Skip to content
← Glossary

Entropy scoring & verification

HIPAA

The U.S. Health Insurance Portability and Accountability Act of 1996. Its Privacy and Security Rules set national standards for protecting individuals’ health information, applying to “covered entities” (health plans, most healthcare providers, and healthcare clearinghouses) and the vendors that process health data on their behalf. Narrower applicability than SOC 2/ISO 27001 — relevant mainly to vendors handling health-related data — so Entropy weights it lower. Entropy tracks HIPAA compliance attestation as part of a vendor’s Governance score.

More: When HIPAA does and doesn’t apply

Source: HHS.gov — Summary of the HIPAA Privacy Rule