hipaa.systems
General provisions · 45 CFR 160.103

Covered entity

What makes an organization a HIPAA covered entity, the three types, how the provider test works, and what covered entities must do.

Checked 2026-10-06Sources 2

Covered entity at a glance

A HIPAA covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a standard transaction, such as submitting insurance claims or checking eligibility (45 CFR 160.103). Covered entities must follow the Privacy, Security and Breach Notification Rules and sign business associate agreements with vendors that handle their PHI.

Defined in45 CFR 160.103
Three typesHealth plans, health care clearinghouses, health care providers that conduct standard transactions electronically
Provider testElectronic standard transactions — e.g. claims, eligibility checks — done by you or a billing service for you
Main dutiesPrivacy, Security and Breach Notification Rules; BAAs with vendors
Not covered entitiesMost consumer apps, employers acting as employers, life insurers

HIPAA does not apply to everyone who handles health information. It applies to covered entities and their business associates. Under 45 CFR 160.103, a covered entity is one of three things.

1. Health plans

Individual and group plans that provide or pay for medical care — health insurers, HMOs, Medicare, Medicaid, employer group health plans and others.

2. Health care clearinghouses

Organizations that convert nonstandard health information into standard formats (or the reverse) for other organizations — for example, billing services that reformat claims.

3. Health care providers — with one condition

A provider is a covered entity only if it transmits health information electronically in connection with a standard transaction — such as submitting claims, checking eligibility or receiving remittance. It counts if a billing service or clearinghouse does this on the provider’s behalf.

This is why most practices that accept insurance are covered, while a purely private-pay practice that never conducts these transactions may not be. Confirm rather than assume, and remember that state privacy laws apply either way.

What covered entities must do

See Who must comply with HIPAA for the full picture, including business associates.

Guides

Frequently asked questions

Is every doctor a HIPAA covered entity?

Almost every doctor who takes insurance is, because claims are sent electronically. A provider who never conducts standard electronic transactions — directly or through a billing service — may not be.

Is a therapist in private practice a covered entity?

Yes, if the practice or its billing service submits insurance claims or other standard transactions electronically. A fully private-pay practice may not be.

Can a covered entity also be a business associate?

Yes. A covered entity can act as a business associate of another covered entity when it performs services for it involving PHI.