Skip to main content

GLOSSARY

HIPAA

U.S. law setting privacy and security rules for protected health information (PHI).

HIPAA (and its Security/Privacy Rules) governs how covered entities and business associates handle PHI. It requires safeguards, BAAs, breach notifications, and minimum necessary access.

Services touching PHI need HIPAA-aligned controls in addition to general security attestations like SOC 2 or ISO 27001. Encryption, audit logging, and strict access controls are common measures.

← All terms

In the product

Where this term matters in operation.

The glossary is not meant to be academic. It explains the language teams use in Kotao while selling, planning, paying, reporting, and automating.

In sales

Terms like this appear inside POS, checkout, bookings, offers, and customer communication.

In back office

Finance, inventory, HR, and reporting need the same meaning so reports do not drift apart.

In integrations

APIs, imports, webhooks, and exports work better when teams use the same definitions.