Frameworks

What is a covered entity under HIPAA?

In short

A HIPAA covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits any health information in electronic form in connection with a covered transaction. The definition is at 45 CFR §160.103, and it is the first thing to settle, because it decides whether HIPAA binds you directly or through a business associate agreement.

Last updated

Definition

Covered entity is defined at 45 CFR §160.103 as a health plan, a health care clearinghouse, or a health care provider who transmits any health information in electronic form in connection with a transaction covered by the HIPAA rules. A covered entity is bound by the Privacy, Security and Breach Notification Rules directly.

Background

There are three categories and no others. Health plans include health insurers, HMOs, employer group health plans, and government programs such as Medicare and Medicaid that pay for care. Health care clearinghouses are the organizations that translate health information between standard and non-standard formats, such as billing services and repricing companies. Health care providers are the category where the electronic transmission test bites: a provider is covered only if it transmits health information electronically in connection with a covered transaction, which means claims, eligibility checks, referral authorizations, payment and remittance, and the other transactions standardized in 45 CFR Part 162. Nearly every doctor, dentist, clinic, hospital, pharmacy and nursing home meets that test, because billing a plan electronically is a covered transaction. A provider who takes only cash and bills nothing electronically can fall outside the definition. Two further structures matter in practice. A hybrid entity is a single legal entity whose business is only partly health care: it may designate its health care components, and the HIPAA rules then apply to those components rather than the whole organization (§164.103 and §164.105). An affiliated covered entity is a group of legally separate covered entities under common ownership or control that choose to be treated as one for HIPAA purposes.

Why it matters

Your role decides which duties land on you and how. A covered entity owes the full Privacy Rule, including the notice of privacy practices and the individual rights to access and amendment, and it is the party that notifies patients, the media and HHS after a breach. A business associate owes the Security Rule directly, the Privacy Rule duties its agreement and the regulation assign it, and it reports breaches to the covered entity rather than to individuals. An organization can be both at once: a health plan that also processes claims for other plans is a covered entity for its own members and a business associate for the others. Getting this wrong at the start means building the wrong program, and it also means signing the wrong contract.

Step by step

  1. Decide which of the three categories, if any, describes your organization.
  2. If you are a provider, confirm whether you transmit health information electronically in connection with a covered transaction. Your billing arrangement usually answers this.
  3. If you are not a covered entity, check whether you handle PHI for one. That makes you a business associate, with a business associate agreement required before PHI moves.
  4. If your organization is only partly health care, consider a hybrid entity designation and document the health care components you designate.
  5. Write the conclusion down, with the reasoning, and revisit it when you add a line of business or a new customer type.

Examples

  • A dental practice that submits claims to insurers electronically is a covered entity as a health care provider.
  • A university runs a student health clinic that bills insurers, and designates that clinic as a health care component under a hybrid entity designation; the rest of the university is outside it.
  • A telehealth SaaS sells to clinics and never bills a plan itself. It is not a covered entity. It handles PHI for its clinic customers, so it is a business associate and signs a BAA with each one.

Common mistakes

  • Assuming any company handling health data is a covered entity. Most health-tech vendors are business associates, which is a different set of duties.
  • Treating an employer as a covered entity because it sponsors a health plan. The group health plan is the covered entity; employment records the employer holds in its role as employer are excluded from PHI.
  • Skipping the hybrid entity designation and applying HIPAA to an entire organization, which creates obligations nobody is resourced to meet.
  • Deciding the question once at founding and never revisiting it after a new product line or customer type arrives.

FAQ

What are the covered entities under HIPAA?

Health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with a covered transaction. That is the complete list in 45 CFR §160.103.

Is a business associate a covered entity?

No. They are separate roles. A business associate handles PHI on a covered entity’s behalf and is bound by the Security Rule directly and by the Privacy Rule duties the regulation and its agreement assign it.

Is an employer a covered entity?

Not by being an employer. A group health plan the employer sponsors can be a covered entity, and the employer may be acting as plan sponsor, which carries its own requirements at §164.504(f) and §164.314(b).

Are health apps covered entities?

Usually not. An app consumers use on their own, with no plan or provider involved, is generally outside HIPAA, although the FTC Health Breach Notification Rule and state privacy laws can still apply. An app a provider offers to its patients is a different matter, and the developer is typically a business associate.

Can one organization be both?

Yes. The roles attach to functions rather than to companies, so an organization can be a covered entity for its own activities and a business associate for the work it does for someone else.

Next step

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.