Cybersecurity Glossary

What is HIPAA?

HIPAA is the US Health Insurance Portability and Accountability Act. Its Privacy, Security and Breach Notification Rules apply to covered entities and, through defined arrangements, business associates handling protected health information. The Security Rule focuses on electronic protected health information.

HIPAA is not a universal medical-device security certificate and does not generally apply merely because a company processes health-related data somewhere in the world. Applicability and obligations require legal assessment of role, data and jurisdiction.

What security themes are relevant?

Administrative, physical and technical safeguards address risk analysis, access control, auditability, transmission protection and contingency planning. The rules are risk-based and must be translated into measures appropriate to the organization.

Who falls under the HIPAA Security Rule?

RoleExampleRelevance
Covered EntityCertain health plans, clearinghouses and providers performing covered electronic transactions.Directly subject to applicable HIPAA Rules.
Business AssociateA service provider that creates, receives, maintains or transmits PHI for a Covered Entity.Needs an appropriate agreement and has its own obligations.
SubcontractorA Business Associate's subcontractor with access to PHI.The contractual and regulatory chain continues.
Non-covered consumer appA health app without the relevant role or relationship.May fall under other US or local privacy rules but not automatically HIPAA.

Administrative, physical and technical safeguards

Administrative safeguards include risk analysis, risk management, assigned security responsibility, workforce processes, incident response, contingency planning and evaluation. Physical safeguards cover facilities, workstations and devices. Technical safeguards address access, auditing, integrity, authentication and transmission. Measures follow the documented risk analysis; “addressable” does not mean that a specification can be ignored without evaluation.

Current status of the Security Rule

HHS proposed changes to strengthen cybersecurity in late 2024. Until those changes become an effective Final Rule, the Security Rule described by HHS as currently in effect remains the applicable baseline. Organizations should monitor the proposal and transition planning without presenting proposed requirements as current law. This glossary entry is not legal advice.

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on HIPAA? Tell us!