---
type: CKG Bundle
title: HIPAA Compliance
tags: [Healthcare & Life Sci]
timestamp: 2026-06-18T00:00:00Z
ckg:
  id: hipaa-compliance
  nodes: 75
  license: CC BY 4.0
---

# HIPAA Compliance — Compressed Knowledge Graph

```csv
ConceptID,ConceptLabel,TaxonomyID
1,HIPAA,FOUND
2,Privacy Rule,RULE
3,Security Rule,RULE
4,Breach Notification Rule,RULE
5,Enforcement Rule,RULE
6,HITECH Act,LEGISLATION
7,Protected Health Information,CONCEPT
8,Electronic PHI,CONCEPT
9,De-identified Health Information,CONCEPT
10,Covered Entity,ENTITY_TYPE
11,Healthcare Provider,ENTITY_TYPE
12,Health Plan,ENTITY_TYPE
13,Healthcare Clearinghouse,ENTITY_TYPE
14,Business Associate,ENTITY_TYPE
15,Business Associate Agreement,REQUIREMENT
16,Subcontractor Business Associate,ENTITY_TYPE
17,Minimum Necessary Standard,REQUIREMENT
18,Notice of Privacy Practices,REQUIREMENT
19,Patient Authorization,REQUIREMENT
20,Treatment Payment Operations TPO,PERMITTED_USE
21,Right to Access PHI,PATIENT_RIGHT
22,Right to Amend PHI,PATIENT_RIGHT
23,Right to Accounting of Disclosures,PATIENT_RIGHT
24,Right to Restrict Disclosures,PATIENT_RIGHT
25,Right to Confidential Communications,PATIENT_RIGHT
26,Required Disclosures,PERMITTED_USE
27,Public Health Reporting,PERMITTED_USE
28,Law Enforcement Disclosure,PERMITTED_USE
29,Administrative Safeguards,SECURITY_SAFEGUARD
30,Physical Safeguards,SECURITY_SAFEGUARD
31,Technical Safeguards,SECURITY_SAFEGUARD
32,Risk Analysis,REQUIREMENT
33,Risk Management Plan,REQUIREMENT
34,Workforce Security Training,REQUIREMENT
35,Sanction Policy,REQUIREMENT
36,Access Control Policy,TECHNICAL_CONTROL
37,Audit Controls,TECHNICAL_CONTROL
38,Integrity Controls,TECHNICAL_CONTROL
39,Transmission Security,TECHNICAL_CONTROL
40,Encryption Standard,TECHNICAL_CONTROL
41,Facility Access Controls,PHYSICAL_CONTROL
42,Workstation Security Policy,PHYSICAL_CONTROL
43,Device and Media Controls,PHYSICAL_CONTROL
44,Breach,CONCEPT
45,Unsecured PHI,CONCEPT
46,Breach Risk Assessment,REQUIREMENT
47,Breach Notification to Individual,REQUIREMENT
48,Breach Notification to HHS,REQUIREMENT
49,Breach Notification to Media,REQUIREMENT
50,60-Day Notification Deadline,REQUIREMENT
51,Civil Monetary Penalty Tier 1,PENALTY
52,Civil Monetary Penalty Tier 2,PENALTY
53,Civil Monetary Penalty Tier 3,PENALTY
54,Civil Monetary Penalty Tier 4,PENALTY
55,Criminal Penalty,PENALTY
56,Willful Neglect Uncorrected,PENALTY_CATEGORY
57,Corrective Action Plan,ENFORCEMENT
58,Resolution Agreement,ENFORCEMENT
59,Privacy Officer Role,ROLE
60,Security Officer Role,ROLE
61,HIPAA Audit Program,ENFORCEMENT
62,Business Associate Liability,REQUIREMENT
63,State Attorney General Enforcement,ENFORCEMENT
64,Patient Complaint Process,PROCESS
65,Safe Harbor De-identification Method,METHOD
66,Expert Determination De-identification,METHOD
67,Psychotherapy Notes Special Category,SPECIAL_CATEGORY
68,HIV Status Special Protection,SPECIAL_CATEGORY
69,Substance Use Disorder Records 42 CFR,SPECIAL_CATEGORY
70,Information Blocking Rule,REGULATION
71,Interoperability Requirements,REGULATION
72,EHR Access Requirements,REGULATION
73,FHIR API Standard,TECHNOLOGY
74,Ransomware as Breach,CONCEPT
75,Third-Party Vendor Risk,REQUIREMENT
```

## Edges (prerequisite -> concept)
1 -> 2
1 -> 3
1 -> 4
1 -> 5
1 -> 6
2 -> 7
3 -> 8
7 -> 8
7 -> 9
1 -> 10
10 -> 11
10 -> 12
10 -> 13
10 -> 14
14 -> 15
14 -> 16
2 -> 17
7 -> 17
2 -> 18
2 -> 19
2 -> 20
2 -> 21
2 -> 22
2 -> 23
2 -> 24
2 -> 25
2 -> 26
26 -> 27
26 -> 28
3 -> 29
3 -> 30
3 -> 31
29 -> 32
29 -> 33
32 -> 33
29 -> 34
29 -> 35
34 -> 35
31 -> 36
31 -> 37
31 -> 38
31 -> 39
8 -> 39
39 -> 40
30 -> 41
30 -> 42
30 -> 43
8 -> 43
4 -> 44
7 -> 44
44 -> 45
8 -> 45
44 -> 46
45 -> 46
4 -> 47
44 -> 47
4 -> 48
44 -> 48
4 -> 49
44 -> 49
47 -> 50
48 -> 50
5 -> 51
5 -> 52
5 -> 53
5 -> 54
5 -> 55
54 -> 56
55 -> 56
5 -> 57
51 -> 57
5 -> 58
57 -> 58
10 -> 59
10 -> 60
5 -> 61
14 -> 62
5 -> 62
6 -> 62
5 -> 63
2 -> 64
5 -> 64
9 -> 65
9 -> 66
7 -> 67
19 -> 67
7 -> 68
19 -> 68
7 -> 69
1 -> 70
6 -> 70
70 -> 71
21 -> 72
71 -> 72
72 -> 73
44 -> 74
45 -> 74
14 -> 75
32 -> 75

*Free CKG · Graphify.md · `pip install ckg-mcp` for all · own the knowledge layer, rent the model*
