Across
- 2. Covered ___ must comply with HIPAA (e.g., healthcare providers and health plans).
- 5. Federal law governing the privacy and security of health information.
- 8. These must be reported immediately — even if you are not certain a breach occurred.
- 9. Contract signed with third-party vendors who handle PHI on your organization's behalf.
- 11. Method used to scramble data so only authorized users can read it.
Down
- 1. Must never be shared with a coworker — not even if they ask nicely.
- 3. The type of sensitive health information HIPAA is designed to protect.
- 4. Process of removing all personal identifiers so data can no longer be linked to an individual.
- 5. Federal department responsible for enforcing HIPAA rules.
- 6. HIPAA rule that controls who can view or share health information;
- 7. How often all our employees must complete HIPAA training after their initial hire.
- 10. Type of cyberattack simulated by our InfoSec team in January 2026, disguised as a Microsoft 365 Year-End Security Update.
