Your security and compliance glossary

All the terms you need to know when you’re trying to get compliance audit ready, fast.

Show filters

What is a HIPAA-covered entity?

A HIPAA-covered entity is an individual, organization, or agency to which the HIPAA Rules apply; covered entities include health care providers, health plans, and health care clearinghouses. 


Health care providers include those providers who electronically submit HIPAA transactions like claims. Providers include but are not limited to: 

  • Doctors
  • Clinics
  • Psychologists
  • Dentists
  • Chiropractors
  • Nursing homes
  • Pharmacies 


For HIPAA purposes, health plans include:

  • Health insurance companies
  • HMOs or health maintenance organizations
  • Employer-sponsored health plans
  • Government programs that pay for health care, like Medicare, Medicaid, and military and veterans’ health programs


Health care clearinghouses are public or private entities that process or facilitate the processing of nonstandard health information into standard data elements on behalf of other organizations.


HIPAA Rules apply to covered entities as well as business associates. If a covered entity engages a business associate to help carry out health care activities and functions, the covered entity must have a written business associate contract or other arrangement with the business associate that establishes what the business associate has been engaged to do, and requires the business associate to comply with HIPAA.

Additional resources you might like:

GRC
Events
Scaling Governance, Risk, and Compliance with Trust

Join ShipBob’s Heidi Pili and CMG’s Josh Wasserman for an interactive session on scaling your GRC program, with insights on key trends, Vanta use cases, and effective communication strategies.

SOC 2
Events
Product Demo: Automating Compliance for SOC 2, ISO 27001, HIPAA, and More

Learn how Vanta’s automation tools can help you streamline compliance, continuously monitor security controls, and scale your risk management program with ease.

Compliance
Events
Navigating AI and Compliance in Healthcare: Panel Discussion

Join experts from Vanta, Modern Health, and US Med-Equip as they discuss navigating AI risk management, staying compliant with evolving regulations, and scaling data security in healthcare.

Additional resources you might like:

GRC
Events
Scaling Governance, Risk, and Compliance with Trust

Join ShipBob’s Heidi Pili and CMG’s Josh Wasserman for an interactive session on scaling your GRC program, with insights on key trends, Vanta use cases, and effective communication strategies.

SOC 2
Events
Product Demo: Automating Compliance for SOC 2, ISO 27001, HIPAA, and More

Learn how Vanta’s automation tools can help you streamline compliance, continuously monitor security controls, and scale your risk management program with ease.

Compliance
Events
Navigating AI and Compliance in Healthcare: Panel Discussion

Join experts from Vanta, Modern Health, and US Med-Equip as they discuss navigating AI risk management, staying compliant with evolving regulations, and scaling data security in healthcare.

ISO 42001
Blog
4 lessons learned during our ISO 42001 audit

Key takeaways from our ISO 42001 audit—and tips to help other companies navigate the process with ease.

Compliance
Events
Product Demo: Simplify ISO 27001 and SOC 2 compliance with Vanta

See how Vanta simplifies security and streamlines compliance across 35+ frameworks—live on May 6.

Security
Events
From Insights to Action: Measuring and Advancing Security Maturity

Discover how Vanta’s customizable reporting and dashboarding can help you assess and improve security maturity with real-time insights, better risk visibility, and data-driven decision-making.

Company news
Events
Zero to success: What we got wrong before we got it right

Join experienced founders as they share key lessons on overcoming early startup challenges and driving growth.

SOC 2
Events
Live Demo: Automating Compliance for SOC 2, ISO 27001, and More

Discover how automation can transform your compliance efforts into a streamlined, efficient process. Join the live demo to see it in action and get your compliance questions answered.

Compliance
Events
Demystifying the EU AI Act

Discover how Vanta can streamline your journey through this new regulatory landscape, ensuring your AI operations are secure and future-ready.

OSZAR »