Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
HIPAA Privacy Practices
Covered entities must provide a Notice of Privacy Practices (Privacy Notice) to every individual whose PHI is processed by them. Healthcare providers send this notice to new enrollees during initiation and at least once every three years to the existing ones. Self-insured health plans create their own Privacy Notices, while fully insured plans rely on their insurance issuers for this.
How to provide the notice?
- Any person who requests the Privacy Notice should receive it
- The notice must be prominently displayed on the entity’s website if it provides customer service or benefit information there
- Health plans must give the notice to current members by April 14, 2003 (or April 14, 2004, for smaller plans) and to new enrollees during enrollment
- If the notice changes significantly, it should be reissued within 60 days
- Covered Direct Treatment Providers must give the notice to patients at the first service encounter, and efforts should be made to get a written acknowledgment
- For online or electronic service delivery, an electronic notice should be sent upon the patient’s request
- In emergencies, the notice should be provided as soon as possible, and acknowledgment is not required
- The latest notice reflecting any changes should be available for patients to take and be prominently displayed at the provider’s facility
- If a patient agrees, the notice can be sent via email
Additional reading
Top 11 Picks for Compliance Audit Software in 2026
TL;DR Continuous monitoring beats point-in-time prep: The best compliance audit software keeps controls monitored year-round instead of scrambling before fieldwork. Framework reuse reduces compliance debt: Strong platforms map one control across multiple standards, eliminating duplicate work. Fit depends on maturity and complexity: Startups need guided, fast certification tools; enterprises require configurable workflows, multi-entity oversight, and…
Top 7 Benefits of ISMS Implementation for Modern Businesses
TL,DR: ISMS helps manage sensitive data through policies, controls, and repeatable risk processes. Benefits include better data protection, regulatory alignment, customer trust, and standardized internal security practices. The article explains seven ISMS benefits and how ISO 27001 alignment supports security maturity. Is securing your business’s data and information security in today’s ever-evolving digital threat landscape…
Sprinto’s Integrated Risk Assessment
Making Risk Assessment Insightful, Improved and Instant Risk assessment doesn’t always get the detailed attention it deserves in the run-up to getting audit ready. After all, working with unwieldy spreadsheets, double-guessing risk parameters and allocating risk profiles can make even the best of us wonder if we are going about it the right way! But…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.






