Glossary
HIPAA
Also called: Health Insurance Portability and Accountability Act
HIPAA is the US framework governing protected health information. Its Security Rule sets administrative, physical and technical safeguards, and it is the technical ones — unique user identification, automatic logoff, encryption, audit controls, integrity checks and authentication — that a document management system implements directly.
HIPAA explained
The safeguard that decides it
45 CFR §164.312(b) requires mechanisms that record and examine activity in systems containing protected health information — activity, not merely modification. A system that logs edits but not reads cannot tell you who saw a record before it was disclosed, which is the first question in a breach investigation.
That single requirement disqualifies most general-purpose file stores.
Unique identification
§164.312(a)(2)(i) requires a unique name or number for each user. Shared departmental logins are excluded outright, because a record of "the reception account" opening a file is attributable to nobody and therefore evidences nothing.
Minimum necessary
The Privacy Rule limits uses and disclosures to the minimum needed for the purpose. In practice this requires permissions finer than read and write — a billing clerk confirming a procedure took place does not need the clinical narrative, and preview-only access exists for exactly this case.
Business associate agreements
A vendor storing or transmitting protected health information on a covered entity's behalf is a business associate as a matter of law and must execute an agreement. A vendor that hesitates on that question has answered it.
Retention is not HIPAA's
HIPAA requires six years for compliance documentation such as policies and risk analyses. Clinical record retention is set by state law and varies substantially, with longer clocks for minors — which is the retention question most often misconfigured in healthcare.
FAQ
HIPAA: common questions
Does encryption remove the breach notification duty?
It can. The duty applies to unsecured protected health information, and PHI encrypted to the standard in HHS guidance may fall outside that definition. It does not help if an authorised account is compromised.
Is a signed BAA sufficient assurance?
It is necessary and not sufficient. The agreement allocates responsibility; the controls still have to exist, which is what a security review examines.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
آخر مراجعة: 28 أغسطس 2026. Browse the full glossary.