What Is a Covered Entity in Healthcare? A Complete Guide to Who Qualifies
- Home
- Healthcare Compliance Software
- What Is a Covered Entity in Healthcare? A Complete Guide to Who Qualifies
If you run a practice or handle patient records, you have probably wondered whether HIPAA applies to your work. The rules can feel dense, the language is full of legal terms, and a wrong guess can lead to fines or a stressful audit. Plenty of providers feel the same uncertainty.
A covered entity in healthcare is any health plan, healthcare clearinghouse, or healthcare provider that sends protected health information (PHI) electronically for a transaction covered by HIPAA. PHI is any health detail that can identify a person, such as a name linked to a diagnosis.
This guide clears up the confusion in plain terms. Drawing on ComplyAssistant’s 25-plus years of helping hospitals and health systems with HIPAA, it shows who qualifies as a covered entity, who does not, and the simple steps to confirm where you stand so you can stop guessing and protect your patients with confidence.
Ready to Simplify HIPAA Compliance?
What Is a Covered Entity in Healthcare?
A covered entity is a person, business, or organization that must follow HIPAA, the Health Insurance Portability and Accountability Act of 1996. These groups handle protected health information and have a legal duty to keep it private and secure.
In plain terms, the law looks at two things: what you do and how you handle health data. The U.S. Department of Health and Human Services (HHS) groups covered entities into three buckets: health plans, healthcare clearinghouses, and healthcare providers who send PHI electronically.
The word “entity” can feel impersonal, but it covers a wide mix. A covered entity can be:
- An organization, such as a hospital, an insurance company, or a clinic.
- An institution, such as a university medical center or a public health lab.
- An individual, such as a solo therapist or a private-practice dentist.
The size of your business does not decide the answer. A one-room counselling practice can be a covered entity, while a large wellness company that never bills insurers electronically might not be. What counts is the role you play and whether you move health data in electronic form for covered transactions.
A quick, friendly test: if you create, store, send, or receive patient health information, and you do business with health plans by computer, you are very likely a covered entity. The rest of this guide helps you confirm it.
How HIPAA Defines a Covered Entity Under the Law
HIPAA’s definitions live in the Code of Federal Regulations, mainly in 45 CFR Part 160 and Part 162. Part 160 sets the general rules and definitions. Part 162 lists the electronic transactions that pull an organization into HIPAA’s reach.
Under the law, a covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information in electronic form as part of a covered transaction. That last part is the trigger that catches many providers off guard.
Here is the part worth slowing down on: the electronic transmission is the deciding factor for providers. A doctor becomes a covered entity the moment they send a covered transaction by computer, such as an electronic insurance claim. A provider who only deals in paper and phone calls may sit outside the definition.
Take two therapists in the same building. One submits claims to insurers through billing software. The other only accepts cash and mails the rare paper form. The first is a covered entity. The second, in many cases, is not, even though both keep patient notes.
This is why the format of your work matters as much as the work itself. The same service can place one practice under HIPAA and leave another outside it, based only on how the data travels. Health plans and clearinghouses, by contrast, are covered by the nature of what they do, with no electronic test to clear.
Why Knowing If You’re a Covered Entity Matters
Knowing your status is the starting point for every compliance choice you make. If you are a covered entity, you must follow the HIPAA Privacy Rule, the Security Rule, and the Breach Notification Rule. You also need a risk analysis, staff training, written policies, and a named privacy and security officer.
Get the label wrong, and the cost can be steep. HHS, through its Office for Civil Rights (OCR), enforces civil money penalties using a four-tier system based on how careless the conduct was. The figures below reflect the inflation-adjusted amounts that took effect on January 28, 2026.
Tier | What it means | Annual cap (same rule) | |
Tier 1 | You did not know and could not reasonably have known | $145 to $73,011 | $2,190,294 |
Tier 2 | Reasonable cause, not willful neglect | $1,461 to $73,011 | $2,190,294 |
Tier 3 | Willful neglect, fixed within 30 days | $14,602 to $73,011 | $2,190,294 |
Tier 4 | Willful neglect, not fixed within 30 days | $73,011 and up | $2,190,294 |
Money is only part of the picture. A breach or fine can shake patient trust, draw an OCR audit, and damage a reputation that took years to build. When you know your status early, you can put the right safeguards in place before a problem starts, not after.
The Three Types of Covered Entities in Healthcare
HIPAA sorts covered entities into three groups. Each one handles health data in a different way, but all three must meet the same core privacy and security duties. The table below gives a quick view, and the sections that follow add detail and real cases.
Type | Who it includes | Everyday example |
Healthcare providers | Doctors, hospitals, clinics, dentists, pharmacies, therapists | A dental office filing claims through billing software |
Health plans | Insurers, HMOs, employer and government plans | A company health plan that pays employee medical claims |
Healthcare clearinghouses | Billing services and data processors | A service that turns paper claims into standard electronic ones |
Healthcare Providers
Healthcare providers are the group most people picture first. They include doctors, hospitals, clinics, dentists, chiropractors, psychologists, therapists, nursing homes, pharmacies, and home health agencies. The list reaches well beyond hospitals and into small private practices.
A provider becomes a covered entity only when they send PHI electronically for a covered transaction. The most common case is submitting insurance claims or checking patient eligibility online. The moment that data moves by computer, HIPAA applies.
Not every provider clears that bar. Say a massage therapist or a small wellness clinic only takes direct payment and never bills insurers electronically. That practice may fall outside the definition of a covered entity, even if it still maintains health records. The activity is the same; the electronic step is what changes the answer.
Health Plans
Health plans pay for medical care or offer health benefits. This group includes health insurance companies, health maintenance organizations (HMOs), preferred provider organizations (PPOs), employer-sponsored plans, and government programs like Medicare, Medicaid, and military and veterans’ health programs.
Because they manage large volumes of identifiable health data, health plans are covered by the nature of their work. There is no electronic test for them to pass, unlike providers.
One useful exception helps clear up confusion. An insurer that pays health costs only as a side benefit is not a covered entity. Picture an auto insurance policy that covers medical bills after a crash. The payment is a secondary feature of the car policy, so the auto insurer is not a covered entity under HIPAA.
Healthcare Clearinghouses
Healthcare clearinghouses work behind the scenes. They act as a middle layer between providers and health plans, converting nonstandard health data into a standard format and vice versa.
Their main job is to keep claims, eligibility checks, and payments moving when a provider’s system and a payer’s system do not speak the same language. They also catch errors before a claim reaches the health plan, which helps avoid delays in patient care.
Say a small clinic still produces paper claims. A clearinghouse can convert those into the standard electronic transactions that insurers accept. Because that work runs on PHI, clearinghouses are covered entities and must protect the data they touch.
Which HIPAA Transactions Trigger Covered Entity Status?
For providers, the trigger is sending a “standard transaction” in electronic form. HHS set standards for these transactions in 45 CFR Part 162, and they cover the routine business between providers and health plans.
The standard electronic transactions include:
- Healthcare claims sent to a health plan for payment.
- Payment and remittance advice from a plan back to a provider.
- Eligibility checks to confirm a patient’s coverage.
- Claim status requests and responses.
- Enrollment and disenrollment in a health plan.
- Referral certification and authorization.
- Coordination of benefits between plans.
- Healthcare electronic fund transfers (EFT).
If your practice handles any of these by computer, you are conducting a covered transaction. That single step can place you under HIPAA, even if it only happens once. One electronic claim is enough to make a provider a covered entity.
A reminder about the data itself: these rules exist to protect PHI, which is health information tied to an identifiable person. A phone call about a bill is not an electronic transaction, and parking-lot license plates are not PHI. The line is drawn around identifiable health data moving through covered transactions.
Covered Entity vs. Business Associate: Key Differences
Covered entities rarely work alone. They often hire outside companies to help with billing, data storage, legal work, or technology. When one of those companies needs access to PHI to do its job, HIPAA calls it a business associate.
A business associate is a person or company that performs a service for a covered entity and, in doing so, creates, receives, stores, or sends PHI. The difference comes down to access. A covered entity holds PHI as part of its core work. A business associate only touches PHI to support the covered entity.
Common business associates include:
- Medical billing and claims processing companies.
- IT providers and cloud storage services.
- Medical transcriptionists.
- Lawyers, accountants, and consultants who handle PHI.
- Pharmacy benefit managers and collection agencies.
The table below shows the practical split.
Feature | Covered Entity | Business Associate |
Role | Provides or pays for care | Supports a covered entity |
Relationship with patients | Direct | Indirect |
How it gets PHI | Through its own core work | Through a contract with a covered entity |
Privacy Rule duty | Full | Depends on the service and contract |
Security and Breach rules | Full | Full |
One point trips people up: a covered entity can also be a business associate of another covered entity. A hospital that processes claims for a separate provider is acting as a business associate in that role, even though it is a covered entity in its own right.
What Is a Business Associate Agreement (BAA)?
A business associate agreement (BAA) is a written contract between a covered entity and a business associate. It must be signed before the business associate handles any PHI. The contract spells out what the business associate may do with the data and requires it to follow HIPAA.
A solid BAA sets out:
- The exact services the business associate will provide.
- How PHI may be used and disclosed, and nothing beyond that.
- The safeguards the business associate must keep in place.
- How and when to report a breach.
There is a narrow exception. A company with only brief, passing contact with PHI does not need a BAA. The U.S. Postal Service, when it delivers a results letter, does not sign a BAA, because it does not really access the contents. For most vendors that handle your patient data, though, a signed BAA is a must, and managing those agreements is a core part of staying compliant. ComplyAssistant’s vendor risk management software helps track these relationships in one place.
Special Covered Entity Classifications
Not every organization fits neatly into one box. Some run both health and non-health operations, and others are part of a larger family of related businesses. HIPAA offers a few special structures for these cases. Understanding them can save you from over-applying the rules or missing a gap.
Hybrid Entities
A hybrid entity is a single legal organization that performs both covered and non-covered work. Instead of treating the whole organization as a covered entity, it can formally label only the parts that handle PHI as its “health care components.” HIPAA then applies mainly to those named parts.
Take a university with a student health clinic and a separate business school. The clinic handles PHI and falls under HIPAA, while the business school does not. By designating the clinic as a health care component, the university limits HIPAA to the area that needs it.
Other groups that may operate as hybrid entities include state health departments, public health labs that also run general testing, and corrections departments that provide medical care alongside custody work. The label must be documented, not just assumed.
Affiliated Covered Entities
An affiliated covered entity lets legally separate organizations under shared ownership or control act as one covered entity for HIPAA purposes. This helps large health systems and multi-site hospital networks run a single compliance program instead of many.
Once affiliated, the related entities can use one set of HIPAA policies and share PHI for permitted reasons without signing BAAs between themselves. This cuts paperwork and supports coordinated care across a group of related providers and plans.
To use this structure, the organizations must show common ownership or control and document the designation. Done well, it turns a tangle of separate entities into a single, easier-to-manage compliance unit.
Organized Health Care Arrangements (OHCAs)
An Organized Health Care Arrangement (OHCA) lets separate covered entities share PHI for joint treatment, payment, and healthcare operations without a BAA between each one. Unlike an affiliated entity, the members are not under shared ownership. They stay independent but team up for specific, shared purposes.
A common case is a hospital and the independent physicians who practice there. They share patient data to coordinate care, run joint quality reviews, and manage shared operations. The OHCA structure supports teamwork while keeping each member responsible for their own compliance.
OHCAs also help group health plans, insurers, and HMOs that work together on the same benefit program. The goal is smoother coordination among parties that serve the same patients.
Partial Entities and Self-Insured Employer Plans
“Partial entity” is not a formal HIPAA term, but it is a handy way to describe a tricky situation. It comes up most often when an employer runs a self-insured health plan for its workers.
In that setup, the health plan is the covered entity, not the employer. But the employer often needs access to PHI to administer the plan. The employer cannot be a business associate to its own plan since they are the same legal entity, and HIPAA does not allow an entity to be its own business associate.
So the employer must build a wall around that data. It has to certify that PHI will be protected as HIPAA requires, used only to run the health plan, and kept away from employment decisions like hiring, firing, or promotions. Mixing plan data with HR work is exactly the kind of slip that leads to violations.
Who Is Not a Covered Entity Under HIPAA
Plenty of organizations handle health-related data yet sit outside HIPAA’s covered entity rules. Knowing the difference keeps you from applying rules that do not fit, and it flags the gaps that other privacy laws may cover instead.
The table below shows the groups that are usually not covered entities.
Organization | Why it usually is not a covered entity |
Wearable tech and health apps | They collect health data but do not run HIPAA transactions. The maker can become a business associate if a hospital or plan hires it to handle PHI. |
Life, auto, and workers’ compensation insurers | They pay health costs only as a side benefit, not as a health plan. |
Most employers | Staff health records kept for normal HR reasons are not used for covered transactions. |
Schools | Student health records at most public schools are “education records” under FERPA, a separate law. |
Insurance brokers | A broker may be a business associate for a health plan but is not a covered entity itself. |
Cash-only providers | A clinic that never bills insurers electronically may fall outside the definition. |
Being outside HIPAA does not always mean no rules apply. State privacy laws, FERPA, and the Federal Trade Commission’s health breach rules can still reach data that HIPAA does not. The safe move is to confirm which laws apply to your work rather than assume none do.
How to Determine If Your Organization Is a Covered Entity in Healthcare
You do not need a law degree to check your status. A short, honest walk-through of how you handle health data will get you most of the way. Work through these steps in order.
- Name your role. Are you a healthcare provider, a health plan, or a healthcare clearinghouse? If you are none of these, you are likely not a covered entity, though you may still be a business associate.
- Check for PHI. Do you create, store, send, or receive health information that can identify a patient? If yes, keep going.
- Look at the electronic step. Do you send any covered transactions by computer, such as an electronic claim or an eligibility check? For providers, this is the deciding factor.
- Match the transaction. Confirm that the electronic transaction is one HHS has set standards for, like claims, payment, or referral authorization.
- Account for special structures. If you run both health and non-health work, consider whether a hybrid or affiliated setup fits.
If you answer yes to the role, the PHI question, and the electronic transaction, you are almost certainly a covered entity. When you are still unsure, the Centers for Medicare and Medicaid Services (CMS) offers a free Covered Entity Decision Tool that walks you through the same questions.
The decision tool is a strong starting point, not a final legal answer. Grey areas, like wellness clinics that mix medical and non-medical services, often need a closer look. A short review with a compliance specialist can save you from guessing wrong on a question that carries real penalties.
How ComplyAssistant Helps Covered Entities Stay HIPAA Compliant
Once you know you are a covered entity, the next question is simple: how do you turn that label into a clear, daily program you can prove? That is the work ComplyAssistant has focused on for more than 25 years, serving hospitals, health systems, providers, and the partners who support them.
ComplyAssistant pairs governance, risk, and compliance (GRC) software with hands-on cybersecurity services, both built around the needs of healthcare. The aim is to take a complex set of rules and make them manageable, so your team can spend more time on patients and less on paperwork.
Here is how the pieces fit together for a covered entity:
- HIPAA compliance software to organize your policies, risk analysis, and documentation in one place, with dashboards and alerts that keep work on track.
- HIPAA audits run by experienced consultants who give an unbiased review and a clear action plan, with results delivered in the software rather than a loose spreadsheet.
- Vendor risk management to track your business associates and confirm they meet their own HIPAA duties.
- Virtual CISO services that bring senior security leadership to organizations that do not have it in-house.
- Policy and audit management software to create, update, and share policies and stay ready for any review.
ComplyAssistant’s compliance team often makes a simple point: the organizations that struggle are rarely the ones doing something wrong on purpose. They are the ones without documentation to show what they did right. Good software fixes that by keeping a clear record of every step.
Wrapping Up!
A covered entity in healthcare is a health plan, a healthcare clearinghouse, or a healthcare provider that sends PHI electronically for a HIPAA-covered transaction. Those three groups carry the same core duty to keep patient data private and secure.
The electronic transaction is the part to watch. For providers, that single step is what turns a practice into a covered entity, no matter how small the office is. Health plans and clearinghouses are covered by the nature of their work.
Getting the label right is more than a box to check. With civil penalties reaching into the millions per violation category and criminal penalties on top, a wrong guess can be costly. Confirm your status first, then build a program you can stand behind.
If you are ready to move from “we think we are compliant” to “we can prove it,” ComplyAssistant can help you get there. Contact the team to see what a clear, healthcare-focused compliance program looks like for your organization.
FAQs
Is a covered entity the same as a healthcare provider?
No. A healthcare provider is one of three types of covered entities, alongside health plans and healthcare clearinghouses. A provider is only a covered entity when it sends PHI electronically for a covered transaction. A provider that never bills insurers by computer may not qualify.
Can an individual be a covered entity in healthcare?
Yes. A solo provider, such as a private-practice dentist, therapist, or psychologist, can be a covered entity if they send PHI electronically for a covered transaction. Staff who work for a covered entity are not covered entities themselves, but they must follow their employer’s HIPAA policies.
Are employers covered entities under HIPAA?
Usually no. An employer that keeps staff health records for normal HR reasons is not a covered entity, because those records are not used for covered transactions. An employer that runs a self-insured health plan must wall off plan data and protect it under HIPAA, even though the health plan, not the employer, is the covered entity.
Are schools and universities covered entities?
Most public schools are not. Student health records are treated as “education records” under FERPA, a separate law, so the school is usually not a covered entity. A university can be a hybrid entity when one part, like a student health clinic, handles PHI while the rest does not.
Do all healthcare providers count as covered entities?
No. A provider is a covered entity only when it sends a covered transaction electronically. A cash-only clinic, or one that handles claims by phone or paper, may sit outside the definition. One electronic claim, though, is enough to make a provider a covered entity.
Is a business associate a covered entity?
Not by default. A business associate supports a covered entity and touches PHI to do its job, such as a billing company or a cloud vendor. It must sign a business associate agreement and follow the Security and Breach Notification Rules. A covered entity can also act as a business associate of another covered entity.
Are telehealth platforms and health apps covered entities?
Health apps and wearables, like fitness trackers, are usually not covered entities on their own. They can become business associates when a hospital or health plan hires them to handle PHI. A telehealth tool used by a covered provider should be set up to meet HIPAA, which often means a signed business associate agreement.
Do covered entities have to follow every HIPAA rule?
A covered entity must follow every HIPAA rule that applies to its work, not every rule on the books. Some rules apply only to health plans, others only to providers or clearinghouses. If you outsource a function to a business associate, certain parts may not apply to you directly, but you still answer for choosing and overseeing that partner.