HIPAA
US federal regulation for protecting health information privacy security
AS9120B
Aerospace QMS standard for distributors of parts.
Quick Verdict
HIPAA mandates privacy/security for healthcare PHI, enforced by OCR penalties. AS9120B certifies aerospace distributors' QMS for traceability/counterfeit prevention. Organizations adopt HIPAA for legal compliance, AS9120B for supply chain access.
HIPAA
Health Insurance Portability and Accountability Act of 1996
Key Features
- Risk-based safeguards for ePHI confidentiality, integrity, availability
- Minimum necessary principle limiting PHI uses and disclosures
- Presumption-of-breach model with four-factor risk assessment
- Direct liability for business associates via BAAs
- Individual rights to access, amend, and account for PHI
AS9120B
AS9120B Quality Management Systems - Requirements
Key Features
- Counterfeit and unapproved parts prevention
- Traceability and chain-of-custody controls
- Risk-based external provider evaluation
- Configuration management for split lots
- Product safety and ethical awareness
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
HIPAA Details
What It Is
HIPAA (Health Insurance Portability and Accountability Act of 1996) is a US federal regulation establishing national standards to protect individuals' protected health information (PHI). It includes Privacy, Security, and Breach Notification Rules, adopting a flexible, risk-based, technology-neutral approach for covered entities and business associates.
Key Components
- Privacy Rule (45 CFR Part 164 Subparts A/E): Controls PHI uses/disclosures, minimum necessary, TPO permissions, patient rights.
- Security Rule (Subpart C): Administrative, physical, technical safeguards for ePHI; requires risk analysis/management.
- Breach Notification Rule (Subpart D): Presumption-of-breach notifications within 60 days. Seven pillars like scope, BA governance; enforced by OCR, no certification.
Why Organizations Use It
- Mandatory compliance for healthcare providers, plans, clearinghouses, BAs.
- Mitigates breach risks, multimillion penalties.
- Enables secure data flows, builds patient trust.
- Supports operations, partnerships, cyber resilience.
Implementation Overview
Phased: Assess (risk analysis, scoping), Build (safeguards, BAAs, training), Operate (monitoring), Assure (audits). Applies US-wide to healthcare; ongoing program with 6-year documentation.
AS9120B Details
What It Is
AS9120B is the IAQG quality management system standard for aviation, space, and defense distributors. It augments ISO 9001:2015's high-level structure with over 100 aerospace-specific requirements. Primary purpose: ensure safe procurement, storage, splitting, and resale of parts without altering characteristics. Adopts risk-based thinking and PDCA approach focused on distribution risks like traceability loss and counterfeits.
Key Components
- **Core clausesContext (4), Leadership (5), Planning (6), Support (7), Operation (8), Evaluation (9), Improvement (10).
- Distributor emphases: counterfeit prevention, traceability, supplier controls, configuration management.
- Built on ISO 9001:2015; certification via accredited bodies with IAQG OASIS listing.
Why Organizations Use It
- Commercial necessity for OEM supply chains.
- Mitigates risks of nonconformities, counterfeits.
- Enhances market access, customer trust, efficiency.
Implementation Overview
- Phased: gap analysis, process design, training, audits (6-12 months).
- For distributors globally; requires internal audits, management reviews.
Key Differences
| Aspect | HIPAA | AS9120B |
|---|---|---|
| Scope | PHI privacy, security, breach notification | Aerospace distribution QMS, traceability, counterfeit prevention |
| Industry | Healthcare, covered entities, business associates | Aerospace parts distributors, stockists |
| Nature | Mandatory US federal regulation | Voluntary certification standard |
| Testing | Risk analysis, internal audits, OCR investigations | Internal audits, certification body surveillance audits |
| Penalties | Civil monetary penalties, criminal prosecution | Loss of certification, market exclusion |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about HIPAA and AS9120B
HIPAA FAQ
AS9120B FAQ
You Might also be Interested in These Articles...

Top 5 Audit Survival Secrets for Your First SOC 2 Type 2: What Auditors Really Check (and How to Pass)
Master your first SOC 2 Type 2 audit with proven strategies: 40-sample testing, vendor gaps, CPA walkthroughs. Get checklists, scripts & tips from SignWell to s

CMMC Scoping Mastery for Defense Supply Chains: Enclave Mapping, Subcontractor Flow-Down, and CUI Inventory Blueprint
Master CMMC scoping for DIB: delineate FCI/CUI boundaries, segment enclaves, manage subcontractor flow-down. Prevent 80% assessment failures with SSP templates,

Beyond the Checkbox: Why Maturity Assessments are the Secret to Sustainable Compliance
Discover why maturity assessments beat binary compliance checks by uncovering hidden gaps and enabling continuous improvement for sustainable success. Read now!
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
SAFe vs LGPD
Compare SAFe vs LGPD: Scale agile enterprises with built-in compliance for Brazil's data law. Boost velocity, embed security & DPIAs. Transform agility now!
ITIL vs EU AI Act
Discover ITIL vs EU AI Act: Align ITIL 4's SVS with AI risk mgmt, data governance & compliance for high-risk systems. Boost ITSM resilience—explore synergies now!
DORA vs LEED
DORA vs LEED: EU finance resilience regulation meets green building standard. Compare ICT risk mgmt, testing & third-party oversight vs energy, IEQ credits. Boost compliance now!