HIPAA
Health Insurance Portability and Accountability Act. US law governing the privacy and security of protected health information. Identity vendors serving healthcare must sign Business Associate Agreements and meet the Security Rule's access controls.
For identity teams HIPAA translates into concrete controls: unique user identification, automatic logoff, audit controls over PHI access, and emergency access procedures. The access-log requirement is the one that drives architecture, because "who viewed this record and why" has to be answerable years later. Vendors handling PHI need a Business Associate Agreement, which is a procurement gate before it is a technical one.
See also: compliance guides, access certification, break-glass, healthcare identity vertical
Related on Start with Identity
- GuideIAM Audit Preparation Guide: SOX, SOC 2, and HIPAA Readiness
Prepare for identity and access management audits with complete evidence collection, access review documentation, and compliance frameworks for SOX, SOC 2, and
- GuideIdentity Controls for HIPAA
HIPAA's Security Rule requires safeguards for electronic protected health information (ePHI), and its access-related standards are about identity: who can reach
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include
- GuideCustomer Identity Verification Guide: KYC, Document Verification, and Fraud Prevention
Implement customer identity verification with KYC processes, document verification, liveness detection, progressive profiling, and fraud prevention strategies.
- GlossaryFedRAMP
Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used
- GlossaryGDPR
General Data Protection Regulation. EU privacy law in force since 2018. Establishes user rights (access, rectification, erasure, portability) and obligations on