Reference Guide

Glossary of Privacy Terms

Health privacy is full of confusing terms and acronyms. This guide explains them in plain language so you can understand your rights and what's happening with your data.

A
5 terms

Access

CMS

Your ability to obtain medical care and services. Under HIPAA, patients generally have the right to access and obtain copies of their protected health information held by covered entities.

Administrative Simplification

Part of HIPAA that sets national rules for how health information is exchanged electronically. It standardizes how hospitals, insurers, and other organizations format and transmit your data.

Audit trail

A log that records every time someone accesses your health data — who looked at it, when, and what they changed. Audit trails are how you can find out if your records were accessed without a good reason.

Authentication

Verification of the identity of a person or process. Authentication mechanisms ensure that users are who they claim to be before granting access to protected health information.

Authorization

Your written permission for someone to use or share your health data for a specific purpose. Under HIPAA, hospitals and insurers can use your data for treatment and billing without asking, but they need your authorization for most other uses — like marketing or research.

B
3 terms

Blanket coerced consent

Deborah Peel

When an insurance company makes you sign over access to all your past and future medical records just to get coverage. You technically "consent," but you have no real choice — it’s agree or go without insurance.

Breach notification

The legal requirement that hospitals, insurers, and their contractors must tell you if your health data has been stolen or accidentally exposed. For large breaches, they also have to notify the government and the media.

Business associate

CMS

Any company that handles your health data on behalf of a hospital or insurer — like billing companies, IT contractors, or data analysts. They’re required to follow the same privacy rules as the hospital itself.

C
3 terms

Confidentiality

A third party's obligation to protect the personal information with which it has been entrusted. Confidentiality is the cornerstone of the patient-physician relationship and essential for trust in the healthcare system.

Consent

Voluntary agreement by an individual to a proposed course of action. In health privacy, consent refers to a patient's agreement to the collection, use, or disclosure of their health information. Meaningful consent requires that the patient be informed and not coerced.

Covered entity

CMS

A hospital, doctor’s office, insurance company, or claims processor that must follow HIPAA rules to protect your health information. If an organization handles your health data electronically, it’s likely a covered entity.

D
4 terms

Data Integrity

The accuracy and completeness of data, to be maintained by appropriate security measures. Data integrity ensures that health information has not been altered or destroyed in an unauthorized manner.

Data segmentation

The process of separating sensitive categories of health information so that access to certain data can be restricted. This allows patients to consent to the sharing of some health data while withholding more sensitive information such as mental health or substance use records.

De-identification

Removing names, dates, and other identifying details from health records so that — in theory — nobody can figure out who the data belongs to. Research has shown this doesn’t always work, since combining even a few data points can reveal someone’s identity.

Disclosure of health information

When a hospital, insurer, or other organization shares your health data with someone outside their organization. This can happen for treatment, billing, or other legally permitted reasons — often without your knowledge.

E
3 terms

Electronic health record(s)

Health records kept in electronic form. EHRs are digital versions of patients' paper charts and can include a range of data such as medical history, diagnoses, medications, treatment plans, immunization dates, and test results.

Electronic Prescribing

Secure bidirectional communication between practitioners and pharmacies. E-prescribing replaces handwritten or faxed prescriptions with electronic transmission, improving accuracy while also creating new data flows that require privacy protections.

Encryption

The process of enciphering or encoding a message to render it unintelligible to unauthorized parties. Encryption is a key safeguard for protecting health data in transit and at rest, and is considered a safe harbor under HIPAA breach notification rules.

F
1 term

Federal "regulatory permission"

A rule that lets hospitals and insurers use and share your health information for treatment, billing, and operations without asking your permission first. This means your data can flow through the healthcare system before you even know about it.

G
1 term

Gramm-Leach-Bliley Act

Federal act allowing banks and financial institutions to share sensitive records without consent. Also known as the Financial Services Modernization Act of 1999, it permits the sharing of personal financial information, including health-related financial data, among affiliated companies.

H
5 terms

Health care clearinghouse

CMS

A company that acts as a middleman between your doctor and your insurance company, translating medical claims and billing into a standard format. They process your health data even though you probably don’t know they exist.

Health Information Exchange (HIE)

Systems that let hospitals, doctors, and pharmacies share your health records electronically. The idea is better-coordinated care, but it also means your data travels between more organizations than you might expect.

HIPAA

The Health Insurance Portability and Accountability Act — the main federal law protecting your health information. HIPAA requires doctors, hospitals, and insurers to keep your data private, but it has significant gaps and doesn’t cover every company that handles health data.

Health plan

An entity that assumes the risk of paying for medical treatments. Health plans include health insurance issuers, HMOs, employer-sponsored health plans, and government programs such as Medicare and Medicaid. Under HIPAA, health plans are classified as covered entities.

HITECH Act

A 2009 federal law that strengthened HIPAA. It made penalties for privacy violations tougher, required organizations to tell you when your data is breached, and banned selling your health information without your permission. PPR helped secure these protections.

I
3 terms

Individually identifiable health information

Information created or received by healthcare entities relating to the past, present, or future physical or mental health or condition of an individual, the provision of health care, or payment for health care, that identifies the individual or could reasonably be used to identify them.

Informed consent

When you actually understand what you’re agreeing to before signing — not just a form shoved at you in the waiting room. Real informed consent means knowing who will see your data, how they’ll use it, and what the risks are.

Interoperability

The ability of two or more systems or components to exchange information and to use the information that has been exchanged accurately, securely, and verifiably. Interoperability is essential for coordinated care but must be balanced with robust privacy protections.

K
1 term

K-anonymity

A way to protect privacy in datasets, developed by PPR President Dr. Latanya Sweeney in 1998. It works by making sure every person’s record looks identical to at least several other people’s records, so no one can be singled out.

M
3 terms

Medical privacy

The right of individuals to determine when, how, and to what extent information about them is communicated to others. Medical privacy encompasses not only the confidentiality of health records but also the broader right to control one's own health information.

Minimum necessary standard

The rule that hospitals and insurers should only access or share the minimum amount of your health data they actually need — not your entire medical history. In practice, this rule is often ignored.

Mosaic effect

When small pieces of information — each harmless on their own — are combined to identify you. For example, your ZIP code, birth date, and gender together can uniquely identify most Americans. This is why "anonymizing" data is harder than it sounds.

N
2 terms

National provider identifier

A system uniquely identifying all healthcare service providers. The NPI is a 10-digit number issued by CMS to health care providers and is required for electronic health care transactions. It replaced multiple provider identification numbers previously used.

Notice of Privacy Practices

The document your doctor or hospital gives you explaining how they use your health data and what rights you have. Read it carefully — it reveals what protections you actually have (and don’t have).

P
5 terms

Personal Health Information (PHI)

Any health-related information that can be linked to you specifically — your diagnoses, treatments, prescriptions, test results, billing records, and more. This is what privacy laws are designed to protect.

Personal Health Record (PHR)

An electronic record of an individual's health information by which the individual controls access to the information and may have the ability to manage, track, and participate in their own health care. Unlike EHRs controlled by providers, PHRs are patient-managed.

Privacy

The right of an individual to control the circulation of information about him- or herself. In the context of health data, privacy involves the individual's ability to determine what health information is collected, who can access it, and how it is used.

Privacy Rule

The HIPAA Standards for Privacy of Individually Identifiable Health Information, which establishes national standards to protect individuals' medical records and other personal health information. The Privacy Rule applies to health plans, health care clearinghouses, and health care providers that conduct certain electronic transactions.

Protected health information

Individually identifiable health information that is transmitted or maintained in any form or medium, including electronic, paper, or oral. PHI excludes individually identifiable health information in education and employment records.

R
4 terms

Re-identification

Figuring out who "anonymous" health data actually belongs to, using publicly available information. Researchers have proven this is surprisingly easy to do, which means de-identification alone isn’t enough to protect your privacy.

Right to be let alone

Brandeis

The foundational privacy concept articulated by Justice Louis D. Brandeis that protects Americans in their beliefs, thoughts, emotions, and sensations. Brandeis called it "the most comprehensive of rights and the right most valued by civilized men."

Right to privacy

The claim of individuals, groups, or institutions to determine for themselves when, how, and to what extent information about them is communicated to others. While not explicitly enumerated in the Constitution, it has been recognized through multiple Supreme Court decisions.

Risk Assessment

The evaluation of the chance of vulnerabilities being exploited in a system. Under HIPAA, covered entities must conduct periodic risk assessments to identify potential threats to the confidentiality, integrity, and availability of electronic PHI.

S
3 terms

Security

The degree to which data, databases, or other assets are protected from exposure to accidental or malicious access, disclosure, modification, or destruction. The HIPAA Security Rule establishes standards for the protection of electronic PHI.

Security Rule

The HIPAA rules that require hospitals, insurers, and their contractors to protect your electronic health data with real security measures — things like encryption, access controls, and monitoring for unauthorized access.

Self-insured

When your employer pays for employee healthcare directly instead of buying insurance from another company. This means your employer may have direct access to claims data about your health — a significant privacy concern many workers don’t know about.

T
2 terms

theDataMap

A research tool developed by Dr. Latanya Sweeney at Harvard that maps the flow of health data across organizations. It tracks how patient health information moves through the system, revealing the scale and complexity of data sharing in healthcare.

Transaction

Under HIPAA, the exchange of information between two parties to carry out financial or administrative activities related to health care. Standard transactions include claims, enrollment, eligibility inquiries, and payment and remittance advice.

U
1 term

Use of health information

When a hospital or insurer accesses or analyzes your health data within their own organization — as opposed to sharing it with an outside party (which is called "disclosure"). Both are regulated, but use happens behind closed doors.