| Term | Definition |
| HIPAA | Health Insurance Portability and Accountability Act of 1996. |
| HIPAA Privacy Rule | HIPAA required comprehensive health information privacy regulations; the Final HIPAA Privacy Rule was issued August 14, 2002 (requiring compliance by April 14, 2003). |
| PHI | Protected Health Information. PHI is health information created or received by a Covered Entity or an employer that relates to past, present, or future physical or mental health condition, provision of or payment for health care. PHI is any health information that identifies an individual. |
| Covered Entity | Covered Entities under the HIPAA Privacy Rule are Health Care Providers, Health Plans and Health Care Clearinghouses. |
| TPO | TPO is treatment, payment and health care operations. The HIPAA Privacy Rule permits disclosure of PHI only for TPO or when regulatory exception applies (e.g. public health reporting). |
| HIPAA Research Authorization | The Research Authorization required under the HIPAA Privacy Rule is a written patient authorization that must specify:>
|
| De-identified Data | De-identified data excludes all eighteen HIPAA Identifiers. De-identified data is not "anonymous data" under the Common Rule. |
| Common Rule | Seventeen federal departments and agencies agreed to adopt basic human subject protections regulations published in 1991 as the Common Rule. The Common Rule was derived from the first of four subparts of the DHHS regulations for the protection of human subjects. |
| HIPAA Identifiers | The eighteen HIPAA Identifiers are:
|
| Limited Data Set | A limited data set under HIPAA Privacy Rule may not include:
|
| Research | The HIPAA Privacy Rule and the Common Rule have the same definition of research: Systematic investigation, including research development, testing and evaluation designed to develop or contribute to generalizable knowledge (45 CFR 64.10). |
| Notice of Privacy Practices | The HIPAA Privacy Rule requires that a Covered Entity must tell individuals how PHI is used and disclosed. A good faith effort must be made to obtain written acknowledgement of receipt of a Privacy Notice. |
| Minimum Necessary Rule | Covered Entities and their Business Associates must make all reasonable efforts to limit disclosures of PHI to the minimum amount necessary to accomplish the intended purpose. |
| Waiver of HIPAA Research Authorization | Under the Final HIPAA Privacy Rule a Waiver of HIPAA Research Authorization may be granted under the following criteria:
|
| Minimal Risk to Privacy | There is minimal risk to privacy under HIPPA if the following criteria are met:
|
| Business Associates | The HIPAA Privacy Rule also applies Business Associates who are persons or entities that create, use, or disclose PHI to perform or assist in the functions of a Covered Entity. |
| GPP | Good Privacy Practices |
| RAF | Research Authorization Form |
