---
title: Online Tech Blog | HIPAA
description: HIPAA |
---

Call Today 1-734-213-2020

- [Events](http://onlinetech.com/events)
- [Support](http://onlinetech.com/support)
- [OTPortal](https://customer.onlinetech.com/CustomerLogin.aspx)
- [Company](http://onlinetech.com/company/overview)
- [News](http://onlinetech.com/news/overview)
- [Resources](http://onlinetech.com/resources/overview)
- [Blog](http://resource.onlinetech.com/)
- [Contact](http://onlinetech.com/contact)

[![twitter](https://web.otava.com/hs-fs/file-1181652072-png/Images/twitter.png)](http://twitter.com/onlinetech)[![linkedin](https://web.otava.com/hs-fs/file-1181371560-png/Images/linkedin.png)](http://www.linkedin.com/company/online-tech?trk=fc_badge)

[![OnLINE TECH](https://web.otava.com/hs-fs/file-1190669575-png/Images/logo-new.png "OnLINE TECH")](http://onlinetech.com/)

- [Home](http://onlinetech.com/)
- [Colocation](http://onlinetech.com/colocation/overview) 
    - [Overview](http://onlinetech.com/colocation/overview)
    - [Locations](http://onlinetech.com/colocation/locations)
    - [Packages](http://onlinetech.com/colocation/packages)
    - [Features](http://onlinetech.com/colocation/features)
    - [Resources](http://onlinetech.com/colocation/resources)
    - [Quote](http://onlinetech.com/colocation/quote)
    - [Rack and Stack](http://onlinetech.com/colocation/rack-and-stack)
- [Managed Servers](http://onlinetech.com/managed-dedicated-servers/overview) 
    - [Overview](http://onlinetech.com/managed-dedicated-servers/overview)
    - [Packages](http://onlinetech.com/managed-dedicated-servers/overview)
    - [Features](http://onlinetech.com/managed-dedicated-servers/features)
    - [Resources](http://onlinetech.com/managed-dedicated-servers/resources)
    - [Quote](http://onlinetech.com/managed-dedicated-servers/quote)
- [Cloud](http://onlinetech.com/cloud-computing-hosting/overview) 
    - [Overview](http://onlinetech.com/cloud-computing-hosting/overview)
    - [Packages](http://onlinetech.com/cloud-computing-hosting/packages)
    - [Features](http://onlinetech.com/cloud-computing-hosting/features)
    - [Resources](http://onlinetech.com/cloud-computing-hosting/resources)
    - [Quote](http://onlinetech.com/cloud-computing-hosting/quote)
- [Managed Services](http://onlinetech.com/managed-services/overview) 
    - [Overview](http://onlinetech.com/managed-services/overview)
    - [IT Disaster Recovery](http://onlinetech.com/managed-services/it-disaster-recovery)
    - [Offsite Backup](http://onlinetech.com/managed-services/offsite-backup)
    - [OTMonitor](http://onlinetech.com/managed-services/remote-server-monitoring)
    - [OTManage](http://onlinetech.com/managed-services/colocation-management)
    - [OTPortal](http://onlinetech.com/managed-services/client-hosting-portal)
    - [Managed SAN Hosting](http://onlinetech.com/managed-services/managed-san-hosting)
- [Compliant Hosting](http://onlinetech.com/compliant-hosting/overview) 
    - [Overview](http://onlinetech.com/compliant-hosting/overview)
    - [PCI Compliant Hosting](http://onlinetech.com/compliant-hosting/pci-compliant-hosting/overview)
    - [HIPAA Compliant Hosting](http://onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview)
    - [SOX Compliant Hosting](http://onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting)
    - [Safe Harbor Compliant Hosting](http://onlinetech.com/compliant-hosting/safe-harbor-compliant-hosting)
    - [Quote](http://onlinetech.com/compliant-hosting/quote)
- [Secure Hosting](http://onlinetech.com/secure-hosting/overview) 
    - [Overview](http://onlinetech.com/secure-hosting/overview)
    - [Technical Security](http://onlinetech.com/secure-hosting/technical-security)
    - [Physical Security](http://onlinetech.com/secure-hosting/physical-security)
    - [Administrative Security](http://onlinetech.com/secure-hosting/administrative-security)
    - [Defense in Depth](http://onlinetech.com/secure-hosting/defense-in-depth)

# OT Blog

We are a community of IT professionals.

[![mobile-securtiy-whitepaper-banner-module-graphic](https://web.otava.com/hs-fs/file-1200369117-png/Images/mobile-securtiy-whitepaper-banner-module-graphic.png "mobile-securtiy-whitepaper-banner-module-graphic")](http://www.onlinetech.com/resources/white-papers/mobile-security)

- [![Overview](https://web.otava.com/hs-fs/file-1200848795-png/Images/icon_newsletter.png)All Posts](http://resource.onlinetech.com)
- [![Quote](https://web.otava.com/hs-fs/file-1194859824-png/Images/icon_hipaa.png)HIPAA Compliance](http://resource.onlinetech.com/category/hipaa-compliance-2/)
- [![Locations](https://web.otava.com/hs-fs/file-1200954737-png/Images/icon_pci.png)PCI Compliance](http://resource.onlinetech.com/category/pci-compliance-2/)
- [![Features](https://web.otava.com/hs-fs/file-1200893870-png/Images/icon_cloud.png)Cloud Computing](http://resource.onlinetech.com/category/cloud-computing/)
- [![Resources](https://web.otava.com/hs-fs/file-1200893840-png/Images/icon_disaster_recovery.png)Disaster Recovery](http://resource.onlinetech.com/category/disaster-recovery-trends/)
- [![CEO Voices](https://web.otava.com/hs-fs/file-1200893845-png/Images/icon_the_team.png)CEO Voices](http://resource.onlinetech.com/category/ceo-voices)
- [![Data Centers](https://web.otava.com/hs-fs/file-1194859849-png/Images/icon_data_centers.png)Data Centers](http://resource.onlinetech.com/category/data-centers)

## [HIPAA Glossary of terms](https://web.otava.com/blog/hipaa-glossary-of-terms)

 Posted on [July 31, 2014](https://web.otava.com/blog/hipaa-glossary-of-terms) by [April Sage](https://web.otava.com/blog/author/april-sage)

[![](https://web.otava.com/hs-fs/hub/390445/file-1353693624.png)](https://web.otava.com/blog/hipaa-glossary-of-terms)

It's a jungle out there in healthcare, and we want to make sure you have the info you need to cut through some of the jargon. Here's a comprehensive glossary of basic HIPAA terms to define the key phrases you need to understand HIPAA compliance today.

**Business Associates**  
Anyone who has access to patient information, whether directly, indirectly, physically or virtually. Additionally, any organization that provides support in the treatment, payment or operations is considered a business associate, i.e. an IT company or a billing and claims processing company. Other examples include a document destruction company, a telephone service provider, accountant or lawyer. The business associates also have the responsibility to achieve and maintain HIPAA compliance in terms of all of the internal, administrative and technical safeguards. A business associate does not work under the covered entity’s workforce, but instead performs some type of service on their behalf.

**Business Associate Agreement**  
The agreement standard document that clearly defines the roles and responsibilities of a business associate and the covered entity. The other key piece of the Business Associates Agreement is the assurance that businesses will take proper steps to implement the appropriate administrative, physical and technical safeguards.

**Covered Entities (CE)**  
Anyone who provides treatment, payment and operations in healthcare. It could include a doctor’s office, dental office, clinics, psychologist, nursing home, pharmacy, hospital or home healthcare agency. This also includes health plans, health insurance companies, HMOs, company health plans and government programs that pay for health care. Health clearing houses are also considered covered entities.

[![Read Blog: HIPAA FAQ](https://no-cache.hubspot.com/cta/default/390445/dcf869fd-631c-482b-8e80-258257eefea0.png)](https://cta-redirect.hubspot.com/cta/redirect/390445/dcf869fd-631c-482b-8e80-258257eefea0)

**Electronic Data Interchange (EDI)**   
The communication or exchange of business documents between companies via computer.

**Electronic Health Records (EHR)**  
Electronic health records are any electronic record of patient health information generated within a clinical institution or environment, such as a hospital or doctor’s office. This may include medical history, laboratory results, immunizations, demographics, etc.

**Electronic Protected Health Information (EPHI)**  
All individually identifiable health information that is created, maintained or transmitted electronically.

**Healthcare Clearinghouse**  
An organization that standardizes health information. One example is a billing company that processes data from its initial format into a standardized billing format.

**Health Information**  
Patient information collected by a health plan, health care provider, public health authority, employer, healthcare clearinghouse or other organization that falls under covered entity.

**Healthcare Insurance Portability and Accountability Act (HIPAA)**  
Developed in 1996, the acronym HIPAA stands for Healthcare Insurance Portability and Accountability Act. Initially created to help the public with insurance portability, they eventually built administrative simplifications that involved electronic, medical record technology and other components. In addition, they built a series of privacy tools to protect healthcare data.

**Health Information Technology for Economic and Clinical Health (HITECH)**  
In 2009, as part of the American Recovery and Reinvestment Act (ARRA), there was an act within that called HITECH, short for The Health Information Technology for Economic and Clinical Health Act. The act included incentives offered to physicians in private practices, as well as institutional practices to implement and adopt electronic medical records.

In addition to incentives, the act included a series of fines to help enforce HIPAA rules. HITECH also mandated that business associates of covered entities, as well as the covered entities themselves, were responsible for the same level of HIPAA compliance.

**HIPAA Audit**  
A HIPAA audit is based off a set of regulations, standards and implementation specifications. The audit is an analysis that helps to pinpoint the organization’s current state and what steps need to be taken to get the organization compliant.

An evaluation is part of the audit - a company must perform an evaluation and undergo periodic evaluations once a year at minimum. As technology changes, different components are added to an organization’s infrastructure and they should be re-evaluated.

While covered entities need to undergo HIPAA audits, third-party business associates also need to comply. This includes any company that might provide services for a covered entity, for example, an application hosted in a cloud and provided to a covered entity.

**HIPAA Violations**  
If a company fails to comply with HIPAA rules, they are subject to both civil and criminal penalties.

**Civil Penalties**  
Established by the American Recovery and Reinvestment Act of 2009 (ARRA), the tiered civil penalty structure below determines the cause and consequences of the HIPAA breaches. The Secretary of the Department of Health and Human Services has the ability to ultimately determine fines and penalties due to the extent of the violation on a case-by-case basis.

**Due Diligence**  
An organization is in violation, but they have taken every possible step they could have foreseen to prevent that.   
*Minimum fine*: $100 per incident with annual maximum of $25,000 for repeat violations   
*Maximum fine*: $50,000 per violation with annual maximum of $1.5 million for repeat violations

**Reasonable Cause**  
The steps have been taken, but something was not addressed. For example, a company went into a HIPAA audit and provided a gap analysis, but something wasn’t addressed yet. The violation is due to reasonable cause and not willful neglect.   
*Minimum fine*: $1,000 per incident with annual maximum of $100,000 for repeat violations   
*Maximum fine*: $50,000 per incident with annual maximum of $1.5 million for repeat violations

**Willful Neglect**  
There are two types of willful neglect. The first is when a company clearly ignores the HIPAA law but corrects their mistake within the given amount of time.   
*Minimum fine*: $10,000 per incident with annual maximum of $1.5 million for repeat violations   
*Maximum fine*: $50,000 per violation with annual maximum of $1.5 million for repeat violations

The second type of willful neglect is when a company ignores the HIPAA law and does not correct their mistake.   
*Minimum fine*: $50,000 per incident with annual maximum of $1.5 million for repeat violations   
*Maximum fine*: $50,000 per incident with annual maximum of $1.5 million for repeat violations

**Criminal Penalties**  
The U.S. Department of Justice established who can be held liable for HIPAA violations due to criminal activity. This includes covered entities and any specified individual working under a covered entity. Anyone who knowingly misuses health information can be fined up to $50,000 including up to a year of imprisonment. More serious offenses call for higher fines and prison time.

**Individually Identifiable Health Information**  
A subset of health information, this includes demographic information about an individual’s health that identifies or can be used to identify the individual. This includes name, address, date of birth, etc.

**OCR HIPAA Audit Protocol**  
Up through early 2012, there was no federal standard for third-party auditors to conduct a HIPAA audit. With the publication of the new Office for Civil Rights audit protocol, auditors are able to gain a more consistent direction on how the OCR will conduct HIPAA audits in the future. The new protocol covers requirements found in the HIPAA Security Rule, Privacy Rule and Breach Notification Rule. Read more [here](http://resource.onlinetech.com/the-hipaa-police-are-on-their-way/).

**Privacy Rule**  
The part of the HIPAA rule that addresses the saving, accessing and sharing of medical and personal information of an individual, including a patient’s own right to access.

[![New Call-to-action](https://no-cache.hubspot.com/cta/default/390445/c64ad3bb-746e-4c42-8439-882a317e87de.png)](https://cta-redirect.hubspot.com/cta/redirect/390445/c64ad3bb-746e-4c42-8439-882a317e87de)

 

 

**Protected Health Information (PHI)**  
This includes any individually identifiable health information collected from an individual by a healthcare provider, employer or plan that includes name, social security number, phone number, medical history, current medical condition, test results and more.

**Security Rule**  
The part of the HIPAA rule that outlines national security standards intended to protect health data created, received, maintained or transmitted electronically.

Resources:

[HIPAA Enforcement Rule](http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/enfifr.pdf)

 

[Read More](https://web.otava.com/blog/hipaa-glossary-of-terms)

- [Tweet](https://twitter.com/share)

 Posted in [HIPAA](https://web.otava.com/blog/topic/hipaa)

## [Up your HIPAA Compliance IQ with a little HIPAA FAQ](https://web.otava.com/blog/up-your-hipaa-compliance-iq-with-a-little-hipaa-faq)

 Posted on [July 24, 2014](https://web.otava.com/blog/up-your-hipaa-compliance-iq-with-a-little-hipaa-faq) by [April Sage](https://web.otava.com/blog/author/april-sage)

[![](https://web.otava.com/hs-fs/hub/390445/file-1318364585.jpg)](https://web.otava.com/blog/up-your-hipaa-compliance-iq-with-a-little-hipaa-faq)

Are you wondering what all the HIPAA fuss is about? Here are a few basics go get you started, along with some reference to in-depth videos along the way.

[Read More](https://web.otava.com/blog/up-your-hipaa-compliance-iq-with-a-little-hipaa-faq)

- [Tweet](https://twitter.com/share)

 Posted in [HIPAA](https://web.otava.com/blog/topic/hipaa)

[All posts](https://web.otava.com/blog/all)

### Follow Us

<https://www.youtube.com/user/OnlineTechDataCenter?sub_confirmation=1><https://twitter.com/OtavaLLC><https://www.linkedin.com/company/14060381>

### White Papers

 View a list of our [white papers](http://www.onlinetech.com/resources/white-papers):

- [Encryption of Cloud Data](http://www.onlinetech.com/resources/white-papers/encryption-of-cloud-data)
- [HIPAA Compliant Hosting](http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers)
- [PCI Compliant Hosting](http://www.onlinetech.com/resources/white-papers/pci-compliant-data-centers)
- [Disaster Recovery](http://www.onlinetech.com/resources/white-papers/disaster-recovery)
- [Mobile Security](http://www.onlinetech.com/resources/white-papers/mobile-security)

Search for:

### Want to stay informed on all things Online Tech?

Sign up to receive compliant and secure hosting resources now!

View our [Privacy Policy](http://www.onlinetech.com/site-resources/privacy-policy).

### Subscribe to Email Updates

### Informative Videos

[![Data Center Carbon Footprint](http://i.ytimg.com/vi/RlGuz4HURkc/hqdefault.jpg) Data Center Industry Lowers Carbon Footprint: Watch Video»](http://www.onlinetech.com/resources/wiki/data-centers/how-the-data-center-industry-lowers-the-carbon-footprint) [![Mobile Data Centers](http://i.ytimg.com/vi/2egqPGQrmKY/hqdefault.jpg) Mobile Data Centers: Watch Video »](http://www.onlinetech.com/resources/wiki/data-centers/after-the-cloud-what-next-mobile-technology-in-data-centers) [![Private Cloud](http://i.ytimg.com/vi/B0GwEDGCF6Y/hqdefault.jpg) Switch to the Private Cloud: Watch Video »](http://www.onlinetech.com/resources/wiki/data-centers/the-big-switch-to-managed-services-and-private-cloud)

### Categories

- [Cybersecurity (5)](https://web.otava.com/blog/topic/cybersecurity)
- [General IT (3)](https://web.otava.com/blog/topic/general-it)
- [HIPAA (2)](https://web.otava.com/blog/topic/hipaa)
- [Audits (1)](https://web.otava.com/blog/topic/audits)

### About Online Tech

[Online Tech](http://www.onlinetech.com/) is the leader in [secure, compliant hosting services](http://www.onlinetech.com/compliant-hosting/overview) including [private cloud hosting](http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud), [managed cloud hosting](http://www.onlinetech.com/cloud-computing-hosting/packages/managed-cloud), [hybrid cloud hosting](http://www.onlinetech.com/cloud-computing-hosting/packages/hybrid-cloud-hosting), [managed dedicated servers](http://www.onlinetech.com/managed-dedicated-servers/packages/basic-managed-server), [disaster recovery](http://www.onlinetech.com/managed-services/it-disaster-recovery/it-disaster-recovery-case-studies), [offsite backup](http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup) services, and [Michigan colocation.](http://www.onlinetech.com/colocation/overview)

Online Tech’s Midwest data centers assure mission critical applications are always available, comply with government & industry regulations, and continue operating after a disaster.

Backed by independent [HIPAA](http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview), [PCI](http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview), [SAS 70](http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting), [SSAE 16](http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting), [SOC 2](http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting), and [SOC 3](http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/soc-3-hosting) audits, Online Tech delivers the security, privacy, and availability expected from world class data center operators.

For more information, call (734) 213-2020 or email [contactus@onlinetech.com](mailto:contactus@onlinetech.com).

- [![footer_dell_logo](https://web.otava.com/hs-fs/file-1193999208-gif/Images/img_trans.gif?width=30&height=30&name=img_trans.gif)](http://onlinetech.com/company/online-tech-partners)
- [![footer_fortinet_logo](https://web.otava.com/hs-fs/file-1193999208-gif/Images/img_trans.gif?width=126&height=15&name=img_trans.gif)](http://onlinetech.com/company/online-tech-partners)
- [![Managed VMware Logo](https://web.otava.com/hs-fs/file-1193999208-gif/Images/img_trans.gif?width=115&height=30&name=img_trans.gif)](http://onlinetech.com/company/online-tech-partners)
- [![RedHat Dedicated Server Logo](https://web.otava.com/hs-fs/file-1193999208-gif/Images/img_trans.gif?width=30&height=30&name=img_trans.gif)](http://onlinetech.com/company/online-tech-partners)
- [![CentOS Dedicated Server Logo](https://web.otava.com/hs-fs/file-1193999208-gif/Images/img_trans.gif?width=115&height=30&name=img_trans.gif)](http://www.onlinetech.com/company/online-tech-partners)
- [![Microsoft Logo](https://web.otava.com/hs-fs/file-1193999208-gif/Images/img_trans.gif?width=115&height=30&name=img_trans.gif)](http://onlinetech.com/company/online-tech-partners)
- [![Cisco Logo](https://web.otava.com/hs-fs/file-1193999208-gif/Images/img_trans.gif?width=49&height=30&name=img_trans.gif)](http://onlinetech.com/company/online-tech-partners)

## [Colocation](http://onlinetech.com/colocation/overview)

- [Overview](http://www.onlinetech.com/colocation/overview)
- [Locations](http://www.onlinetech.com/colocation/locations)
- [Packages](http://www.onlinetech.com/colocation/packages)
- [Features](http://www.onlinetech.com/colocation/features)
- [Resources](http://www.onlinetech.com/colocation/resources)
- [Quote](http://www.onlinetech.com/colocation/quote)

## [Managed Servers](http://onlinetech.com/managed-dedicated-servers/overview)

- [Overview](http://onlinetech.com/managed-dedicated-servers/overview)
- [Packages](http://onlinetech.com/managed-dedicated-servers/packages)
- [Features](http://onlinetech.com/managed-dedicated-servers/features)
- [Resources](http://onlinetech.com/managed-dedicated-servers/resources)
- [Quote](http://onlinetech.com/managed-dedicated-servers/quote)

## [Cloud Hosting](http://onlinetech.com/cloud-computing-hosting/overview)

- [Overview](http://onlinetech.com/cloud-computing-hosting/overview)
- [Packages](http://onlinetech.com/cloud-computing-hosting/packages)
- [Features](http://onlinetech.com/cloud-computing-hosting/features)
- [Resources](http://onlinetech.com/cloud-computing-hosting/resources)
- [Quote](http://onlinetech.com/cloud-computing-hosting/quote)

## [Managed Services](http://onlinetech.com/managed-services/overview)

- [Overview](http://www.onlinetech.com/managed-services/overview)
- [IT Disaster Recovery](http://www.onlinetech.com/managed-services/it-disaster-recovery)
- [OTMonitor](http://www.onlinetech.com/managed-services/remote-server-monitoring)
- [OTManage](http://www.onlinetech.com/managed-services/colocation-management)
- [OTPortal](http://www.onlinetech.com/managed-services/client-hosting-portal)
- [Rack and Stack](http://www.onlinetech.com/managed-services/rack-and-stack)
- [Managed SAN Hosting](http://www.onlinetech.com/managed-services/managed-san-hosting)

## [Secure Hosting](http://onlinetech.com/compliant-hosting/overview)

- [Overview](http://www.onlinetech.com/secure-hosting/overview)
- [PCI Compliant Hosting](http://www.onlinetech.com/secure-hosting/pci-compliant-hosting)
- [HIPAA Compliant Hosting](http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview)
- [SOX Compliant Hosting](http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting)
- [Quote](http://www.onlinetech.com/secure-hosting/quote)

## [Site Resources](http://onlinetech.com/site-resources/overview)

- [Overview](http://onlinetech.com/site-resources/overview)
- [Sitemap](http://onlinetech.com/site-resources/sitemap)
- [Legal Notices](http://onlinetech.com/site-resources/legal-notices)
- [Rules of Use](http://onlinetech.com/site-resources/rulesofuse)
- [Acceptable Use Policy](http://onlinetech.com/site-resources/aup)
- [Privacy Policy](http://onlinetech.com/site-resources/privacy-policy)

Copyright 2012 Online Tech. All Rights Reserved.