Guide

HIPAA Glossary

Plain-language definitions of 45+ HIPAA terms — PHI, ePHI, BAA, minimum necessary, safe harbor, designated record set, and the rest.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Every HIPAA conversation runs on a shared vocabulary, and misusing it is how programmes drift. Here are the terms that matter, defined the way practitioners actually use them.

The law and its rules

HIPAA — The Health Insurance Portability and Accountability Act of 1996. The privacy and security obligations everyone means by “HIPAA” live in its implementing regulations at 45 CFR Parts 160 and 164.

HITECH Act — The 2009 law that strengthened HIPAA: it created the breach notification requirement, extended direct liability to business associates, established the four-tier penalty structure, and authorised state attorney general enforcement.

Privacy Rule — The regulation governing how PHI in any form may be used and disclosed, and the rights individuals hold over their information. See the Privacy Rule guide.

Security Rule — The regulation requiring administrative, physical, and technical safeguards for ePHI. See the Security Rule guide.

Breach Notification Rule — The regulation requiring notification of individuals, HHS, and sometimes the media following a breach of unsecured PHI.

Omnibus Rule — The 2013 final rule implementing HITECH: direct business associate liability, the revised breach standard, and updated authorisation requirements.

Enforcement Rule — The regulation setting out investigation procedures and the civil money penalty structure, including the culpability tiers.

Preemption — The principle that HIPAA overrides contrary state law — but not state laws that are more protective of privacy, which is why state regimes like the CMIA and SHIELD Act apply on top of HIPAA.

Data and information types

PHI (protected health information) — Individually identifiable health information held or transmitted by a covered entity or business associate, in any form: electronic, paper, or oral.

ePHI — PHI in electronic form. The subset the Security Rule protects.

IIHI (individually identifiable health information) — Health information that identifies an individual or could reasonably be used to. PHI is IIHI held by regulated entities; the same data in your fitness app’s hands may be neither.

De-identification — Removing identifiers so information is no longer PHI and falls outside HIPAA. Two accepted methods: Expert Determination and Safe Harbor.

Safe Harbor (de-identification) — The de-identification method that removes 18 specified categories of identifiers — names, dates more specific than year, geographic units smaller than a state (with limited zip-code allowances), contact details, identifying numbers, biometrics, photographs, and the rest — with no actual knowledge the remainder could identify the individual.

Expert Determination — The alternative de-identification method: a qualified statistician determines the re-identification risk is very small and documents the analysis.

Limited data set — PHI stripped of most direct identifiers but retaining elements like dates and geographic detail, usable for research, public health, or operations under a data use agreement.

Data use agreement — The required contract governing a recipient’s use of a limited data set.

Designated record set — The group of records a covered entity uses to make decisions about individuals — medical and billing records, claims and case management files. It defines the scope of the patient’s rights of access and amendment.

Psychotherapy notes — A therapist’s process notes kept separate from the medical record. They receive extra protection: most disclosures require specific authorisation, and they sit outside the patient’s ordinary access right.

Entities and roles

Covered entity — A healthcare provider that transmits standard electronic transactions, a health plan, or a healthcare clearinghouse. (Some states — notably Texas — define the term far more broadly for state-law purposes.)

Business associate — A person or organisation that creates, receives, maintains, or transmits PHI on behalf of a covered entity — cloud hosts, billing firms, analytics vendors, shredding companies. Directly liable under HIPAA since the Omnibus Rule.

Subcontractor — A business associate’s business associate. Obligations flow downstream: each link in the chain needs its own agreement.

BAA (business associate agreement) — The mandatory contract establishing what a business associate may do with PHI, the safeguards required, and breach reporting duties. See the BAA guide.

Hybrid entity — An organisation with both covered and non-covered functions — a university with a clinic, for instance — that formally designates its healthcare components to contain HIPAA’s application.

OHCA (organised health care arrangement) — A recognised arrangement letting participating entities — such as a hospital and its medical staff — share PHI for joint operations under a joint notice.

Privacy Officer / Security Officer — The individuals a regulated entity must designate, in writing, as responsible for privacy compliance and for the security programme respectively. One person may hold both roles in a small organisation.

Workforce — Employees, volunteers, trainees, and others under the entity’s direct control — the population that must be trained and sanctioned, whether or not paid.

OCR (Office for Civil Rights) — The HHS office that administers and enforces the HIPAA rules through investigations, audits, penalties, and resolution agreements.

HHS — The US Department of Health and Human Services, HIPAA’s parent agency. HHS runs no certification programme — no organisation can be “HIPAA certified,” only compliant and able to prove it.

Privacy Rule concepts

TPO (treatment, payment, and healthcare operations) — The three purposes for which PHI may be used and disclosed without patient authorisation. The workhorse permission underlying routine healthcare.

Minimum necessary — The standard requiring uses, disclosures, and requests to be limited to the least PHI needed for the purpose. It does not apply to disclosures for treatment or to the individual.

Authorisation — The signed, specific permission required for uses and disclosures beyond what the Privacy Rule permits — marketing, most research, sale of PHI. Validity requirements are prescriptive; defective forms are void.

NPP (Notice of Privacy Practices) — The document telling individuals how their PHI may be used and what rights they hold. Must be provided, posted, and — for providers — acknowledged in writing where possible.

Right of access — The individual’s right to inspect and obtain a copy of their PHI in the designated record set, generally within 30 days and at limited cost. The subject of a sustained OCR enforcement initiative.

Amendment — The individual’s right to request correction of their records, with a process for acceptance or documented denial.

Accounting of disclosures — The individual’s right to a list of certain disclosures of their PHI made in the prior six years, excluding TPO and several other categories.

Incidental disclosure — A secondary disclosure that occurs despite reasonable safeguards — an overheard name at a pharmacy counter. Permitted, provided minimum necessary and reasonable safeguards were in place.

Sale of PHI — Receiving remuneration in exchange for PHI, prohibited without specific authorisation subject to narrow exceptions.

Security Rule concepts

Administrative safeguards — The management layer: risk analysis, workforce security, training, incident procedures, contingency planning, evaluation. Detailed in the administrative safeguards guide.

Physical safeguards — Facility access controls, workstation security, and device and media controls, including disposal.

Technical safeguards — Access control, audit controls, integrity, authentication, and transmission security for ePHI.

Required vs addressable — Every Security Rule implementation specification is one or the other. Required means implement it. Addressable means implement it, implement a documented equivalent, or document why neither is reasonable and appropriate. Addressable never means optional.

Risk analysis — The accurate, thorough assessment of risks to all ePHI the organisation holds — the foundational Security Rule requirement and the most commonly cited gap in enforcement. See the risk analysis guide.

Risk management — The follow-through: implementing measures that reduce identified risks to a reasonable and appropriate level, with owners and dates.

Audit controls — Mechanisms that record and allow examination of activity in systems containing ePHI — plus, in practice, somebody actually reviewing the output.

Encryption — Rendering data unreadable without a key. Addressable at rest and in transit under the Security Rule, but the safe harbor makes it the single highest-leverage control.

Safe harbor (encryption) — The breach-notification exemption: if compromised ePHI was encrypted consistent with HHS guidance and the keys were not compromised, the data is not “unsecured PHI” and notification is generally not triggered.

Contingency plan — The required trio of data backup plan, disaster recovery plan, and emergency mode operation plan — tested, not just written.

Sanction policy — The required written policy for disciplining workforce members who violate privacy and security policies, applied and recorded when applied.

Breach and enforcement concepts

Security incident — Attempted or successful unauthorised access, use, disclosure, modification, or destruction of information or interference with operations. Broader than a breach; all incidents get logged, few become breaches.

Breach — An impermissible acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy — presumed reportable unless a risk assessment demonstrates a low probability of compromise.

Four-factor risk assessment — The analysis used to rebut the breach presumption: the nature and extent of the PHI, the unauthorised person involved, whether the PHI was actually acquired or viewed, and the extent of mitigation.

Unsecured PHI — PHI not rendered unusable, unreadable, or indecipherable through encryption or destruction per HHS guidance. Only breaches of unsecured PHI trigger notification.

Corrective action plan — The multi-year, OCR-monitored remediation programme attached to most resolution agreements — frequently more expensive in practice than the settlement payment itself.

Resolution agreement — The settlement instrument closing an OCR enforcement action, typically pairing a payment with a corrective action plan.

Civil money penalty (CMP) — The formal penalty OCR imposes when a case does not settle, calculated under the four culpability tiers. For how the tiers work and what enforcement actually looks like, see the violations and penalties guide.

Willful neglect — Conscious, intentional failure or reckless indifference to HIPAA obligations — the culpability standard that separates the top two penalty tiers from the bottom two, and the reason documentation is a penalty defence.

Questions

What is the difference between PHI and ePHI?

PHI is protected health information in any form — paper, spoken, electronic. ePHI is the electronic subset. The Privacy Rule governs PHI in all forms; the Security Rule applies specifically to ePHI.

What does BAA stand for?

Business associate agreement — the required contract between a covered entity (or business associate) and any vendor that creates, receives, maintains, or transmits PHI on its behalf. Operating without one is itself a violation.

What does 'addressable' mean in the Security Rule?

Not optional. An addressable implementation specification must be implemented, met with a documented equivalent alternative, or formally documented as not reasonable and appropriate for your environment. The one thing you cannot do is silently skip it.

Is there such a thing as HIPAA certification?

No. HHS operates no certification programme and no private body can confer one. Organisations demonstrate compliance through documentation and, where useful, an independent third-party assessment.

What is safe harbor encryption?

If breached ePHI was encrypted to standards consistent with HHS guidance and the keys were not compromised, the data is considered unusable and the incident generally falls outside the breach notification obligation. It is the strongest single technical argument for encrypting everything.

What does TPO mean?

Treatment, payment, and healthcare operations — the three purposes for which the Privacy Rule permits use and disclosure of PHI without patient authorisation. Most uses beyond TPO require a signed authorisation.

Who enforces HIPAA?

The Office for Civil Rights (OCR) within HHS handles civil enforcement, the Department of Justice handles criminal cases, and state attorneys general can bring civil actions under authority granted by the HITECH Act.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo