Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
A
Availability
BAA
Business Associates
Covered Entities
Data Use Agreement
De-Identified Information
Designated Record Set
DHS
Direct Treatment Relationships
Disaster Recovery Plan
Electronic Media
Emergency Mode Operations Plan
EMO Plan
ePHI
External Entity
Facility Security Plan
Health Care Clearinghouse
Health Care Component
Health Care Provider
HHS
HIC
HIPAA Liaison
Hybrid Entity
Limited Data Set
OCR
PHI
Physical Safeguards
Privacy Official
Public Health Activities
Risk Assessment
Risk Management
Security Official
SRA Tool
Subcontractors
Unsecured Protected Health Information

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.

Availability
Availability means the healthcare facility should keep their hardware and software systems up and running properly. This requires covered entities and business associates to keep their infrastructure updated to protect it against security threats. Availability is a requirement for HIPAA technical and physical safeguards. Its goal is to allow authorized individuals to access necessary information…
Administrative Safeguards
Administrative Safeguards are actions, policies, and procedures to manage the development, implementation, and maintenance of security measures to protect PHI. It guides covered entities to be compliant with the HIPAA security rule. In order to comply with Administrative Safeguards, one must evaluate their existing security controls, accurately analyze risks to the systems, and evaluate documented…
Subcontractors
Subcontractors are individuals to whom business associates delegate a task or function or service that involves creation, transmission, or management of PHI. They work on behalf of a BA and are subject to comply with HIPAA privacy requirements.
Business Associates
Business Associates are individuals or entities who work for or provide a service for a covered entity. The work involves use and disclosure of Protected Health Information (PHI). They must comply with the privacy rule of HIPAA. Business Associates perform functions like claims processing, data analysis, quality assurance, practice management, repricing, and more.
Covered Entities
Covered Entities can be a health plan, health care clearinghouse, or health care provider. They electronically transmit health information as per HHS standards and include individuals and organizations. – Health plans are individuals or groups who provide medical care or cover its expenses. – Health care clearinghouses are private or public firms who process health…
PHI
Protected Health Information (PHI) refers to any data in a medical data record that can be used to identify an individual. This data was created, used, or disclosed during the course of offering health services to a patient. The Privacy Rule of HIPAA extensively covers the rights an individual has over this information. Covered entities…