Glossary
/
HIPAA

HIPAA

HIPAA does not apply to every company or every piece of health-related data. Applicability depends on the organization, relationship, transaction, and information involved. The Privacy Rule governs uses and disclosures of protected health information, while the Security Rule establishes safeguards for electronic protected health information. Analytics teams in regulated environments should use approved architectures, contracts, access controls, auditability, and minimum-necessary practices.

What is HIPAA?

HIPAA is a United States federal law whose Privacy, Security, and Breach Notification Rules protect certain health information handled by covered entities and their business associates.

Why it matters

HIPAA does not apply to every company or every piece of health-related data. Applicability depends on the organization, relationship, transaction, and information involved. The Privacy Rule governs uses and disclosures of protected health information, while the Security Rule establishes safeguards for electronic protected health information. Analytics teams in regulated environments should use approved architectures, contracts, access controls, auditability, and minimum-necessary practices.

Example

A healthcare provider configures analytics so protected health information is handled only by authorized systems and vendors under appropriate agreements.

Related terms