Your security and compliance glossary

All the terms you need to know when you’re trying to get compliance audit ready, fast.

Show filters

What is HIPAA?

HIPAA is the acronym for the Health Insurance Portability and Accountability Act passed by Congress in 1996.  HIPAA helps by:

  • Providing the ability to transfer and continue health insurance coverage for millions of American workers and their families when they change or lose their jobs;
  • Reducing health care fraud and abuse;
  • Mandating  industry-wide standards for health care information on electronic billing and other processes;
  • Requiring the protection and confidential handling of protected health information

HIPAA compliance is relevant to Covered Entities and Business Associates. Covered Entities include the following:

  • Healthcare providers - Hospitals, doctors, clinics, psychologists, dentists, chiropractors, nursing homes, and pharmacies
  • Health plans - health insurance companies, HMOs, company health plans, Medicare, and Medicaid
  • Healthcare clearinghouses - an entity that takes in information from a healthcare entity, puts the data into a standard format, and then returns the information to another healthcare entity.

Business Associates are vendors or subcontractors who have access to private health information (PHI). If your company stores or processes PHI, you should be HIPAA  compliant.

Additional resources you might like:

GDPR
Blog
GDPR compliance for US companies: Step-by-step guide

Learn how GDPR impacts US organizations and what it takes to achieve compliance.

GDPR
GDPR
Blog
An actionable guide to GDPR compliance for startups

Learn what GDPR compliance means for startups and how to achieve it while building trust and scaling with confidence.

Compliance
Blog
How to choose the best regulatory compliance software: A buyer’s guide

Find out what to look for in compliance software as AI and regulatory requirements continue to change.

Additional resources you might like:

GDPR
Blog
GDPR compliance for US companies: Step-by-step guide

Learn how GDPR impacts US organizations and what it takes to achieve compliance.

GDPR
Blog
An actionable guide to GDPR compliance for startups

Learn what GDPR compliance means for startups and how to achieve it while building trust and scaling with confidence.

Compliance
Blog
How to choose the best regulatory compliance software: A buyer’s guide

Find out what to look for in compliance software as AI and regulatory requirements continue to change.

GDPR
Events
Learn How to Automate Compliance for ISO 27001, GDPR, and more

Join our live demo to learn how Vanta automates compliance for ISO 27001, DORA, the EU AI Act, and more, saving you time and money.

Compliance
Events
Learn How to Automate Compliance for SOC 2, ISO 27001, and More

Watch our on-demand demo to learn how Vanta can help you accelerate compliance with deep automation and agentic workflows that handle evidence, policies, and remediation for you across frameworks like SOC 2, ISO 27001, HIPAA, and more.

ISO 27001
Blog
The Australian startups guide to ISO 27001

Understand the benefits, steps to certification, and how Vanta simplifies the journey.

SOC 2
Blog
What is SOC 2 and why Australian startups need it

SOC 2 for Aussie startups.

Compliance
Events
3 Steps to Kick Off First-Time Compliance in 2026

Watch this on-demand webinar to learn how to make compliance work at your pace, without slowing momentum, stalling deals, or putting revenue at risk.

Vendor Risk Management
Events
Office Hour: Transform how you manage third-party and internal risk

Check out our on demand Office Hour where we dive deeper into Vanta’s vision for unified, continuous, AI-powered risk management, and what it means for your business today.