Start with Identity
← Glossary
Compliance

HIPAA

Health Insurance Portability and Accountability Act. US law governing the privacy and security of protected health information. Identity vendors serving healthcare must sign Business Associate Agreements and meet the Security Rule's access controls.

For identity teams HIPAA translates into concrete controls: unique user identification, automatic logoff, audit controls over PHI access, and emergency access procedures. The access-log requirement is the one that drives architecture, because "who viewed this record and why" has to be answerable years later. Vendors handling PHI need a Business Associate Agreement, which is a procurement gate before it is a technical one.

See also: compliance guides, access certification, break-glass, healthcare identity vertical

Last reviewed By SWI Community TeamSuggest a correctionHow we research