All Courses HIPAA HIPAA Training Important HIPAA Terminology

Important HIPAA Terminology

Video 5 of 14
4 min 4 sec
English
English

In this lesson, we will go through some essential HIPAA definitions and core terms to help you better understand the law, including encryption standards, business associate liabilities, and risk assessment structures.

Key HIPAA Terms & Definitions

  • HIPAA: Health Insurance Portability and Accountability Act of 1996.
  • HITECH: Health Information Technology for Economic and Clinical Health Act of 2009. HITECH promotes the adoption and meaningful use of health IT while significantly expanding HIPAA privacy rules and security standards.
  • PHI (Protected Health Information): Any personal health information that identifies or pertains to a patient.
  • ePHI (Electronic Protected Health Information): Personal health information stored or transmitted electronically, including faxes, emails, cloud providers, data backups, patient portals, removable media, and secure texting.

Encryption & "Reasonable and Appropriate" Standards

All ePHI should be encrypted at rest and in transit wherever reasonable and appropriate. "Reasonable and appropriate" is not a matter of opinion; it refers to what a careful organization of your size, resources, and risk level would do to protect data. If encryption is not feasible, the reason must be documented and an equivalent safeguard implemented instead.

Business Associate Requirements

A Business Associate is any individual or entity that supports the healthcare industry and performs functions on behalf of a covered entity. Under HITECH regulations, business associates must comply directly with HITECH rules and assume financial liability for data breaches caused by their organization or employees.

Business associates are required to maintain:

  • Formal Risk Assessments
  • Employee Training Programs
  • A customized Book of Evidence (policies and procedures)

Understanding Risk Assessments

A Risk Assessment consists of government-mandated questions to identify potential security gaps and risk levels. It requires a corresponding risk report featuring a clear roadmap to resolution. Questionnaires cover three main domains (Administrative, Technical, and Physical) and utilize three implementation levels:

  • Standard: Measures compliance to ensure confidentiality, integrity, and availability of ePHI.
  • Required: Mandatory implementation for all covered entities and business associates.
  • Addressable: Provides operational flexibility based on risk level. However, addressable does not mean optional; organizations must apply appropriate security measures to manage the risk.

Pro Tip #1: A Book of Evidence is your customized set of written policies and procedures explaining how your organization manages PHI and ePHI, including data breach notification protocols, disaster recovery, and privacy policies.

Pro Tip #2: Covered entities must provide patients with a copy of their Privacy Policy upon request. Business associates must make their privacy policies available to internal employees, downstream suppliers, and government auditors.