Your security and compliance glossary

All the terms you need to know when you’re trying to get compliance audit ready, fast.

Show filters

What is a HIPAA business associate?

A HIPAA business associate is a person or entity that performs certain functions or activities involving the use or disclosure of protected health information (PHI) on behalf of, or through the provision of services to, a covered entity. For example, health plans, health care clearinghouses, and certain health care providers.


Most providers and plans do not carry out all of their health care activities and functions by themselves; they often use the services of other persons and businesses. The HIPAA Privacy Rule allows covered entities to disclose protected health information to these business associates if the providers or plans obtain satisfactory assurances the business associate will:

  • Use the information only for the purposes they’ve been engaged 
  • Safeguard the information from misuse
  • Help the covered entity comply with some of the covered entity’s duties under the Privacy Rule  


HIPAA Rules apply to covered entities as well as business associates. Suppose a covered entity engages a business associate to help carry out its health care activities and functions. In that case, the business associate must comply with HIPAA, and the covered entity must have a written business associate contract or another arrangement with the business associate that establishes the engagement specifics.


Covered entities may disclose protected health information to an entity in its role as a business associate only to help the covered entity carry out its health care functions—not for the business associate’s independent use or purposes, except as needed for the proper management and administration of the business associate.

Additional resources you might like:

Compliance
Event
Simplifying SOC 2 and ISO 27001 compliance for growing businesses

Join us for a 45-minute webinar where we’ll demonstrate how Vanta automates up to 90% of the work for security and privacy frameworks, and helps you move towards a state of continuous compliance.

Security
Event
The State of Trust 2024: How UK Businesses are managing risk and compliance with automation

Join our upcoming webinar, where leading cybersecurity experts Ciaran Martin and Victoria Baines will discuss findings from Vanta’s second annual State of Trust Report. Understand the risks facing UK organisations, why good security means good business and how to minimise manual security work through AI and automation. 

SOC 2
Event
Compliance for startups with Fern (YC W23)

Join Danny Sheridan, Co-founder and CEO at Fern (YC W23), and Brian Kuan, Product Marketing Manager at Vanta (YC W18), for a deep dive into why startups should prioritize compliance early in their journey, and how Vanta can help you become SOC 2-ready in as little as four weeks—giving time back for you to focus on building a company.

Additional resources you might like:

Compliance
Event
Simplifying SOC 2 and ISO 27001 compliance for growing businesses

Join us for a 45-minute webinar where we’ll demonstrate how Vanta automates up to 90% of the work for security and privacy frameworks, and helps you move towards a state of continuous compliance.

Security
Event
The State of Trust 2024: How UK Businesses are managing risk and compliance with automation

Join our upcoming webinar, where leading cybersecurity experts Ciaran Martin and Victoria Baines will discuss findings from Vanta’s second annual State of Trust Report. Understand the risks facing UK organisations, why good security means good business and how to minimise manual security work through AI and automation. 

SOC 2
Event
Compliance for startups with Fern (YC W23)

Join Danny Sheridan, Co-founder and CEO at Fern (YC W23), and Brian Kuan, Product Marketing Manager at Vanta (YC W18), for a deep dive into why startups should prioritize compliance early in their journey, and how Vanta can help you become SOC 2-ready in as little as four weeks—giving time back for you to focus on building a company.

Compliance
Event
Simplify Compliance and Enhance Your Customer’s Trust

Curious about why compliance is so important, which businesses need it, and how Vanta's automation can help you quickly achieve it? Join Vanta’s 45-minute live product demo where you’ll learn how Vanta goes beyond compliance to enhance your overall security and trust management.

Compliance
Event
Fostering a culture of security in an AI world

Join our expert-led session to explore strategies for embedding a security-first culture in an AI-driven world. We'll address unique challenges and share actionable insights to help safeguard your organization.

Compliance
Event
Streamlining SOC 2 Compliance with Vanta and AWS

Watch our Coffee and Compliance session, where our experts, Ethan Heller, GRC, Subject Matter Expert at Vanta, and Brad Dispensa,WWPS Specialist SA at Amazon Web Services (AWS) cover some of the challenges of SOC 2 compliance and show how Vanta and AWS work together to simplify and accelerate SOC 2 compliance.

Compliance
Event
How to streamline SOC 2 and ISO 27001 compliance with automation

Watch Vanta’s 45-minute live product demo. Our Vanta team will walk you through the platform and answer questions throughout the session.

ISO 42001
Event
How to demonstrate secure AI practices with ISO 42001

Watch Vanta and A-LIGN's Coffee and Compliance session on ISO 42001 —what it is, what types of organizations need it, and how it works.

Company news
Event
What’s new in Vanta: Unveiling the Future of GRC Roadmap

We had the pleasure of hosting Jeremy Epling, Vanta’s CPO from our Vanta Sydney office, where he shares and demonstrates some exciting new product updates designed to help security teams future-proof and scale their GRC programs more easily.