical and technical safeguards.

The Security Rule is where the risk analysis requirement lives, and it is deliberately flexible: what is reasonable and appropriate for a fourteen-person billing company is not what is expected of a hospital system. That flexibility is why documenting your reasoning matters as much as the controls themselves.

Source: 45 CFR Part 164, Subpart C

See also: Risk analysis, Administrative safeguards, Technical safeguards

HIPAA Privacy Rule

The standards governing how protected health information may be used and disclosed, and the rights individuals have over their own records.

Where the Security Rule is about protecting the data, the Privacy Rule is about what you are permitted to do with it — including the minimum necessary standard, patients' right of access, and the restrictions on using health information for marketing.

Source: 45 CFR Part 164, Subpart E

See also: Minimum necessary, Protected health information

Breach Notification Rule

The requirements for notifying affected individuals, the Secretary of HHS and in some cases the media after a breach of unsecured protected health information.

An impermissible use or disclosure is presumed to be a reportable breach unless a risk assessment shows a low probability that the information was compromised. Notification timing and recipients depend on how many individuals were affected, which is why the count matters so much during an incident.

Source: 45 CFR 164.400–414

See also: Four-factor risk assessment, Willful neglect

Risk analysis

Also called: Security risk assessment, SRA

A required, documented assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information you hold.

This is the single most commonly cited failure in enforcement actions, usually because an organization either never did one or did one once and never revisited it. The rule does not mandate any particular tool or format — HHS publishes a free one — but it does expect the analysis to be accurate, thorough and current.

Source: 45 CFR 164.308(a)(1)(ii)(A)

See also: HIPAA Security Rule, Administrative safeguards

Four-factor risk assessment

The four-part analysis used to decide whether an impermissible use or disclosure is a reportable breach.

The factors are the nature and extent of the information involved, who used it or received it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Documenting how you reached your conclusion is the part investigators ask to see, whichever way the conclusion went.

Source: 45 CFR 164.402

See also: Breach Notification Rule

Minimum necessary

The requirement to limit uses, disclosures and requests of protected health information to the least needed to accomplish the purpose.

In practice this is mostly an access-control question. If your systems only offer all-or-nothing access per user, front desk staff will see clinical notes because they need to see appointments, and no policy document fixes that.

Source: 45 CFR 164.502(b), 164.514(d)

See also: HIPAA Privacy Rule, Technical safeguards

Administrative safeguards

The policies, procedures and workforce measures required by the Security Rule — including risk analysis, workforce training, access management and incident procedures.

This is the largest of the three safeguard groups and the one small organizations neglect most, because it is paperwork and process rather than technology. It is also the group an investigator can assess fastest, since it is entirely documentary.

Source: 45 CFR 164.308

See also: HIPAA Security Rule, Risk analysis

Physical safeguards

Controls over physical access to facilities, workstations and devices holding electronic protected health information.

Facility access, workstation placement and positioning, and how devices and media are handled, reused and disposed of. Small practices tend to do the building well and the disposal badly.

Source: 45 CFR 164.310

See also: HIPAA Security Rule

Technical safeguards

The technology controls required by the Security Rule — access control, audit controls, integrity, authentication and transmission security.

This is where unique user identification, automatic logoff, audit logging and encryption sit. Several of these are addressable rather than required, which does not mean optional: it means you implement it, or document why it is not reasonable and appropriate and what you did instead.

Source: 45 CFR 164.312

See also: HIPAA Security Rule, Minimum necessary

Addressable vs required

Security Rule implementation specifications are labelled either required, which must be implemented, or addressable, which must be implemented if reasonable and appropriate — or documented and substituted if not.

Addressable is the most misread word in the Security Rule. It is not a synonym for optional. Skipping an addressable specification without a documented assessment and an alternative is a gap, not a choice.

Source: 45 CFR 164.306(d)

See also: Technical safeguards, HIPAA Security Rule

Willful neglect

Conscious, intentional failure or reckless indifference to a HIPAA obligation — the culpability tier attracting the most severe penalties.

The practical distinction is documentation. An organization that assessed a risk, recorded its reasoning and got it wrong is in a very different position from one that never looked, which is why a maintained risk analysis is worth more than its contents alone suggest.

Source: 45 CFR 160.401, 160.404

See also: Risk analysis

De-identification

Removing identifiers so that information is no longer individually identifiable, and therefore no longer protected health information.

There are two recognised methods: Safe Harbor, which removes a specified list of identifiers, and Expert Determination, in which a qualified person concludes the re-identification risk is very small. Deleting names alone satisfies neither.

Source: 45 CFR 164.514(a)–(b)

See also: Protected health information

Office for Civil Rights

Also called: OCR

The office within the US Department of Health and Human Services that enforces the HIPAA Privacy, Security and Breach Notification Rules.

Most organizations encounter OCR through a data request letter following a complaint or a reported breach rather than through a formal audit. The overwhelming majority of investigations close with corrective action rather than a financial penalty.

Source: hhs.gov/ocr

See also: Breach Notification Rule, Willful neglect

Check whether a specific tool can be used with patient information →

Plain-language summaries for orientation, with the citation for each so you can read the source. They are not a substitute for the regulation text and are not legal advice. Where a definition matters to a decision you are making, read the cited section or ask counsel.