Your security and compliance glossary

All the terms you need to know when you’re trying to get compliance audit ready, fast.

Show filters

What is HIPAA?

HIPAA is the acronym for the Health Insurance Portability and Accountability Act passed by Congress in 1996.  HIPAA helps by:

  • Providing the ability to transfer and continue health insurance coverage for millions of American workers and their families when they change or lose their jobs;
  • Reducing health care fraud and abuse;
  • Mandating  industry-wide standards for health care information on electronic billing and other processes;
  • Requiring the protection and confidential handling of protected health information

HIPAA compliance is relevant to Covered Entities and Business Associates. Covered Entities include the following:

  • Healthcare providers - Hospitals, doctors, clinics, psychologists, dentists, chiropractors, nursing homes, and pharmacies
  • Health plans - health insurance companies, HMOs, company health plans, Medicare, and Medicaid
  • Healthcare clearinghouses - an entity that takes in information from a healthcare entity, puts the data into a standard format, and then returns the information to another healthcare entity.

Business Associates are vendors or subcontractors who have access to private health information (PHI). If your company stores or processes PHI, you should be HIPAA  compliant.

Additional resources you might like:

GRC
Blog
Understanding inherent risk vs residual risk—and why the gap matters

Learn about inherent and residual risk beyond definitions and see how they influence decisions.

Compliance
Events
Agentic compliance in action with Vanta and Claude

Register to learn how Vanta's MCP Server brings your compliance program directly into Claude.

GRC
Blog
How to write a risk appetite statement in 5 steps

A risk appetite statement isn’t useful unless it drives decisions. Learn how to create one with clear thresholds that help align action with your risk appetite.

Additional resources you might like:

GRC
Blog
Understanding inherent risk vs residual risk—and why the gap matters

Learn about inherent and residual risk beyond definitions and see how they influence decisions.

Compliance
Events
Agentic compliance in action with Vanta and Claude

Register to learn how Vanta's MCP Server brings your compliance program directly into Claude.

GRC
Blog
How to write a risk appetite statement in 5 steps

A risk appetite statement isn’t useful unless it drives decisions. Learn how to create one with clear thresholds that help align action with your risk appetite.

GRC
Blog
Risk appetite and risk tolerance: What’s the difference?

Learn what risk appetite and risk tolerance mean, how they differ and formalize them at scale.

Comparisons and reviews
Video
Why enterprise leaders choose Vanta over Drata to prove and manage trust

Learn how Vanta is uniquely equipped to meet the needs of large, complex organizations.

Compliance
Blog
The 9 compliance risks hiding in your organization (and how to fix them)

Learn what compliance risk is and what its most common types are. Find out how to assess and manage your compliance risk and best practices to follow.

Comparisons and reviews
Blog
The best TPRM software for 2026

Discover the best third-party risk management software solutions for 2026.

Comparisons and reviews
Blog
Top 5 OneTrust alternatives

Check out top OneTrust alternatives for compliance and risk management.

Comparisons and reviews
Blog
Top 4 Secureframe alternatives

Explore features, limitations, and scalable compliance solutions.