Covered entity
What makes an organization a HIPAA covered entity, the three types, how the provider test works, and what covered entities must do.
Covered entity at a glance
A HIPAA covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a standard transaction, such as submitting insurance claims or checking eligibility (45 CFR 160.103). Covered entities must follow the Privacy, Security and Breach Notification Rules and sign business associate agreements with vendors that handle their PHI.
| Defined in | 45 CFR 160.103 |
|---|---|
| Three types | Health plans, health care clearinghouses, health care providers that conduct standard transactions electronically |
| Provider test | Electronic standard transactions — e.g. claims, eligibility checks — done by you or a billing service for you |
| Main duties | Privacy, Security and Breach Notification Rules; BAAs with vendors |
| Not covered entities | Most consumer apps, employers acting as employers, life insurers |
HIPAA does not apply to everyone who handles health information. It applies to covered entities and their business associates. Under 45 CFR 160.103, a covered entity is one of three things.
1. Health plans
Individual and group plans that provide or pay for medical care — health insurers, HMOs, Medicare, Medicaid, employer group health plans and others.
2. Health care clearinghouses
Organizations that convert nonstandard health information into standard formats (or the reverse) for other organizations — for example, billing services that reformat claims.
3. Health care providers — with one condition
A provider is a covered entity only if it transmits health information electronically in connection with a standard transaction — such as submitting claims, checking eligibility or receiving remittance. It counts if a billing service or clearinghouse does this on the provider’s behalf.
This is why most practices that accept insurance are covered, while a purely private-pay practice that never conducts these transactions may not be. Confirm rather than assume, and remember that state privacy laws apply either way.
What covered entities must do
- Follow the Privacy Rule, Security Rule and Breach Notification Rule.
- Sign a business associate agreement with every vendor that is a business associate — one that creates, receives, maintains or transmits PHI on your behalf.
- Give patients a Notice of Privacy Practices and honor their rights.
See Who must comply with HIPAA for the full picture, including business associates.
Guides
- HIPAA law →How the HIPAA law is structured: the 1996 statute, the HHS regulations in 45 CFR, the HITECH Act and the Omnibus Rule — and who enforces them.
- HIPAA meaning →What HIPAA stands for, what people actually mean when they say "HIPAA", and what it does and does not cover.
- What is HIPAA? →A plain-English overview of HIPAA: what it protects, who it applies to, the three main rules, patients' rights and how it is enforced.
- Who must comply with HIPAA? →Who HIPAA applies to — covered entities and business associates — with examples, common edge cases like health apps and private-pay practices, and who is outside HIPAA.
Related requirements
- Business associate →§ 160.103
- PHI and ePHI →§ 160.103
- Business associate agreements (BAAs) →§ 164.502(e)
Frequently asked questions
Is every doctor a HIPAA covered entity?
Almost every doctor who takes insurance is, because claims are sent electronically. A provider who never conducts standard electronic transactions — directly or through a billing service — may not be.
Is a therapist in private practice a covered entity?
Yes, if the practice or its billing service submits insurance claims or other standard transactions electronically. A fully private-pay practice may not be.
Can a covered entity also be a business associate?
Yes. A covered entity can act as a business associate of another covered entity when it performs services for it involving PHI.