Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » HIPAA Confidentiality

HIPAA Confidentiality

The HIPAA Privacy Rule sets standards for safeguarding individuals’ medical records and identifiable health information, commonly known as PHI. 

For example, discussions between doctors and patients should occur privately, and patients may prefer to be contacted on their cell phones rather than at home. Even well-meaning family members may not necessarily access a loved one’s medical information.

Ethical healthcare practices have traditionally emphasized keeping patients’ medical data confidential. HIPAA has formalized this responsibility for covered entities, including healthcare providers, health plans, healthcare clearinghouses, and business associates who transmit health information electronically.

Confidential communication

Healthcare practitioners should ensure confidential communication with patients in line with their preferences. While medical discussions should be private, practitioners can share medical information with a patient’s immediate family or close friends if related to the patient’s care payment by limiting information exchange to what’s necessary. 

Personal representatives authorized by the patient have the same access and confidentiality rights, although practitioners may restrict information if there are concerns about domestic violence, abuse, or neglect.

Certain situations may require disclosure by law, typically when a patient’s condition poses a risk to others. 

For example, infectious diseases like COVID-19, HIV, syphilis, and tuberculosis must be reported to public health agencies. Signs of abuse or neglect, including child, adult, or elder abuse, are generally reported to protective services. 

Conditions affecting a patient’s ability to drive, such as dementia or recent seizures, may need to be reported to the Department of Motor Vehicles in some states.

Additional reading

SaaS Security: Ensuring Compliance and Protection in the Cloud

TL,DR: SaaS security protects user privacy and company data in cloud-hosted applications through encryption, authentication, access controls, and recovery procedures. 55% of SaaS businesses faced security incidents in the past two years Key challenges include third-party integration risks, insider threats, data exposure through misconfigured cloud settings, compliance violations, and shadow IT from unauthorized applications Compliance…

ISO 27001 Compliance [2026]: An Updated Guide

TL;DR ISO 27001 compliance means implementing a risk-based Information Security Management System (ISMS) that protects data confidentiality, integrity, and availability. Organizations achieve certification through risk assessments, control implementation (Annex A), internal audits, and external certification audits (Stage 1 & Stage 2). The standard includes core clauses (4–10) covering context, leadership, planning, operations, evaluation, and continuous…

Recovery Point Objective for Costs, Risks, and Resilience

TL,DR: Recovery Point Objective (RPO) is the maximum acceptable data loss measured in time during an unexpected event. It works alongside RTO, which determines how quickly systems must be restored RPO is calculated from 3 factors: data recovery cost, required system performance, and overall risk tolerance. Critical systems require near-zero RPO with continuous replication, while…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.