HIPAAmart

Glossary of Terms

Regulatory language, translated.

A directory of HIPAA terms with plain-language definitions, context, examples, and official references.

Reviewed August 2026

Available guidance

  • Protected health information (PHI)

    Individually identifiable health information held or transmitted by a covered entity or business associate in a form or medium covered by HIPAA.

  • Business associate

    A person or entity that performs certain functions or activities for, or provides certain services to, a covered entity involving the use or disclosure of PHI.

  • Covered entity

    A health plan, health care clearinghouse, or health care provider that conducts certain covered electronic transactions.

  • Electronic protected health information (ePHI)

    PHI created, received, maintained, or transmitted in electronic form.

  • Minimum necessary

    A Privacy Rule standard calling for reasonable steps to limit many uses, disclosures, and requests for PHI to what is needed for the intended purpose.

  • Business associate agreement (BAA)

    A written arrangement establishing permitted and required uses and disclosures of PHI and the parties' responsibilities.

  • Risk analysis

    A thorough and accurate assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

  • Security incident

    The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.

  • Administrative safeguards

    Administrative actions, policies, and procedures used to manage the selection, development, and implementation of security measures for ePHI.

  • Technical safeguards

    Technology and related policies and procedures used to protect ePHI and control access to it.

  • Breach

    An impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI, subject to the rule's exceptions and risk analysis framework.

  • Addressable implementation specification

    A Security Rule implementation specification that requires an organization to assess whether and how to implement it based on its circumstances.