Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » HIPAA Privacy Practices

HIPAA Privacy Practices

Covered entities must provide a Notice of Privacy Practices (Privacy Notice) to every individual whose PHI is processed by them. Healthcare providers send this notice to new enrollees during initiation and at least once every three years to the existing ones. Self-insured health plans create their own Privacy Notices, while fully insured plans rely on their insurance issuers for this.

How to provide the notice?

  • Any person who requests the Privacy Notice should receive it
  • The notice must be prominently displayed on the entity’s website if it provides customer service or benefit information there
  • Health plans must give the notice to current members by April 14, 2003 (or April 14, 2004, for smaller plans) and to new enrollees during enrollment
  • If the notice changes significantly, it should be reissued within 60 days
  • Covered Direct Treatment Providers must give the notice to patients at the first service encounter, and efforts should be made to get a written acknowledgment
  • For online or electronic service delivery, an electronic notice should be sent upon the patient’s request
  • In emergencies, the notice should be provided as soon as possible, and acknowledgment is not required
  • The latest notice reflecting any changes should be available for patients to take and be prominently displayed at the provider’s facility
  • If a patient agrees, the notice can be sent via email

Additional reading

ISO 27000 Series

ISO 27000 Series of Standards – Complete Guide

With data breaches on the rise, more businesses are seeking vendors who can protect their sensitive data. To provide that guarantee, you need to maintain the highest security standard. And the ISO 27000 series is a good starting point. The ISO 27000 is a series of information security standards that help ensure that your organization…
third party due diligence

 100+ Ransomware Statistics You Should Know

No matter how much you beef up your defenses, there’s always a bad actor out there eager to find that one overlooked weakness. Ransomware is one type of malware that threatens to destroy or lock up your critical data unless you cough up a ransom. If you’re feeling overwhelmed after reading those dramatic headlines that…
HITRUST Certification

HITRUST Certification: Your Gateway to Robust Security

As the healthcare industry actively embraces cloud technology and the electronic transmission of PHI, it has become an increasingly soft target for malicious actors. While HIPAA lays the groundwork for protecting health information, there was a need for a comprehensive framework to address the gaps in the healthcare cybersecurity landscape. That’s when HITRUST came into…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.