Skip to content
Live12+ production solutions40+ clients deployeddirect + partner
Glossary · Compliance & Data

What is HIPAA?

The US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.

Also known as

health insurance portability and accountability acthipaa privacy rulehipaa security rule
Definition

HIPAA — explained.

HIPAA (Health Insurance Portability and Accountability Act, 1996) is the US federal law governing the handling of Protected Health Information (PHI). It applies to 'covered entities' (providers, health plans, clearinghouses) and their 'business associates' (any vendor handling PHI on their behalf). The two operationally important rules are the Privacy Rule (what PHI can be used and disclosed for, patient rights) and the Security Rule (administrative, physical, and technical safeguards for electronic PHI). The Breach Notification Rule requires notification to affected individuals and HHS within 60 days of discovery. Penalties for non-compliance range up to $1.5m per violation per year, with criminal penalties for wilful neglect. For software vendors handling PHI, the practical implications are: signing a Business Associate Agreement (BAA) with the covered entity; implementing the Security Rule's required safeguards (access controls, audit logs, encryption, contingency planning); demonstrating risk assessment; ensuring PHI residency in the US (or under permitted cross-border arrangements). HIPAA is the US analogue to GDPR for healthcare specifically — many Zeour MediCare deployments outside the US still adopt HIPAA-aligned controls as a recognisable benchmark even when not strictly required.

Solutions where hipaa applies

Zeour solutions that operate on this layer.

MediCare Clinic

medicare · clinic · management · system

Zeour MediCare — the multilingual on-premise clinic and EMR management system for small-to-mid healthcare practices. Covers patients (records, allergies, conditions, medications, body diagrams), appointments + visits with SOAP notes, prescriptions with drug-interaction checks, lab orders + samples + results, billing + payments + invoicing, inventory, expenses, referrals, medical certificates, refill requests, patient communications, telemedicine (WebRTC), an AI clinical assistant (OpenAI-powered with 7 modes), a patient self-service portal, and a full role-based access model across Admin, Doctor, Reception, and Lab Tech roles. Engineered multilingual — (with full RTL) as the production baseline, extensible to any locale — and runs locally on a single server.

See the solution

Self-Service Kiosks

digital · self · service · kiosk

Zeour builds bespoke self-service kiosks end-to-end — software and hardware engineered together for the exact service you need to digitize. Self-payment kiosks (utilities, fines, fees, tuition, taxes), self-ordering for restaurants and QSR, charity donation kiosks, airport taxi-booking kiosks, telecom SIM-dispenser kiosks, bank self-service (cash deposit / withdrawal / cheque), KYC kiosks with passport / national ID / face match / fingerprint, tender-participation kiosks for government procurement, utility payment kiosks, government self-service citizen portals, restaurant self-ordering + POS integration, and more. Every deployment is custom-fitted to your operation; every kiosk integrates with your existing systems; every transaction is auditable.

See the solution
Industries where this matters

Verticals where hipaa is operationally critical.

Related terms

Adjacent definitions to read next.

EMR (Electronic Medical Records)

Healthcare & Clinical

A clinic's digital record of every patient encounter — vitals, history, notes, prescriptions, labs, attachments — owned by a single provider.

GDPR

Compliance & Data

The EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.

Data Residency

Sovereign Deployment

A requirement that personal or regulated data is stored, processed, and backed up within a defined jurisdiction — usually a country or a treaty bloc.

Sovereign Deployment

Sovereign Deployment

Software that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.

CCPA / CPRA

Compliance & Data

California's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.

Cyber Essentials

Compliance & Data

The UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.

Data Subject Access Request (DSAR)

Compliance & Data

The data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.

Explicit Consent

Compliance & Data

Consent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.

Want to discuss hipaa for your operation?

Talk to a Zeour engineer.

A 30-minute scoping call to walk your operational profile against where hipaa actually sits in your stack, then a fixed-fee Discovery price by the end of the call.