HIPAA glossary for private practices
The HIPAA vocabulary a solo or small practice actually meets, defined in plain language and grounded in the exact 45 CFR section that defines each term. Every entry links to the regulation and to the document it maps to in your binder.
Last verified: July 23, 2026· every citation checked against the current 45 CFR text
The terms, defined
Eight terms carry most of HIPAA for a private practice. Start with whichever one sent you here; each links to a fuller definition, the regulation, and the matching document. Wondering what all of this costs to put in place? See how much HIPAA compliance costs a small practice.
Breach Notification Rule
The Breach Notification Rule (45 CFR 164.400–414) requires covered entities to notify affected individuals, HHS, and sometimes the media after a breach of unsecured PHI. Notice to individuals is due without unreasonable delay and no later than 60 days from discovery. It applies to breaches occurring on or after September 23, 2009.
45 CFR §§ 164.400–414Business Associate
A business associate is a person or company that creates, receives, maintains, or transmits protected health information on behalf of a covered entity, other than as a member of its workforce (45 CFR 160.103). Common examples: an EHR vendor, a billing service, a cloud backup, or an email provider that touches patient data.
45 CFR § 160.103Business Associate AgreementBAA
A Business Associate Agreement (BAA) is the written contract a covered entity must have with any vendor that handles PHI on its behalf. Under 45 CFR 164.502(e) the covered entity must obtain satisfactory assurances the vendor will safeguard the data, and 45 CFR 164.504(e) sets the clauses the contract must contain.
45 CFR § 164.502(e), § 164.504(e)Covered Entity
A covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits any health information in electronic form in connection with a HIPAA transaction (45 CFR 160.103). For a private practice the trigger is the electronic transaction, most often an insurance claim, not the act of seeing patients.
45 CFR § 160.103Minimum Necessary Standard
The minimum necessary standard requires that when a covered entity or business associate uses, discloses, or requests PHI, it makes reasonable efforts to limit the information to the minimum needed for the purpose (45 CFR 164.502(b)). It does not apply to treatment disclosures between providers or to disclosures to the individual, among other exceptions.
45 CFR § 164.502(b)Notice of Privacy PracticesNPP
A Notice of Privacy Practices (NPP) is the document a covered entity must give patients describing how it uses and discloses their PHI and their rights over it. Under 45 CFR 164.520 the individual has a right to adequate notice, and providers with a direct treatment relationship must give it at first service, post it, and put it online.
45 CFR § 164.520Protected Health InformationPHI
Protected health information (PHI) is individually identifiable health information a covered entity or business associate holds or transmits in any form, electronic, paper, or oral. Under 45 CFR 160.103 it excludes education records governed by FERPA, employment records held by an employer, and information about someone deceased more than 50 years.
45 CFR § 160.103Security Risk AnalysisSRA
A Security Risk Analysis (SRA) is HIPAA’s required, documented assessment of the risks and vulnerabilities to the electronic PHI a practice holds. Under 45 CFR 164.308(a)(1)(ii)(A) it must be an accurate and thorough assessment of potential risks to the confidentiality, integrity, and availability of ePHI. It is the single most-cited deficiency in OCR enforcement.
45 CFR § 164.308(a)(1)(ii)(A)From definitions to the actual documents
Every term here maps to a document a covered practice keeps. See the full set, or generate the three you can build yourself right now.
See what goes in a HIPAA binderSources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164
- www.hhs.gov/hipaa/for-professionals/index.html
Last verified July 23, 2026. Educational self-help information about HIPAA, not legal advice. Definitions paraphrase the regulation; the controlling text is the linked 45 CFR section. Whether HIPAA applies to your practice depends on the covered-entity test. State law may add stronger requirements.