- ePHI
- Electronic protected health information — the patient data the HIPAA Security Rule protects.
- Business associate and BAA
- A vendor that handles protected health information for a US covered entity, and the agreement that binds it to HIPAA. Indian BPOs are usually business associates.
- HIS / HMS
- The hospital information or management system that runs admissions, billing, wards and pharmacy.
- EMR / EHR
- The patient’s electronic medical or health record — the clinical history clinicians work from.
- PACS and DICOM
- The imaging archive that stores scans, and the standard format and network protocol it uses.
- LIS
- The laboratory information system that manages test orders, samples and results.
- IoMT
- The internet of medical things: infusion pumps, monitors and imaging modalities on the network, often on legacy operating systems.
- Data Fiduciary and Data Processor
- Under the DPDP Act, the organisation that decides why personal data is processed, and the one that processes it on its behalf. A hospital is the fiduciary; its HMS vendor is usually a processor.
- Significant Data Fiduciary
- A fiduciary the government designates for higher risk, with an annual DPIA and audit on top of the ordinary duties.
- Risk analysis (HIPAA)
- The enterprise-wide assessment of risks to ePHI that the Security Rule requires — and the failure OCR penalises most often.
- CERT-In-empanelled auditor
- An auditing firm on CERT-In’s approved list, needed where a regulator or partner requires an empanelled audit.
- Segmentation
- Dividing a network so that a compromise in one zone — the office — cannot reach another, such as clinical devices.