The HIPAA glossary
117 terms, acronyms, and agency names, A to Z, each defined faithfully to the regulation with its citation attached. The vocabulary of HIPAA, without the fog.
Last verified: 2026-07-12
Every field hides its rules inside its vocabulary, and HIPAA is worse than most, because half its words look like ordinary English and are not. “Breach” has a legal test. “Workstation” includes a phone. “Addressable” does not mean what anyone assumes. Here are 117 terms, acronyms, and agency names, A to Z, defined as the regulation defines them, with the citation on every entry that makes a legal claim.
A · B · C · D · E · F · G · H · I · L · M · N · O · P · R · S · T · U · W
“Half its words look like ordinary English and are not.”
A
Access
The ability or means to read, write, modify, or communicate data, or otherwise use a system resource (45 CFR 164.304).
Accounting of disclosures
An individual’s right to receive a list of certain disclosures of their PHI made in the six years before the request, with listed exceptions including treatment, payment, and operations (45 CFR 164.528).
Addressable
A label on an implementation specification meaning: assess it, then implement it, or document why it is not reasonable and appropriate and implement an equivalent alternative where one is (45 CFR 164.306(d)(3)). It has never meant optional. The full explanation, with a table of every specification.
Administrative safeguards
Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures and the conduct of the workforce (45 CFR 164.304). The requirements live at 45 CFR 164.308.
Administrative simplification provision
The collective name for the statutory and regulatory requirements HIPAA enforcement covers, including the Privacy, Security, and Breach Notification Rules (45 CFR 160.103).
ALJ
Administrative Law Judge (45 CFR 160.103). Where a civil money penalty goes if the entity contests it.
Audit controls
Hardware, software, or procedural mechanisms that record and examine activity in systems containing or using ePHI, a technical safeguard standard (45 CFR 164.312(b)).
Authentication
Corroboration that a person is the one claimed (45 CFR 164.304). The login is authentication; what the login may do is access control.
Authorization
The individual’s written, signed permission required before PHI can be used or disclosed for purposes the rules do not otherwise permit, with required elements and statements (45 CFR 164.508).
Availability
The property that data or information is accessible and usable upon demand by an authorized person (45 CFR 164.304). Ransomware is, among other things, an availability attack.
B
Breach
The acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule which compromises its security or privacy (45 CFR 164.402). An impermissible use or disclosure is presumed a breach unless a documented risk assessment demonstrates a low probability of compromise, weighing at least four listed factors.
Breach Notification Rule
The rule requiring notification of individuals, HHS, and in large cases the media, after a breach of unsecured PHI (45 CFR Part 164, Subpart D).
Business associate
A person or company outside your workforce that creates, receives, maintains, or transmits PHI while performing functions or services for a covered entity: billing, practice management, data analysis, cloud storage, IT, legal, accounting, and more (45 CFR 160.103).
Business associate agreement (BAA)
The written contract through which a covered entity obtains satisfactory assurances that a business associate will safeguard PHI, with contents the rules specify (45 CFR 164.502(e), 45 CFR 164.504(e), 45 CFR 164.314(a)). No BAA, and the disclosure to that vendor is itself a violation.
C
CFR
The Code of Federal Regulations, the codification of federal agency rules. HIPAA’s rules live in Title 45, Parts 160 through 164.
CISA
The Cybersecurity and Infrastructure Security Agency, within DHS. Not a HIPAA regulator, but the source of the ransomware and vulnerability advisories that healthcare security programs, and OCR’s expectations, increasingly track.
Civil money penalty
The monetary penalty HHS may impose for violations, with amounts set by culpability tier and adjusted annually for inflation (45 CFR 160.404).
Clearinghouse
Short for health care clearinghouse: an entity that converts health information between standard and nonstandard formats, for example a billing service that reformats claims (45 CFR 160.103). One of the three types of covered entity.
CMS
The Centers for Medicare and Medicaid Services, within HHS (45 CFR 160.103). Runs Medicare and Medicaid and administers the transaction and code set standards in 45 CFR Part 162.
Compliance date
The date by which an entity must comply with a standard, implementation specification, or modification (45 CFR 160.103).
Confidentiality
The property that data or information is not made available or disclosed to unauthorized persons or processes (45 CFR 164.304).
Corrective action plan
The remediation program an entity agrees to in an OCR settlement, typically monitored by OCR for one to three years. The lasting cost of most enforcement actions is the plan, not the payment.
Covered entity
One of three things: a health plan, a health care clearinghouse, or a health care provider that transmits any health information electronically in connection with a transaction HIPAA covers (45 CFR 160.103). That last clause is a real legal test; we wrote it up in full.
Covered transaction
Informal shorthand for a transaction for which HHS has adopted a standard under 45 CFR Part 162. See Transaction.
Credentialing
The payer’s process of verifying a provider’s qualifications before admitting them to a network. HIPAA classifies reviewing the competence or qualifications of health care professionals and conducting credentialing activities as health care operations (45 CFR 164.501), so PHI may be used for it without an authorization.
D
Data use agreement
The required contract before sharing a limited data set, binding the recipient to specified uses, safeguards, and no re-identification (45 CFR 164.514(e)).
De-identification
Rendering health information no longer individually identifiable, by expert determination or by removing eighteen listed identifiers with no actual knowledge the remainder could identify the person (45 CFR 164.514(a) and (b)). Properly de-identified information is no longer PHI.
Designated record set
The medical and billing records maintained by or for a provider, and any records used, in whole or in part, to make decisions about individuals (45 CFR 164.501). This is the set the right of access attaches to. In ABA it includes assessments, treatment plans, session data, and progress notes.
DHS
The Department of Homeland Security. Not a HIPAA regulator; relevant to healthcare through CISA’s cybersecurity advisories.
Direct data entry
The direct entry of data, for example using web browsers, that is immediately transmitted into a health plan’s computer (45 CFR 162.103). Typing into a payer portal is conducting an electronic transaction.
Disclosure
The release, transfer, provision of access to, or divulging in any manner of information outside the entity holding it (45 CFR 160.103). Compare Use.
Disposal
The required implementation specification for final disposition of ePHI and the hardware or media on which it is stored (45 CFR 164.310(d)(2)(i)).
DOJ
The Department of Justice. Criminal HIPAA violations (42 U.S.C. 1320d-6) are referred to and prosecuted by DOJ, not OCR.
E
eCFR
The Electronic Code of Federal Regulations at ecfr.gov, the continuously updated online CFR. Every regulatory citation on this site links to it.
EHR
Electronic health record. A system category, not a defined HIPAA term; an EHR holding ePHI is squarely inside the Security Rule’s scope.
Electronic media
Electronic storage material (drives, devices, memory cards) and transmission media used to exchange information already in electronic storage (45 CFR 160.103). A paper-to-paper fax and a voice call are not electronic media if the information was not electronic immediately before sending.
Emergency access procedure
The required technical procedure for obtaining necessary ePHI during an emergency (45 CFR 164.312(a)(2)(ii)). Required, and the most commonly missing item in small-practice programs.
Encryption
The use of an algorithmic process to transform data into a form with a low probability of assigning meaning without a confidential process or key (45 CFR 164.304). Done to the standards in HHS guidance, it also takes lost data out of the breach notification machinery; see Unsecured protected health information.
ePHI
Electronic protected health information: PHI transmitted by or maintained in electronic media (45 CFR 160.103). The Security Rule protects this subset.
F
FDA
The Food and Drug Administration, within HHS. Appears in HIPAA mainly as a permitted public-health disclosure recipient for product safety purposes (45 CFR 164.512(b)).
Federal Register
The daily journal of the federal government, where proposed and final rules publish. “90 FR 800” means Federal Register volume 90, page 800.
FERPA
The Family Educational Rights and Privacy Act (20 U.S.C. 1232g). Education records covered by FERPA are excluded from the definition of PHI (45 CFR 160.103), which is why school-based services raise a which-law-applies question rather than a both-laws question.
FIPS 140-2
The federal cryptographic module standard referenced in HHS breach guidance for securing ePHI in motion. Encryption consistent with it is part of the breach notification safe harbor.
FTC
The Federal Trade Commission. Enforces the separate Health Breach Notification Rule covering health apps and records outside HIPAA’s reach, and polices deceptive privacy claims generally.
G
Genetic information
Information about a person’s genetic tests, their family members’ genetic tests, family disease history, or requests for genetic services (45 CFR 160.103). A health plan may not use it for underwriting (45 CFR 164.502(a)(5)(i)).
GINA
The Genetic Information Nondiscrimination Act of 2008 (Pub. L. 110-233), the statute behind HIPAA’s genetic information provisions.
Group health plan
An employer-sponsored plan providing medical care with 50 or more participants or administered by someone other than the employer (45 CFR 160.103). A type of health plan, and therefore a covered entity.
H
Health care
Care, services, or supplies related to the health of an individual, including preventive, diagnostic, therapeutic, rehabilitative, maintenance, or palliative care, and counseling (45 CFR 160.103). ABA therapy is health care.
Health care operations
The administrative and quality activities of running a covered entity: quality assessment, training, licensing, business management, and more, as listed in the definition (45 CFR 164.501). The O in TPO.
Health care provider
A provider of medical or health services, and any person or organization that furnishes, bills, or is paid for health care in the normal course of business (45 CFR 160.103).
Health information
Any information, oral or recorded, created or received by a provider, plan, employer, or clearinghouse, relating to a person’s past, present, or future health, care, or payment for care (45 CFR 160.103).
Health plan
An individual or group plan that provides or pays the cost of medical care, including insurers, HMOs, Medicare, Medicaid, and employer group plans (45 CFR 160.103). One of the three types of covered entity.
HHS
The U.S. Department of Health and Human Services, the department that writes and enforces the HIPAA rules (45 CFR 160.103).
HIPAA
The Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191). The statute; the Privacy, Security, and Breach Notification Rules are regulations issued under it.
HITECH
The Health Information Technology for Economic and Clinical Health Act of 2009 (part of Pub. L. 111-5). Extended HIPAA obligations directly to business associates, created the Breach Notification Rule, and raised the penalty structure.
Hybrid entity
A single legal entity whose activities include both covered and non-covered functions and that designates its health care components, confining most HIPAA obligations to them (45 CFR 164.103, 45 CFR 164.105).
I
Implementation specification
Specific requirements or instructions for implementing a standard (45 CFR 160.103). Each is labelled Required or Addressable (45 CFR 164.306(d)).
Incidental use or disclosure
A secondary use or disclosure that occurs as a by-product of a permitted one, permissible if minimum necessary and reasonable safeguards were applied (45 CFR 164.502(a)(1)(iii)). A sibling overhearing a home session is the ABA example.
Individual
The person who is the subject of the protected health information (45 CFR 160.103). In an ABA clinic, usually the child.
Individually identifiable health information
Health information, including demographics, that identifies the individual or provides a reasonable basis to believe it could (45 CFR 160.103).
Information system
An interconnected set of information resources under the same direct management control, sharing common functionality, including hardware, software, information, data, applications, communications, and people (45 CFR 164.304).
Integrity
The property that data or information has not been altered or destroyed in an unauthorized manner (45 CFR 164.304). Keeping the data right, not just secret.
L
Limited data set
PHI with sixteen direct identifiers removed but retaining dates, town or city, state, and ZIP code, usable only for research, public health, or health care operations under a data use agreement (45 CFR 164.514(e)).
M
Malicious software
Software, for example a virus, designed to damage or disrupt a system (45 CFR 164.304). Protection against it is an addressable training specification (45 CFR 164.308(a)(5)(ii)(B)).
Marketing
A communication about a product or service that encourages the recipient to purchase or use it, with treatment-communication carve-outs and paid-communication conditions as defined (45 CFR 164.501). Generally requires an authorization (45 CFR 164.508(a)(3)).
MFA
Multi-factor authentication: verifying identity with two or more factors. The current Security Rule does not name it; the person or entity authentication standard (45 CFR 164.312(d)) leaves the method to you, and the January 2025 proposed rule would mandate it. The honest version of that story.
Minimum necessary
The standard requiring reasonable efforts to limit uses, disclosures, and requests of PHI to the minimum needed for the purpose, with listed exceptions including treatment and disclosures to the individual (45 CFR 164.502(b)).
N
NIST
The National Institute of Standards and Technology, within the Department of Commerce. Its publications, including SP 800-66 (implementing the Security Rule) and SP 800-111 (storage encryption, referenced in HHS breach guidance), are the technical vocabulary OCR expects programs to speak.
Notice of Privacy Practices (NPP)
The plain-language notice of your uses and disclosures of PHI, the individual’s rights, and your duties, with required content, a required header, and distribution and acknowledgment rules (45 CFR 164.520).
NPI
National Provider Identifier, the standard unique health identifier for health care providers (45 CFR 162.406).
O
OCR
The Office for Civil Rights, within HHS. Administers and enforces the HIPAA rules, investigates complaints and breach reports, and negotiates the settlements you read about.
OIG
The HHS Office of Inspector General. Fights fraud, waste, and abuse in HHS programs, runs the exclusion list that screening programs check, and audits HHS itself, including OCR’s HIPAA oversight. Distinct from OCR: OIG polices the programs, OCR polices privacy and security.
Omnibus Rule
The 2013 final rule (78 FR 5566) that implemented HITECH: direct business associate liability, the current breach standard, and the modern penalty tiers.
ONC
The office overseeing national health IT policy within HHS, reorganized in 2024 as the Assistant Secretary for Technology Policy (ASTP/ONC). Co-publisher, with OCR, of the free Security Risk Assessment Tool.
Organized health care arrangement (OHCA)
A clinically integrated setting or other qualifying joint arrangement in which participating covered entities may share PHI for the arrangement’s operations and use a joint notice (45 CFR 160.103).
P
Parent portal
The login through which a parent views records, messages, and schedules. In HIPAA terms it is an information system holding ePHI: unique user identification is required for it (45 CFR 164.312(a)(2)(i)), and the parent generally stands in the child’s shoes as a personal representative (45 CFR 164.502(g)). One shared family login is the textbook small-clinic violation.
Part 2
42 CFR Part 2, the separate and stricter federal confidentiality rule for substance use disorder treatment records. Not HIPAA, but enforced alongside it and now carrying HIPAA-scale penalties.
Payment
Activities to obtain premiums or reimbursement, or to determine coverage and provide benefits: billing, claims, eligibility, adjudication, and collections, as defined (45 CFR 164.501). The P in TPO.
Personal representative
Someone with authority under law to act for the individual in health care decisions, who must generally be treated as the individual (45 CFR 164.502(g)). For an unemancipated minor, usually a parent or guardian, with exceptions that matter in custody and abuse situations.
PHI
Protected health information: individually identifiable health information in any form, electronic, paper, or spoken, held or transmitted by a covered entity or business associate (45 CFR 160.103). It excludes FERPA education records, employment records held as an employer, and information about a person dead more than 50 years.
Physical safeguards
Physical measures, policies, and procedures to protect electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion (45 CFR 164.304). The requirements live at 45 CFR 164.310.
Plan sponsor
The employer or organization behind a group health plan. May receive PHI from the plan only under plan-document restrictions (45 CFR 164.504(f)).
Preemption
HIPAA generally overrides contrary state law, with exceptions, most importantly for state law that is more stringent, which then controls (45 CFR 160.203).
Prior authorization
The payer’s advance approval of services. In HIPAA’s vocabulary it is the referral certification and authorization transaction (45 CFR 160.103), one of the standard transactions of 45 CFR Part 162, and requesting one electronically, including through a payer portal, is the kind of act that makes a provider a covered entity.
Privacy official
The person a covered entity must designate as responsible for developing and implementing its privacy policies and procedures (45 CFR 164.530(a)(1)).
Privacy Rule
The rule governing uses and disclosures of PHI in all forms and establishing individual rights (45 CFR Part 164, Subpart E).
Psychotherapy notes
Notes by a mental health professional documenting or analyzing conversation during a counseling session, kept separate from the rest of the record (45 CFR 164.501). The definition excludes session start and stop times, modalities and frequencies, results, and summaries of diagnosis, treatment plan, symptoms, and progress. Nearly everything an ABA clinic writes falls in the exclusions: standard session notes are not psychotherapy notes and do not carry their special protections.
R
Reasonable cause
An act or omission in which the entity knew, or should have known with reasonable diligence, that the act violated a provision, but did not act with willful neglect (45 CFR 160.401). The second culpability tier.
Reasonable diligence
The business care and prudence expected from a person seeking to satisfy a legal requirement under similar circumstances (45 CFR 160.401). Also the standard that starts the breach discovery clock.
Required
A label on an implementation specification meaning: implement it. No assessment, no alternative (45 CFR 164.306(d)(2)).
Resolution agreement
The settlement instrument OCR uses to close an investigation: a payment, a corrective action plan, and monitoring, with no admission of liability.
Right of access
The individual’s right to inspect and obtain a copy of their PHI in a designated record set, generally within 30 days, in the form requested where readily producible, for a reasonable cost-based fee only (45 CFR 164.524). The subject of a long-running OCR enforcement initiative.
Risk analysis
The required accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of your ePHI (45 CFR 164.308(a)(1)(ii)(A)). The foundation the rest of the program stands on, and the most commonly cited failure in enforcement. Why it is the page OCR reads first.
Risk management
The required implementation of security measures sufficient to reduce identified risks to a reasonable and appropriate level (45 CFR 164.308(a)(1)(ii)(B)). The follow-through the analysis exists for, and the current direction of OCR’s enforcement initiative.
S
Sanction policy
The required implementation specification: apply appropriate sanctions against workforce members who fail to comply with your security policies and procedures (45 CFR 164.308(a)(1)(ii)(C)); the Privacy Rule carries a parallel requirement (45 CFR 164.530(e)).
Secretary
The Secretary of Health and Human Services, or a designee (45 CFR 160.103). When the rules say “the Secretary,” in practice they mean HHS acting through OCR.
Security incident
The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations, in an information system (45 CFR 164.304). Note “attempted”: broader than breach, and your incident procedures apply to it.
Security official
The person a covered entity or business associate must identify as responsible for developing and implementing its security policies and procedures (45 CFR 164.308(a)(2)). One named human, not a committee.
Security Rule
The rule establishing administrative, physical, and technical safeguards for ePHI (45 CFR Part 164, Subpart C).
SRA Tool
The Security Risk Assessment Tool, free software from OCR and ASTP/ONC built to walk small and medium providers through a risk assessment.
Standard
A rule, condition, or requirement describing what covered entities and business associates must achieve (45 CFR 160.103); the Security Rule’s standards may be met flexibly under 45 CFR 164.306(b).
State attorneys general
HITECH gave state attorneys general authority to bring civil actions for HIPAA violations affecting their residents (42 U.S.C. 1320d-5(d)). OCR is not the only enforcer.
Subcontractor
A person to whom a business associate delegates a function, activity, or service, other than as a member of its workforce (45 CFR 160.103). HIPAA follows the data down the chain.
Substitute notice
The alternative breach notification required when contact information is insufficient or out of date: for ten or more such individuals, a 90-day website posting or major media notice plus a toll-free number (45 CFR 164.404(d)(2)).
Superbill
An itemized statement a self-pay family submits to their insurer for reimbursement. The document is PHI in the clinic’s hands, and the delivery path matters: emailed unencrypted, it is an unprotected transmission of ePHI (45 CFR 164.312(e)(1)), and if a billing agent transmits claims electronically on the clinic’s behalf instead, the clinic is a covered entity (45 CFR 160.102, 45 CFR 160.103).
T
Technical safeguards
The technology and the policies and procedures for its use that protect ePHI and control access to it (45 CFR 164.304). The requirements live at 45 CFR 164.312; we wrote them up in full.
Telehealth
Delivering care over a network, which places the session itself inside the transmission security standard (45 CFR 164.312(e)(1)) and makes the platform vendor a business associate that needs a BAA (45 CFR 160.103, 45 CFR 164.308(b)). The temporary COVID-era enforcement discretion for everyday video apps ended in 2023; the ordinary rules apply.
TPO
Treatment, payment, and health care operations: the three purposes for which PHI may generally be used and disclosed without an authorization (45 CFR 164.506).
Transaction
The transmission of information between two parties to carry out financial or administrative health care activities, including claims, eligibility, referral certification and authorization, claim status, enrollment, payment and remittance, premium payments, coordination of benefits, and others listed (45 CFR 160.103). Conducting one electronically is what makes a provider a covered entity.
Transmission security
The technical safeguard standard: guard against unauthorized access to ePHI being transmitted over an electronic communications network (45 CFR 164.312(e)(1)).
Treatment
The provision, coordination, or management of health care and related services, including consultation and referral (45 CFR 164.501). The T in TPO.
U
Unique user identification
The required assignment of a unique name or number for identifying and tracking each user’s identity (45 CFR 164.312(a)(2)(i)). Shared logins are not a risk decision you are entitled to make.
Unsecured protected health information
PHI not rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance, in practice encryption to the specified standards or destruction (45 CFR 164.402). Breach notification applies only to unsecured PHI.
Use
The sharing, employment, application, utilization, examination, or analysis of information within the entity that holds it (45 CFR 160.103). Compare Disclosure.
W
Willful neglect
Conscious, intentional failure or reckless indifference to the obligation to comply (45 CFR 160.401). The highest culpability tier, where penalties become mandatory rather than discretionary.
Workforce
Employees, volunteers, trainees, and other persons whose conduct, in the performance of work, is under the direct control of the entity, whether or not paid (45 CFR 160.103). Your RBTs are workforce. So is the unpaid practicum student.
Workstation
An electronic computing device, for example a laptop or desktop computer, or any other device that performs similar functions, and the electronic media stored in its immediate environment (45 CFR 164.304). The tablet in your RBT’s bag is a workstation. So is the phone with the data collection app.
The short version
- 117 terms, A to Z, each defined as the regulation defines it, with the citation attached.
- The dangerous terms are the familiar ones: breach, workstation, addressable, and psychotherapy notes all mean less or more than they sound.
- ABA session notes are almost never psychotherapy notes; denying parents access on that basis is itself a violation.
- Every entry has its own anchor, so any definition can be linked directly.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Definitions, general45 CFR 160.103https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- Definitions, culpability tiers45 CFR 160.401https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-D/section-160.401
- Definitions, Part 164 general, including hybrid entity45 CFR 164.103https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-A/section-164.103
- Definitions, Security Rule45 CFR 164.304https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.304
- Security standards: General rules45 CFR 164.306https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.306
- Definitions, Breach Notification Rule45 CFR 164.402https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402
- Definitions, Privacy Rule45 CFR 164.501https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.501
- Uses and disclosures: general rules45 CFR 164.502https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- Other requirements, including de-identification and limited data sets45 CFR 164.514https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
Compliance you can actually show.
WiseUpHIPAA is built for ABA clinics. It works out what applies to you, holds your decisions and the evidence behind them, and shows you honestly where you stand, including the parts that are not done yet.