Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » Covered Entities

Covered Entities

Covered Entities can be a health plan, health care clearinghouse, or health care provider. They electronically transmit health information as per HHS standards and include individuals and organizations. 

– Health plans are individuals or groups who provide medical care or cover its expenses.  

– Health care clearinghouses are private or public firms who process health information from a non standard format to a standard one. 

– Health care providers offer medical or health services. They can be individuals or organizations who furnish, bills, or is paid for care services.

Additional reading

ISO 27001 Acceptable Use Policy: Requirements, Template, and Best Practices

TL,DR: An ISO 27001 acceptable use policy sets rules for company devices, apps, networks, and data. It should cover user acknowledgments, asset use, monitoring, consequences, and regular review. The article ties AUP requirements to Annex A.8.1, onboarding, training, and HR workflows. Scaling a fast-growing tech company comes with invisible risks. As new people, devices, and…

GRC Incident Management: Framework, Best Practices & Automation

TL,DR: GRC incident management connects incident response with risks, controls, audits, and reporting obligations. The article recommends a loop: detect, triage, escalate, CAPA, evidence, and review. Use it to track security events, vendor issues, audit findings, and privacy incidents in one process. Most mid-market teams still split incident management and GRC: Ops handle tickets while…

Your Go-To Vendor Risk Management Checklist

TL;DR The vendor risk management checklist covers everything from identifying the right vendor partner to onboarding steps.  To ensure vendors meet your standards, you must evaluate them on competency, quality, capacity, cost, and compliance. Keep track of important documents such as NDAs, service level agreements, insurance policies, financial records, and disaster recovery plans. Have you…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.