{"id":99896,"date":"2025-01-08T12:21:20","date_gmt":"2025-01-08T10:21:20","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?post_type=glossary&#038;p=99896"},"modified":"2025-12-17T15:28:39","modified_gmt":"2025-12-17T13:28:39","slug":"what-is-hipaa","status":"publish","type":"glossary","link":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/","title":{"rendered":"What is HIPAA?"},"content":{"rendered":"<p>HIPAA, short for the Health Insurance Portability and Accountability Act, is a U.S. federal law designed to protect sensitive healthcare data. Although the law does not mandate specific cybersecurity practices or tools related to how software systems collect, store, process or transmit healthcare data, it does define security and privacy goals and outcomes that businesses must uphold to remain HIPAA-compliant.<\/p>\n\n\n\n<p>Healthcare systems often store highly sensitive data \u2013 including not just personally identifiable information (PII) about patients, but also private patient medical data such as health histories. What\u2019s more, healthcare data has a tendency to move around frequently. To deliver effective care, healthcare providers often need to correlate a patient\u2019s health data from across multiple systems, or share it with one other.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-1024x512.jpg\" alt=\"NIST CSF HIPAA Glossary \n\" class=\"wp-image-87308\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-1024x512.jpg 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-300x150.jpg 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-768x384.jpg 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02.jpg 1250w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>For these reasons, healthcare data creates something of a perfect storm when it comes to data privacy: It involves data that is highly sensitive, and that can easily fall into the wrong hands during the process of moving from one system to another.<\/p>\n\n\n\n<p>HIPAA aims to address these challenges by mandating consistent, efficient and secure modes of storing and transmitting healthcare data. To comply with U.S. federal law, most businesses that manage healthcare data for U.S. residents \u2013 including companies not based in the U.S. \u2013 must adhere to HIPAA\u2019s requirements.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">The purpose of HIPAA<\/h2>\n\n\n\n<p>Enacted in 1996, HIPAA establishes a number of requirements and regulations that businesses must follow when working with protected healthcare information. The purpose of the law is to provide a standardized and secure way of storing and sharing healthcare data.<\/p>\n\n\n\n<p>HIPAA emerged out of a recognition that the healthcare industry in the United States lacked an efficient and secure approach to managing health data because different healthcare providers, insurance companies and other entities managed the data in varying ways. By standardizing the process and imposing security rules, HIPAA aimed to reduce risk and add efficiency \u2013 hence the references to \u201cportability\u201d and \u201caccountability\u201d for healthcare data within the law\u2019s name.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">Who must comply with HIPAA?<\/h2>\n\n\n\n<p>Any business that operates in the U.S. and is defined under HIPAA law as a \u201ccovered entity\u201d must comply with the regulation.<\/p>\n\n\n\n<p>In general, any business that engages in storing, processing or transmitting healthcare data is a covered entity and therefore subject to HIPAA. This includes organizations that manage analog healthcare data as well as healthcare data stored digitally (which HIPAA refers to as \u201celectronic protected health information,\u201d or e-PHI).<\/p>\n\n\n\n<p>Note as well that companies do not need to be based in the U.S., or even have a physical presence there, to be subject to HIPAA compliance. International organizations that store, process or otherwise have access to e-PHI associated with U.S. residents are typically subject to the HIPAA mandates.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">What does HIPAA require?<\/h2>\n\n\n\n<p>HIPAA includes five main rules (which are defined in detail on the <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/laws-regulations\/index.html\">HIPAA website<\/a>):<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<strong>Privacy<\/strong>: Prevents medical records from being shared without patients\u2019 consent.<\/li>\n\n\n\n<li>\n<strong>Security<\/strong>: Requires reasonable security measures to be in place to protect against unauthorized access to healthcare data.<\/li>\n\n\n\n<li>\n<strong>Transaction<\/strong>: Standardizes the way healthcare data is transmitted between systems.<\/li>\n\n\n\n<li>\n<strong>Identifiers<\/strong>: Defines standards for identifying healthcare entities.<\/li>\n\n\n\n<li>\n<strong>Enforcement<\/strong>: Describes the enforcement process and establishes penalties for non-compliance.<\/li>\n<\/ul>\n\n\n\n<p>In the context of cybersecurity and data privacy, the Privacy and Security rules are the most important because they describe regulations that are relevant for securing data inside digital systems.<\/p>\n\n\n<script src=\"https:\/\/player.vimeo.com\/api\/player.js\"><\/script>\n<script src=\"https:\/\/www.youtube.com\/iframe_api\"><\/script>\n<div class=\"aticle-video-wrapper\">\n    <p class=\"section-description-top\">Ensure Compliance <\/p>    <h3>Generate SBOMs Automatically with Checkmarx SBoM<\/h3>\n    <div class=\"aticle-video-box\">\n                    <pre><\/pre>\n                        <iframe id=\"vimeoPlayer\" allowfullscreen title=\"vimeo Video Player\" src=\"https:\/\/player.vimeo.com\/video\/1138848546?badge=0&#038;autopause=0&#038;player_id=0&#038;app_id=58479%22&#038;autoplay=0&#038;loop=1?color&amp;muted=1&amp;title=1&amp;portrait=1&amp;byline=1&amp;h=b8faf3a510#t=\"><\/iframe>\n                <\/div>\n    <p>With Checkmarx SBOM you can automatically generate SBOMs on your behalf, saving you time and headache in ensuring you have an up-to-date inventory of 3rd party packages being used within your software projects.<\/p>\n            <a href=\"https:\/\/checkmarx.com\/product\/sbom\/\" class=\"btn btn-2 btn-bg accent demo\">Discover Checkmarx SBOM<\/a>\n        <\/div>\n<script>\n    \/\/ For youtube video only\n    var playerReady = false;\n    var player;\n\n    function onYouTubeIframeAPIReady() {\n        const iframe = document.querySelector('iframe.youtube-player');\n        if (!iframe) {\n            console.warn('Youtube player not found');\n            return;\n        }\n\n        player = new YT.Player(iframe, {\n            events: {\n                onReady: () => {\n                    playerReady = true;\n                }\n            }\n        });\n    }\n\n\n    document.addEventListener('DOMContentLoaded', () => {\n        let videoBtn = document.querySelector('.youtube-overlay-image-link');\n\n        if (!videoBtn) return;\n\n\n        videoBtn.addEventListener('click', (e) => {\n            e.preventDefault();\n            videoBtn.style.display = 'none';\n\n            if (!player || !playerReady) {\n                console.warn('The player isn\\'t ready yet');\n                return;\n            }\n\n            player.playVideo();\n\n        })\n    })\n<\/script>\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">HIPAA challenges<\/h2>\n\n\n\n<p>Unfortunately, the Privacy and Security HIPAA rules can also be somewhat difficult for cybersecurity teams to interpret. That is because HIPAA lays out high-level requirements but doesn\u2019t describe exactly how to achieve them.<\/p>\n\n\n\n<p>For example, the Security rule states in part that businesses must ensure the integrity, availability, and confidentiality of all e-PHI they create, maintain, transmit or receive. But it doesn\u2019t describe precisely which types of security controls, tools or processes businesses must implement to meet this requirement.<\/p>\n\n\n\n<p>This lack of precision is unavoidable because technology is always changing, as are cybersecurity and data privacy threats \u2013 so strategies that represent best practices one year may cease to be sufficient for protecting healthcare data or preventing breaches the next. Indeed, given that HIPAA was enacted in 1996, there was no way that the law\u2019s designers could have foreseen modern <a href=\"https:\/\/checkmarx.com\/learn\/code-to-cloud-security\/the-ultimate-guide-to-code-to-cloud-security\/\">cloud security<\/a> challenges, given that the cloud as we know it did not exist in the 1990s.<\/p>\n\n\n\n<p>Nonetheless, HIPAA places the onus on organizations to interpret its rules and enforce them in a way that regulators deem adequate. This includes implementing tools and processes \u2013 such as zero-trust security policies, continuous <a href=\"https:\/\/checkmarx.com\/glossary\/why-vulnerability-scanning-is-critical-for-companies\/\">vulnerability scanning<\/a> and security monitoring \u2013 that can help to mitigate the risk of breaches and, in the event they do occur, help businesses to identify and remediate them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\">Best practices for HIPAA compliance<\/h2>\n\n\n\n<p>To minimize the risk of HIPAA non-compliance, consider the following security and data privacy best practices:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<strong>Minimize data exposure<\/strong>: The less e-PHI data you transmit or store, the lower your risk of security events that could affect HIPAA compliance. In general, it\u2019s a best practice to avoid allowing applications and systems to interact with HIPAA-regulated data unless necessary.<\/li>\n\n\n\n<li>\n<strong>Encrypt data<\/strong>: While simply encrypting data is not enough on its own to guarantee HIPAA compliance, data encryption can help reduce the risk of unauthorized access.<\/li>\n\n\n\n<li>\n<strong>Embrace least privilege<\/strong>: Least privilege \u2013 the practice of granting users only the minimum access rights necessary \u2013 helps prevent data breaches linked to malicious insiders or stolen access credentials.<\/li>\n\n\n\n<li>\n<strong>Perform recurring audits<\/strong>: Audits allow you to detect cybersecurity shortcomings that could trigger HIPAA non-compliance.<\/li>\n\n\n\n<li>\n<strong>Educate employees<\/strong>: No matter how many security controls or automations you deploy, you can\u2019t guarantee that employees won\u2019t place sensitive health data at risk. Educating workers on where and how they can use protected data helps prevent HIPAA compliance violations.<\/li>\n<\/ul>\n\n\n\n<section class=\"section-accordion\" id=\"FAQ\">\n    <div class=\"main-wrapper section-accordion__wrapper\">\n        <h2 class=\"section-title article-anchor\" id=\"article-anchor-6\">HIPAA Compliance FAQ<\/h2>\n        <div class=\"fag-accordion__wrapper\">\n            <div class=\"js-accordion fag-accordion\">\n                <div>\n\n                                            <div class=\"js-accordion__item fag-accordion__item \">\n                            <h3 class=\"js-accordion__btn fag-accordion__btn\">\n                                <svg width=\"34px\" height=\"23px\" viewbox=\"0 0 34 23\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                                    <g id=\"Page-1\" stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\">\n                                        <g id=\"Shape\" transform=\"translate(0.939453, 1.530000)\" stroke-width=\"3\">\n                                            <path d=\"M19.810947,20.4179 L31.029947,9.14 M30.029947,10.1989 L0,10.1989 M31.029947,11.26 L19.810947,0\"><\/path>\n                                        <\/g>\n                                    <\/g>\n                                <\/svg>\n                                What are the 5 main rules of HIPAA?                            <\/h3>\n                            <div class=\"js-accordion-content fag-accordion__content\">\n                                <ul class=\"i8Z77e\">\n<li class=\"TrT0Xe\">Privacy Rule. The HIPAA Privacy Rule sets the federal standard for protecting patient PHI. &#8230;<\/li>\n<li class=\"TrT0Xe\">Security Rule. The HIPAA Security Rule sets the federal standard for managing a patient&#8217;s ePHI. &#8230;<\/li>\n<li class=\"TrT0Xe\">Transactions Rule. &#8230;<\/li>\n<li class=\"TrT0Xe\">Unique Identifiers Rule. &#8230;<\/li>\n<li class=\"TrT0Xe\">Enforcement Rule.<\/li>\n<\/ul>\n                            <\/div>\n                        <\/div>\n                        <\/div>\n<div>                <\/div>\n            <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n\n\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"url\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What are the 5 main rules of HIPAA?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Privacy Rule. The HIPAA Privacy Rule sets the federal standard for protecting patient PHI. &#8230;\\nSecurity Rule. The HIPAA Security Rule sets the federal standard for managing a patient&#8217;s ePHI. &#8230;\\nTransactions Rule. &#8230;\\nUnique Identifiers Rule. &#8230;\\nEnforcement Rule.\"}}]}<\/script>\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-7\">HIPAA compliance with Checkmarx<\/h2>\n\n\n\n<p>As a <a href=\"https:\/\/checkmarx.com\/glossary\/what-is-code-to-cloud-security\/\">code-to-cloud security<\/a> platform, Checkmarx provides the broad range of capabilities you need to help protect applications from the vulnerabilities and other risks that could lead to HIPAA violations. Alongside other types of tools \u2013 like Data Loss Prevention (DLP) software, which can help identify where e-PHI resides \u2013 Checkmarx\u2019s application and infrastructure security solutions are one key pillar of a modern HIPAA compliance strategy.<\/p>\n\n\n\n<p>Checkmarx&#8217;s <a href=\"https:\/\/checkmarx.com\/resources\/resource-type\/customer-testimonials\/\">customers <\/a>do business everywhere in the world. Our solutions <a href=\"https:\/\/checkmarx.com\/trust\/\">comply <\/a>with global industry standards and regulations to protect both our business data and yours.<\/p>\n\n\n\n<p><\/p>","protected":false},"excerpt":{"rendered":"<p>HIPAA, short for the Health Insurance Portability and Accountability Act, is a U.S. federal law designed to protect sensitive healthcare data. Although the law does not mandate specific cybersecurity practices or tools related to how software systems collect, store, process or transmit healthcare data, it does define security and privacy goals and outcomes that businesses [&hellip;]<\/p>\n","protected":false},"author":92,"featured_media":0,"template":"","glossary-tags":[],"class_list":["post-99896","glossary","type-glossary","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What is HIPAA? - Checkmarx<\/title>\n<meta name=\"description\" content=\"Understand the HIPAA regulations within the context of DevSecOps. Learn how to ensure compliance and mitigate risks. Click to learn more.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is HIPAA? - Checkmarx\" \/>\n<meta property=\"og:description\" content=\"Understand the HIPAA regulations within the context of DevSecOps. Learn how to ensure compliance and mitigate risks. Click to learn more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-17T13:28:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-1024x512.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/\",\"url\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/\",\"name\":\"What is HIPAA? - Checkmarx\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-1024x512.jpg\",\"datePublished\":\"2025-01-08T10:21:20+00:00\",\"dateModified\":\"2025-12-17T13:28:39+00:00\",\"description\":\"Understand the HIPAA regulations within the context of DevSecOps. Learn how to ensure compliance and mitigate risks. Click to learn more.\",\"breadcrumb\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02.jpg\",\"width\":1250,\"height\":625,\"caption\":\"NIST CSF HIPAA Glossary\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Glossary\",\"item\":\"https:\/\/checkmarx.com\/glossary\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is HIPAA?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is HIPAA? - Checkmarx","description":"Understand the HIPAA regulations within the context of DevSecOps. Learn how to ensure compliance and mitigate risks. Click to learn more.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/","og_locale":"en_US","og_type":"article","og_title":"What is HIPAA? - Checkmarx","og_description":"Understand the HIPAA regulations within the context of DevSecOps. Learn how to ensure compliance and mitigate risks. Click to learn more.","og_url":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_modified_time":"2025-12-17T13:28:39+00:00","og_image":[{"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-1024x512.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_site":"@checkmarx","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/","url":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/","name":"What is HIPAA? - Checkmarx","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02-1024x512.jpg","datePublished":"2025-01-08T10:21:20+00:00","dateModified":"2025-12-17T13:28:39+00:00","description":"Understand the HIPAA regulations within the context of DevSecOps. Learn how to ensure compliance and mitigate risks. Click to learn more.","breadcrumb":{"@id":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Public-Sector-Advocate-Intro-Post-02.jpg","width":1250,"height":625,"caption":"NIST CSF HIPAA Glossary"},{"@type":"BreadcrumbList","@id":"https:\/\/checkmarx.com\/glossary\/what-is-hipaa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Glossary","item":"https:\/\/checkmarx.com\/glossary\/"},{"@type":"ListItem","position":2,"name":"What is HIPAA?"}]},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/99896","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/92"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/99896\/revisions"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=99896"}],"wp:term":[{"taxonomy":"glossary-tags","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary-tags?post=99896"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}