Healthcare & AI Glossary
Clear definitions of key healthcare technology terms
AES-256 Encryption
The Advanced Encryption Standard with a 256-bit key length, widely considered the gold standard for symmetric encryption in healthcare and government applications. AES-256 is approved by the US National Security Agency (NSA) for protecting classified information up to TOP SECRET level and is mandated or recommended by HIPAA, GDPR, PCI DSS, and most national health data protection frameworks....
Ambient Clinical Scribe
An AI-powered documentation tool that passively listens to the patient-provider conversation during a clinical encounter and automatically generates structured clinical notes (typically SOAP format), diagnostic codes, and follow-up orders. Unlike traditional dictation or manual documentation, ambient scribes require no specific voice commands or templates—the AI understands natural clinical conversation and extracts relevant medical information....
API in Healthcare (Application Programming Interface)
A set of protocols, tools, and definitions that allows different healthcare software systems to communicate with each other programmatically. Healthcare APIs enable EHR data sharing, third-party app integration, patient data access, and cross-system workflow automation without requiring direct database access or custom point-to-point integrations....
Audit Trail
A chronological, tamper-evident record of all system activities, data access events, and user actions that provides accountability and traceability for regulatory compliance and security investigations. In healthcare, audit trails are mandated by HIPAA (Security Rule §164.312), GDPR (Article 30), and most national health data regulations....
BAA (Business Associate Agreement)
A legally binding contract required under HIPAA between a covered entity (healthcare provider, health plan, or healthcare clearinghouse) and a business associate—any organization that creates, receives, maintains, or transmits protected health information (PHI) on behalf of the covered entity. The BAA must specify the permitted uses and disclosures of PHI, require the business associate to implement appropriate safeguards, mandate breach notification, and ensure subcontractors comply with the same requirements....
Capitation
A payment model in which a healthcare provider receives a fixed, predetermined amount per enrolled patient per period (usually monthly), regardless of the number or type of services provided. Capitation shifts financial risk from payers to providers, incentivizing preventive care, efficient resource utilization, and population health management....
Care Coordination
The deliberate organization of patient care activities between two or more participants involved in a patient's care to facilitate the appropriate delivery of healthcare services. Care coordination involves sharing information among all participants concerned with a patient's care, ensuring that the patient's needs and preferences are known and communicated at the right time to the right people....
Care Pathway
A standardized, evidence-based plan that outlines the expected course of treatment for a specific clinical condition, including assessments, interventions, medications, follow-up schedules, and patient education milestones. Care pathways reduce unwarranted clinical variation, ensure guideline adherence, and improve patient outcomes by providing a structured framework that coordinates care across providers and settings....
Charge Capture
The process of recording all billable services, procedures, supplies, and medications provided during a patient encounter to ensure accurate and complete claims submission. Charge capture bridges the gap between clinical documentation and billing—if a service is performed but not captured, the revenue is lost....
Claims Management
The end-to-end process of creating, submitting, tracking, and resolving insurance claims for healthcare services rendered. Claims management includes coding accuracy verification, payer-specific rule compliance, electronic submission (EDI 837), remittance processing (ERA 835), and denial appeal workflows....
Clinical Decision Support System (CDSS)
A health information technology system that provides clinicians with knowledge and patient-specific information, intelligently filtered and presented at the point of care, to enhance clinical decision-making. CDSS encompasses drug-drug and drug-allergy interaction alerts, evidence-based guideline recommendations, diagnostic support, order sets, dosage calculators, and risk scoring models....
Clinical Terminology Mapping
The process of translating clinical concepts between different coding systems and vocabularies—such as SNOMED CT, ICD-10, LOINC, and local national terminologies—so that data recorded in one system retains its clinical meaning when exchanged with another. Terminology mapping is a semantic interoperability requirement: two systems can exchange a FHIR message (structural interoperability) yet still misinterpret the clinical content if their underlying vocabularies are not mapped....
Consent Management
The systematic process of obtaining, recording, managing, and honoring patient consent for data processing, treatment, and information sharing in compliance with applicable regulations. In healthcare, consent management spans clinical consent (informed consent for procedures), data privacy consent (GDPR/HIPAA authorization for data use), research consent (IRB-approved study participation), and marketing consent (communication preferences)....
CPOE (Computerized Provider Order Entry)
A system that allows healthcare providers to enter medical orders—medications, laboratory tests, imaging studies, referrals, and procedures—electronically rather than on paper. CPOE systems integrate with clinical decision support to check for errors, interactions, and guideline compliance at the point of order entry, significantly reducing adverse drug events and transcription errors....
CPT Codes (Current Procedural Terminology)
A standardized coding system maintained by the American Medical Association that describes medical, surgical, and diagnostic services performed by healthcare providers. CPT codes are used for claims submission, reimbursement, and utilization tracking....
Data Residency
The requirement, imposed by law or contract, that certain categories of data be stored and processed within a specific geographic or legal jurisdiction. Many healthcare regulations require patient data to remain within national or regional borders—for example, several EU member states and Gulf countries impose local hosting requirements for health records....
Denial Management
The systematic process of analyzing, appealing, and resolving denied insurance claims while implementing preventive measures to reduce future denials. Effective denial management involves root cause analysis (coding errors, missing information, eligibility issues), timely appeal submission, and pattern identification to address systemic issues....
DICOM (Digital Imaging and Communications in Medicine)
The international standard for handling, storing, printing, and transmitting medical imaging data. DICOM defines file formats and communication protocols for medical images from modalities including X-ray, CT, MRI, ultrasound, and PET scans....
Digital Health
The broad field encompassing the use of digital technologies to improve healthcare delivery, including mobile health (mHealth), telehealth, electronic health records, wearable devices, artificial intelligence, and health information exchange. Digital health transforms how care is delivered, consumed, and managed—enabling remote consultations, continuous monitoring, data-driven clinical decisions, and personalized patient engagement....
DPA (Data Processing Agreement)
A legally binding contract required under GDPR (Article 28) between a data controller and a data processor that governs the processing of personal data. The DPA must specify the subject matter and duration of processing, the nature and purpose of processing, the types of personal data and categories of data subjects, and the obligations and rights of the controller....
DRG (Diagnosis-Related Group)
A patient classification system that groups inpatient hospital stays into clinically coherent categories based on principal diagnosis, procedures performed, patient age, complications, comorbidities, and discharge status. DRGs are used as the basis for prospective payment systems—hospitals receive a fixed payment per DRG regardless of actual resource consumption....
e-Prescribing (Electronic Prescribing)
The electronic generation, transmission, and filling of medical prescriptions, replacing traditional handwritten or faxed prescriptions. e-Prescribing systems check for drug-drug interactions, drug-allergy conflicts, therapeutic duplications, and formulary compliance at the point of prescribing, reducing medication errors by up to 70%....
Electronic Health Record (EHR)
A comprehensive digital record of a patient's health information maintained by a healthcare organization and designed to be shared across care settings. Unlike paper charts, EHRs enable real-time access to patient data—medical history, diagnoses, medications, lab results, immunizations, allergies, and imaging—from any authorized provider....
Electronic Medical Record (EMR)
A digital version of a patient's chart within a single healthcare practice or organization. While often used interchangeably with EHR, an EMR is typically confined to one practice and not designed for cross-organizational sharing....
ERA/EOB (Electronic Remittance Advice / Explanation of Benefits)
Electronic documents that communicate payment decisions from insurance payers to healthcare providers (ERA, via EDI 835 transactions) and patients (EOB). The ERA details how each claim was adjudicated—amounts paid, adjustments applied, denial reasons, and patient responsibility....
Fee-for-Service (FFS)
A healthcare payment model in which providers are reimbursed for each individual service, procedure, or visit performed. FFS has been the dominant reimbursement model in US healthcare for decades, using CPT and HCPCS codes to determine payment amounts....
FHIR (Fast Healthcare Interoperability Resources)
A standard for exchanging healthcare information electronically, developed by HL7 International. FHIR uses modern web technologies—RESTful APIs, JSON, XML, and OAuth 2.0—to enable seamless data exchange between healthcare systems....
GDPR (General Data Protection Regulation)
The European Union regulation on data protection and privacy applicable to all organizations processing personal data of EU residents, regardless of where the organization is based. GDPR establishes strict requirements including explicit consent, data minimization, the right to erasure ("right to be forgotten"), data portability, mandatory Data Protection Impact Assessments, and breach notification within 72 hours....
Health Information Exchange (HIE)
The electronic sharing of health-related information among healthcare organizations according to nationally recognized standards. HIE enables doctors, nurses, pharmacists, and other providers to appropriately access and securely share a patient's vital medical information electronically—improving the speed, quality, safety, and cost of patient care....
HIPAA (Health Insurance Portability and Accountability Act)
A United States federal law establishing national standards for the protection of sensitive patient health information (Protected Health Information, or PHI). HIPAA's Privacy Rule governs the use and disclosure of PHI, the Security Rule establishes administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notification of affected individuals and HHS within 60 days of a breach affecting 500+ records....
HL7 (Health Level Seven)
A set of international standards for the transfer of clinical and administrative data between healthcare software applications. HL7 v2, the most widely deployed healthcare interface standard globally, uses pipe-delimited messages (ADT, ORM, ORU) for events like patient admissions, lab orders, and results....
ICD-10 (International Classification of Diseases)
The 10th revision of the International Classification of Diseases, maintained by the World Health Organization, providing a standardized system of alphanumeric codes for classifying diseases, symptoms, abnormal findings, and external causes of injury. ICD-10-CM (Clinical Modification) is used in the US for diagnostic coding, while ICD-10-PCS covers procedure coding....
IHE (Integrating the Healthcare Enterprise)
An international initiative that promotes the coordinated use of established standards such as DICOM, HL7, and FHIR to improve how healthcare information systems share information. IHE does not create new standards but rather develops Integration Profiles—detailed specifications that describe how existing standards should be applied to solve specific clinical integration problems....
Interoperability
The ability of different healthcare information systems, devices, and applications to access, exchange, integrate, and cooperatively use data in a coordinated manner. Interoperability operates at four levels: foundational (basic connectivity), structural (data format standards like HL7/FHIR), semantic (shared clinical terminologies like SNOMED CT and LOINC), and organizational (governance, policy, and trust frameworks)....
ISO 27001 (Information Security Management)
The international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Published by the International Organization for Standardization and the International Electrotechnical Commission, ISO 27001 provides a systematic approach to managing sensitive information through risk assessment, control implementation, and continuous improvement....
LOINC (Logical Observation Identifiers Names and Codes)
A universal standard for identifying medical laboratory observations, clinical measurements, and document types. Maintained by the Regenstrief Institute, LOINC provides standardized codes for lab tests (chemistry, hematology, microbiology), vital signs, clinical assessments, and clinical documents....
MFA (Multi-Factor Authentication)
A security mechanism that requires users to provide two or more independent verification factors to gain access to a system, combining something the user knows (password), something the user has (phone, hardware token, smart card), and something the user is (biometrics). MFA is considered a critical security control in healthcare because compromised credentials are the leading cause of healthcare data breaches—81% of hacking-related breaches involve stolen or weak passwords according to the Verizon DBIR....
Patient Engagement
The strategies and technologies used to actively involve patients in their own healthcare, improving adherence to treatment plans, satisfaction, and outcomes. Patient engagement encompasses patient portals, secure messaging, educational content delivery, appointment reminders, satisfaction surveys, and self-management tools....
Patient Portal
A secure online application that provides patients with 24/7 access to their personal health information, including lab results, medication lists, appointment scheduling, secure messaging with providers, and educational materials. Patient portals are a cornerstone of patient engagement strategies and are mandated under the 21st Century Cures Act in the US, which prohibits information blocking....
PDPA (Personal Data Protection Act)
Data protection legislation adopted by several Southeast Asian countries—most notably Singapore (2012) and Thailand (2019)—establishing rules for the collection, use, disclosure, and storage of personal data. PDPA frameworks require organizations to obtain consent, notify individuals of data collection purposes, implement reasonable security arrangements, and allow data access and correction requests....
Personal Health Record (PHR)
A health record that is controlled and maintained by the patient rather than a healthcare organization, allowing individuals to aggregate their medical information from multiple providers, pharmacies, labs, and wearable devices into a single longitudinal record. Unlike EHRs, which are provider-managed, PHRs empower patients to track their own health data, share records with new providers, and maintain continuity across healthcare transitions....
PHI (Protected Health Information)
Any individually identifiable health information that is created, received, stored, or transmitted by a HIPAA-covered entity or business associate. PHI includes 18 specific identifiers defined by HIPAA: names, dates (except year), phone numbers, geographic data, fax numbers, Social Security numbers, email addresses, medical record numbers, account numbers, health plan beneficiary numbers, certificate/license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric identifiers, full-face photos, and any other unique identifying number....
PII (Personally Identifiable Information)
Any information that can be used to identify, contact, or locate a specific individual, either alone or in combination with other data sources. PII is a broader concept than PHI—while PHI is specific to health data under HIPAA, PII encompasses all personal data across all regulatory frameworks including GDPR, CCPA, PDPA, and LGPD....
Population Health
An approach to healthcare that aims to improve the health outcomes of a defined group of individuals by aggregating patient data, stratifying populations by risk, designing targeted interventions, and measuring results over time. Population health management shifts care from reactive to proactive by identifying high-risk cohorts before they require acute intervention....
Predictive Analytics in Healthcare
The application of statistical algorithms, machine learning models, and data mining techniques to historical and real-time healthcare data to predict future events, risks, and outcomes. In clinical settings, predictive analytics powers early warning scores for patient deterioration, readmission risk models, sepsis prediction, medication non-adherence forecasting, and no-show probability scoring....
Prior Authorization
A utilization management process requiring healthcare providers to obtain approval from a health insurer before performing a specific procedure, prescribing a medication, or ordering a test. Prior authorization is intended to ensure medical necessity and cost-effectiveness but frequently creates administrative delays—physicians report spending an average of 14 hours per week on prior authorizations....
RBAC (Role-Based Access Control)
A method of regulating access to computer resources based on the roles of individual users within an organization. In healthcare, RBAC ensures that clinicians, nurses, billing staff, administrators, and patients can only access the specific data and functions required for their job responsibilities—implementing the principle of least privilege mandated by HIPAA's Security Rule....
Remote Patient Monitoring (RPM)
The use of connected medical devices to collect patient health data outside of traditional clinical settings and transmit it electronically to healthcare providers for assessment. RPM devices include blood pressure cuffs, glucometers, pulse oximeters, weight scales, ECG monitors, and spirometers....
Revenue Cycle Management (RCM)
The financial process healthcare organizations use to track patient care episodes from registration and scheduling through final payment collection. RCM encompasses patient registration, insurance verification, charge capture, medical coding, claims submission, payment posting, denial management, and patient collections....
SMART on FHIR (OAuth 2.0 for Healthcare)
A standards-based framework that combines FHIR data models with OAuth 2.0 authorization to enable secure, interoperable third-party applications to launch within EHR systems and access patient data with appropriate permissions. Developed by Boston Children's Hospital and Harvard Medical School, SMART on FHIR allows clinicians to launch specialized apps—growth charts, risk calculators, clinical trial matchers, genomic viewers—directly from the EHR context without re-authentication....
SNOMED CT (Systematized Nomenclature of Medicine – Clinical Terms)
The most comprehensive, multilingual clinical healthcare terminology in the world, maintained by SNOMED International. SNOMED CT contains over 350,000 active concepts organized into hierarchies covering clinical findings, procedures, body structures, organisms, substances, and pharmaceutical products....
SOC 2 (System and Organization Controls 2)
A compliance framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates an organization's information systems based on five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. SOC 2 Type I assesses the design of controls at a point in time, while Type II evaluates the operating effectiveness of controls over a period (typically 6–12 months)....
SSO (Single Sign-On)
An authentication scheme that allows users to log in once with a single set of credentials and gain access to multiple applications and systems without re-authenticating. In healthcare, SSO reduces the number of passwords clinicians must manage—the average healthcare worker accesses 15–20 different systems daily—improving workflow efficiency and reducing password fatigue that leads to insecure practices....
Superbill
A standardized itemized form used by healthcare providers to document the services rendered during a patient encounter, listing the diagnosis codes (ICD-10), procedure codes (CPT/HCPCS), modifiers, units, and charges for each service. The superbill serves as the primary source document for claims submission and patient billing....
Telehealth
The delivery of healthcare services remotely via telecommunications technology, encompassing real-time video consultations, asynchronous secure messaging, remote patient monitoring, and store-and-forward transmission of clinical data. Telehealth extends care access to rural and underserved populations, reduces patient travel burden, and enables continuity between in-person and virtual visits....
Value-Based Care
A healthcare delivery model in which providers are reimbursed based on patient health outcomes rather than the volume of services delivered. Value-based care incentivizes preventive care, chronic disease management, care coordination, and patient engagement—rewarding quality over quantity....
Webhook
An HTTP callback mechanism that allows one system to send real-time notifications to another system when a specific event occurs, without requiring the receiving system to continuously poll for updates. In healthcare IT, webhooks enable event-driven architectures where actions in one system automatically trigger workflows in another—for example, a new lab result in the LIS can trigger a webhook that updates the patient's EHR, alerts the ordering provider, and schedules a follow-up if results are abnormal....
2,156 clinical and operational capabilities. One single platform.
8 business domains, 25 specialties, 7 care settings and 343 AI-augmented capabilities — without stacking more software.
Ready to see these technologies in action?
On-Kare implements all these standards and more