GRC and HIPAA Glossary

GRC, HIPAA, and Preparedness
Terms, Explained Plainly.

This GRC and HIPAA glossary covers no jargon for the sake of jargon. If a term shows up in compliance, cybersecurity, or emergency preparedness work and it’s confusing, it’s here in plain language.

Built by a paramedic and EMS supervisor with 20+ years in emergency healthcare  ·  B.S. Cybersecurity, Cum Laude  ·  SBA Certified SDVOSB

SBA Service-Disabled Veteran-Owned Certified, GRC and HIPAA glossary provider

HIPAA Terms

PHI (Protected Health Information)

Any health information that can be tied to a specific person, including names, dates, medical records, and billing information. If it identifies a patient and relates to their health or care, it’s PHI. See the HHS Privacy Rule summary for the full legal definition.

Covered Entity

An organization that HIPAA directly applies to, such as a healthcare provider, health plan, or healthcare clearinghouse. EMS agencies are covered entities.

Business Associate

A vendor or third party that handles PHI on behalf of a covered entity, such as a billing company, IT vendor, or consultant. Business associates have their own HIPAA obligations.

BAA (Business Associate Agreement)

A legal contract between a covered entity and a business associate defining how PHI will be protected. If a vendor touches PHI, a BAA should exist.

Security Risk Assessment (SRA)

A required HIPAA process that identifies risks and vulnerabilities to PHI across an organization. Not optional, and not the same as a general IT audit.

Minimum Necessary Standard

The HIPAA principle that only the minimum amount of PHI necessary should be used, disclosed, or requested for a given purpose.

OCR (Office for Civil Rights)

The federal office within HHS responsible for enforcing HIPAA. OCR investigates complaints and breaches, and issues fines for noncompliance.

SOC 2 Terms

Trust Service Criteria (TSC)

The five categories SOC 2 audits are built around: Security, Availability, Confidentiality, Processing Integrity, and Privacy. Every organization is assessed on Security; the other four are scoped based on what applies.

SOC 2 Type I vs Type II

Type I assesses whether controls are designed properly at a single point in time. Type II assesses whether those controls actually operated effectively over a period, typically 6 to 12 months.

Readiness Assessment

A pre-audit review that identifies gaps before engaging an actual auditor, so issues get fixed in advance instead of surfacing during the real audit.

Control Deficiency

A gap where a control either doesn’t exist, isn’t documented, or isn’t operating as intended. The most common thing a readiness assessment finds.

AICPA

The American Institute of Certified Public Accountants, the body that defines the SOC 2 framework and Trust Service Criteria.

GRC and Cybersecurity Terms

GRC (Governance, Risk, and Compliance)

The combined discipline of how an organization is governed, how it identifies and manages risk, and how it meets regulatory and contractual obligations. Not a single tool, a way of running the business.

Risk Register

A living document listing identified risks, their likelihood and impact, and who owns addressing each one. The working tool behind most GRC programs.

NIST CSF (Cybersecurity Framework)

A widely used framework from the National Institute of Standards and Technology, organized around five core functions: Identify, Protect, Detect, Respond, and Recover.

Vendor Risk Management

The process of assessing and monitoring the security risk introduced by third-party vendors who have access to your systems or data.

Incident Response Plan

A documented plan for how an organization detects, responds to, and recovers from a security incident. Required by most frameworks, and useless if never tested.

BEC (Business Email Compromise)

A type of fraud where an attacker compromises or impersonates an email account to redirect payments or extract sensitive information, often targeting finance teams.

Emergency Preparedness Terms

HSEEP (Homeland Security Exercise and Evaluation Program)

The federal standard framework for designing, conducting, and evaluating emergency preparedness exercises, including tabletop exercises.

NIMS (National Incident Management System)

The standardized approach to incident management used across federal, state, and local agencies in the U.S., providing common terminology and structure.

ICS (Incident Command System)

A standardized command structure used to manage emergency response, defining clear roles and reporting lines regardless of incident size or agency involved.

BCP (Business Continuity Plan)

A documented plan for how an organization continues operating during and after a disruption, covering people, processes, and systems.

COOP (Continuity of Operations Plan)

Similar to a BCP but typically used in government and public sector context, focused on maintaining essential functions during an emergency.

Business Impact Analysis (BIA)

A process that identifies which business functions are most critical and how quickly they need to be restored after a disruption. The foundation a BCP is built on.

MCI (Mass Casualty Incident)

An incident where the number of patients exceeds the resources immediately available to treat them, requiring triage and resource prioritization.

Tabletop Exercise Terms

Tabletop Exercise

A discussion-based exercise where participants talk through a simulated scenario to test plans, procedures, and decision-making without physically deploying resources.

Inject

A piece of new information introduced during an exercise to advance the scenario and force participants to respond to changing conditions.

Hot Wash

An immediate, informal debrief held right after an exercise ends, while observations are still fresh, before a formal after action report is written.

AAR (After Action Report)

The formal written document capturing what happened during an exercise, what worked, what didn’t, and what needs to change.

Improvement Plan

A companion document to the AAR that assigns specific corrective actions to specific owners with specific deadlines. Without this, an AAR’s findings rarely get fixed.

Facilitator

The person who runs the exercise, delivers injects, and guides discussion. A skilled facilitator pushes past surface-level answers; a weak one accepts the first thing said.

No-Fault Learning Environment

A ground rule that exercise participants will not be penalized for mistakes made during the simulation, encouraging honest engagement instead of defensive answers.

Ready to Go Further

Now you speak the language of this GRC and HIPAA glossary. Let’s put it to work.

No phone call required. Send a quick email and I’ll respond.

Email Michael

michael@forwardsecuritylabs.com  ·  Direct. No sales team. No handoff.

Forward Security Labs / Forward Career Labs LLC  ·  Wolcott, Connecticut  ·  ForwardSecurityLabs.com  ·  SBA Certified SDVOSB  ·  SAM.gov Registered  ·  CAGE: 1AFL4