Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » HIPAA Journal

HIPAA Journal

The HIPAA Journal is a useful website for all things HIPAA. It’s got news, breach info, tips, and the latest in healthcare data security. They’ve got sections like “New HIPAA regulations” and “HIPAA Changes 2023.”

You can find out about the latest HIPAA rule updates, like telehealth rules and security changes. They even wrote about how 79% of healthcare companies had API security problems last year. It’s a good way to keep up with what’s happening in HIPAA.

You can also get the scoop on recent healthcare data breaches. 

They tell you how they happened, what it meant for patients and organizations, and how to improve security. At that time, they covered CareSource and their MOVEit data breach lawsuits.

Additional reading

Secureframe vs Vanta vs Drata: Who actually delivers on Compliance? 2026

If you’re just starting your search for a SOC 2, ISO 27001, HIPAA, or GDPR compliance solution, you’ve likely come across three big names: Secureframe, Vanta, and Drata. Each promises to automate evidence collection, streamline audits, and simplify certification. But which one truly delivers on its promises?  Choosing the wrong platform can mean costly delays…

Best Risk Assessment Tools for Managing Cyber Risk

Risk assessment is an activity that helps organizations strengthen their security posture. A well-rounded risk assessment process helps you identify compliance risks, evaluate their severity, and minimize impact on operations. For organizations subject to PCI DSS, these PCI DSS risk assessment requirements carry additional specificity: the scope must cover the cardholder data environment and the…

ISO 27001 Password Policy: Guidelines and Best Practices

TL;DR ISO 27001 doesn’t mandate specific password rules: it requires a risk-based approach to access control, ensuring passwords are strong, secure, and protected from unauthorized access. Requirements sit in Annex A Control 5.17 (ISO 27001:2022) and related access control clauses (9.1-9.4), covering access control policy, user access management, user responsibilities, and application access. No exact…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.