Health Data
Privacy
Data relating to an individualโs physical or mental health, healthcare services, or status; often regulated and high-risk.
Glossary
Plain-language explanations for encryption, tracking, compliance, and security concepts.
Privacy
Data relating to an individualโs physical or mental health, healthcare services, or status; often regulated and high-risk.
Privacy
US Health Insurance Portability and Accountability Act privacy/security rules for PHI.
Encryption
Cryptographic schemes enabling computation on ciphertexts such that decrypted results match operations on plaintexts.
Encryption
Tamper-resistant hardware for secure key generation, storage, and cryptographic operations with strict controls and audit.
Web Security
HTTP Strict Transport Security header instructing browsers to enforce HTTPS and reject downgrade.
Web Security
Cookie flag preventing client-side scripts from accessing the cookie; mitigates some XSS cookie theft.
Networking
HTTP over TLS with certificate-based authentication.
Authentication
System that authenticates users and issues tokens/assertions to relying parties (SSO).
Threats
Fraudulent use of personal identifiers to impersonate a victim.
Data Management
Backup configuration preventing modification/deletion (WORM/retention locks) for a defined retention period.
Security
Coordinated process for detecting, containing, and remediating incidents.
Privacy
Reduced local persistence of browsing state.
Data Management
Framework of policies, roles, and controls for managing information lifecycle and compliance.
Security
Discipline and control set ensuring confidentiality, integrity, and availability (CIA).
Security
Detection system analyzing traffic/logs to identify threats; provides alerts rather than blocking.
Networking
Numeric identifier for network routing.
Networking
Retention of IP addresses and related metadata.
Privacy
Legal authority of a territory over entities, activities, and data processing.
Privacy
Strategic selection of legal regimes to influence regulatory exposure and obligations.
Session Management
Signed token format (often used as bearer tokens) carrying claims like issuer, subject, audience, and expiry.
Anonymization
Privacy model where each record is indistinguishable from at least kโ1 others on quasi-identifiers.
Encryption
Lifecycle control for cryptographic keys.
Encryption
Periodic replacement of cryptographic keys.
Encryption
Managed key/secret storage providing access control, audit trails, versioning, and sometimes HSM-backed protection.