Cybersecurity Glossary
HIPAA
The United States rules protecting health information, and the contracts that extend them to suppliers.
What HIPAA means
The Health Insurance Portability and Accountability Act sets requirements for protected health information: administrative, physical and technical safeguards, a risk analysis, workforce training and breach notification. Suppliers who handle such information sign a business associate agreement and take on obligations directly.
Why HIPAA matters for small businesses and nonprofits
Many organisations are surprised to find themselves in scope. Anyone processing health information on behalf of a covered entity, including technology suppliers and some nonprofits, carries obligations and liability.
What to do about HIPAA
- Establish whether you are a covered entity or a business associate before anything else
- Complete and document a risk analysis, which is the most commonly missed requirement
- Sign business associate agreements with every supplier that touches the data
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.