Glossary of Terms
Regulatory language, translated.
A directory of HIPAA terms with plain-language definitions, context, examples, and official references.
Reviewed August 2026
Available guidance
- Protected health information (PHI)
Individually identifiable health information held or transmitted by a covered entity or business associate in a form or medium covered by HIPAA.
- Business associate
A person or entity that performs certain functions or activities for, or provides certain services to, a covered entity involving the use or disclosure of PHI.
- Covered entity
A health plan, health care clearinghouse, or health care provider that conducts certain covered electronic transactions.
- Electronic protected health information (ePHI)
PHI created, received, maintained, or transmitted in electronic form.
- Minimum necessary
A Privacy Rule standard calling for reasonable steps to limit many uses, disclosures, and requests for PHI to what is needed for the intended purpose.
- Business associate agreement (BAA)
A written arrangement establishing permitted and required uses and disclosures of PHI and the parties' responsibilities.
- Risk analysis
A thorough and accurate assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- Security incident
The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
- Administrative safeguards
Administrative actions, policies, and procedures used to manage the selection, development, and implementation of security measures for ePHI.
- Technical safeguards
Technology and related policies and procedures used to protect ePHI and control access to it.
- Breach
An impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI, subject to the rule's exceptions and risk analysis framework.
- Addressable implementation specification
A Security Rule implementation specification that requires an organization to assess whether and how to implement it based on its circumstances.