Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » Limited Data Set

Limited Data Set

A limited data set is detailed as health information that excludes certain listed direct identifiers but that may include city;  ZIP Code; state; elements of date; telephone numbers, fax numbers and other characteristics, numbers, or codes not listed as direct identifiers.

The direct identifiers defined in the Privacy Rule’s limited data lays down provisions that apply both to information about the individual as well as to information about the individual’s employers, relatives, or household members. The following list of identifiers must be deleted from health information if the data is to be permitted as a limited data set:

– Medical record numbers

– Names

– Postal address information

– Electronic mail addresses

– Social security numbers

– Certificate/license numbers

– Health plan beneficiary numbers

– Account numbers

– Telephone numbers

– Fax numbers

– Vehicle serial numbers and identifiers, including license plate numbers.

– Biometric identifiers, including fingerprints and voiceprints.

– Device identifiers and serial numbers

– Web universal resource locators (URLs)

– Full-face photographic images and any comparable images

– Internet protocol (I.P.) address numbers

Additional reading

GDPR Fines In 2026: Penalty Structure, Calculation Criteria, and Biggest Fines So Far

TL,DR: GDPR fines apply when organizations fail to protect personal data or meet privacy obligations. Penalties can result from weak consent, poor security, delayed breach reporting, or unlawful processing. Strong privacy governance, records, controls, and response processes reduce fine exposure. In May 2023, Meta was fined €1.3 billion by the Irish Data Protection Commission for…

GRC in Cybersecurity: How to Build a Program That Actually Works

TL,DR: Cyber GRC connects security posture to business goals, legal duties, and risk appetite. It defines ownership, risk escalation, control mapping, framework evidence, and board-level reporting. The article covers cybersecurity frameworks, operating models, metrics, AI governance, and a 12-month plan. GRC in cybersecurity is now key to containing rising incident rates. A recent security report…

A Quick-Start Guide To ISO 27001 Compliance Automation

ISO/IEC 27001:2022 is one of the best-known international standards for building and maintaining an Information Security Management System (ISMS). For growing companies, the challenge is rarely understanding why the standard matters, but it’s translating requirements into repeatable controls, evidence, reviews, and audit readiness. With security becoming an increasingly important factor in enterprise buying decisions, companies…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.