Cybersecurity Glossary

HIPAA

The United States rules protecting health information, and the contracts that extend them to suppliers.

What HIPAA means

The Health Insurance Portability and Accountability Act sets requirements for protected health information: administrative, physical and technical safeguards, a risk analysis, workforce training and breach notification. Suppliers who handle such information sign a business associate agreement and take on obligations directly.

Why HIPAA matters for small businesses and nonprofits

Many organisations are surprised to find themselves in scope. Anyone processing health information on behalf of a covered entity, including technology suppliers and some nonprofits, carries obligations and liability.

What to do about HIPAA

Three steps to deal with HIPAA

  • Establish whether you are a covered entity or a business associate before anything else
  • Complete and document a risk analysis, which is the most commonly missed requirement
  • Sign business associate agreements with every supplier that touches the data

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.