Skip to main content
The state of ai impact assessment
Category: Data Governance

Covered Entity

Simply put

A Covered Entity is a type of organization or individual that must follow the rules of the U.S. Health Insurance Portability and Accountability Act (HIPAA). In general, this means health plans, healthcare clearinghouses, and healthcare providers such as doctors, clinics, dentists, pharmacies, and nursing homes that handle health information electronically. Because HIPAA is a U.S. federal regulation, the Covered Entity concept applies within the United States and does not carry the same meaning under other jurisdictions' privacy laws.

Formal definition

Under HIPAA, a Covered Entity is defined as one of the following: (1) a health plan; (2) a healthcare clearinghouse; or (3) a healthcare provider who transmits any health information in electronic form in connection with a covered transaction. Covered Entities are the primary regulated parties directly subject to HIPAA's requirements, and should be distinguished from Business Associates, which are third parties that perform functions or services involving protected health information on a Covered Entity's behalf. An organization that performs both HIPAA-covered and non-covered functions may operate as a hybrid entity, designating and 'walling off' its healthcare components so that HIPAA obligations attach only to those covered functions. Specific classification is fact-specific; readers should verify status against the current official HIPAA regulatory text and HHS guidance, which are periodically amended.

Why it matters

The Covered Entity classification is the threshold question that determines whether HIPAA's obligations apply to an organization at all. If an organization qualifies as a health plan, healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with a covered transaction, it is directly subject to HIPAA's requirements. Misjudging this status can lead an organization either to overlook obligations it is legally bound to meet or to expend resources on requirements that may not apply in the way assumed.

The distinction also matters because HIPAA allocates responsibilities differently among the parties in the healthcare data ecosystem. Covered Entities are the primary regulated parties, while Business Associates—third parties handling protected health information on a Covered Entity's behalf—carry related but distinct obligations, typically governed through contractual arrangements. Treating these roles as interchangeable can produce gaps in compliance programs, misassigned accountability, and flawed contractual protections. Compliance officers and counsel therefore need to establish, as a factual matter, which role an organization occupies before designing controls around it.

Because HIPAA is a U.S. federal regulation, the Covered Entity concept is specific to the United States and does not carry the same meaning under other jurisdictions' privacy regimes. Organizations operating across borders should not assume that qualifying (or not qualifying) as a Covered Entity resolves their obligations under other frameworks. Classification is fact-specific and the underlying regulatory text is periodically amended, so determinations should be verified against the current official HIPAA text and HHS guidance rather than treated as settled once and for all.

Who it's relevant to

Compliance officers and privacy leads at healthcare organizations
Those responsible for HIPAA programs at health plans, clearinghouses, and healthcare providers need to confirm Covered Entity status as the foundation for scoping obligations, allocating accountability, and distinguishing their own responsibilities from those of Business Associates they engage.
Legal counsel advising on healthcare data
Attorneys assessing whether HIPAA applies to a client must make a fact-specific determination of Covered Entity versus Business Associate status, and should verify classification against the current official regulatory text and HHS guidance, which are periodically amended. Application to particular circumstances requires professional judgment.
Hybrid organizations with mixed functions
Entities that perform both HIPAA-covered and non-covered activities—such as universities with student clinics—may operate as hybrid entities by designating and walling off their healthcare components. These organizations need to structure and document that separation carefully so HIPAA obligations attach only to the covered functions.
Auditors and assessors of healthcare privacy programs
Professionals evaluating an organization's HIPAA posture must first establish which regulated role the organization occupies, since the applicable requirements and the boundary between covered and non-covered functions shape the scope of any audit or assessment.

Inside Covered Entity

Statutory definition
"Covered entity" is a defined term of art under U.S. HIPAA (the Health Insurance Portability and Accountability Act), generally encompassing health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with certain standard transactions. The precise scope is set by the applicable statute and implementing regulations and should be verified against the current official text.
Health plans
Generally includes individual and group plans that provide or pay the cost of medical care. The specific categories are enumerated in the regulations and may be subject to exceptions depending on plan type and size.
Health care clearinghouses
Entities that process nonstandard health information into a standard format (or vice versa), typically on behalf of another entity. Their obligations may differ depending on whether they act as a business associate.
Health care providers who transmit electronically
A provider becomes a covered entity generally only when it conducts one or more covered transactions in electronic form; a provider that does not conduct such transactions may fall outside the definition.
Relationship to business associates
A covered entity is distinct from a business associate, which performs functions or services involving protected health information on the covered entity's behalf. The two roles carry different, though related, obligations under the applicable rules.

Common questions

Answers to the questions practitioners most commonly ask about Covered Entity.

Is any organization that handles health information a covered entity under HIPAA?
No. The term "covered entity" under HIPAA is limited to specific categories: health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with certain standard transactions. An organization that merely comes into contact with health information is not automatically a covered entity. Many organizations that handle health data on behalf of covered entities fall instead into the "business associate" category, which carries a distinct set of obligations. Whether a particular organization qualifies depends on its function and the nature of its transactions, so the classification should be assessed against the current regulatory text and, where needed, with professional judgment.
Does being a "covered entity" mean the same thing across all privacy and data protection laws?
No. "Covered entity" is a defined term specific to HIPAA, which governs certain health information in the United States. Other legal regimes use different terminology and scoping concepts. For example, the GDPR in the EU frames obligations around "controllers" and "processors" rather than covered entities. Treating "covered entity" as a universal label risks conflating distinct legal frameworks with different jurisdictional scope, definitions, and obligations. Always identify which regulation is in question and apply its own definitions rather than assuming equivalence across regimes.
How can an organization determine whether it meets the definition of a covered entity?
Assessment generally begins by evaluating whether the organization falls within one of the defined categories and whether it engages in the electronic standard transactions that trigger the definition. This is a fact-specific analysis that turns on the organization's actual functions rather than its industry label alone. Some organizations perform multiple functions, only some of which bring them within scope. Because the classification affects which obligations apply, organizations often document their analysis and verify it against the current official regulatory text, involving legal or compliance professionals where the answer is not clear-cut.
What is the practical difference between being a covered entity and being a business associate?
The two roles are distinct and carry different sets of obligations. A covered entity falls directly within the defined categories under HIPAA, while a business associate generally performs functions or services involving protected health information on behalf of, or for, a covered entity. The relationship between them is typically formalized through a written arrangement. Correctly identifying which role applies matters because it determines the scope and nature of compliance responsibilities. An organization should not assume the roles are interchangeable, and in some situations an entity may need to consider whether it acts in more than one capacity.
What should an organization do if it may act as both a covered entity and a business associate?
Where an organization performs multiple functions, it may need to analyze each function separately to determine which classification applies to which activity. The obligations tied to each role can differ, so a blended or default assumption is generally not advisable. Organizations in this position often map their activities to the relevant definitions, document how each function is treated, and confirm the analysis against the current authoritative text. Because these determinations are fact-specific and interpretations can evolve, professional judgment is typically warranted for edge cases.
How often should an organization revisit whether it qualifies as a covered entity?
Classification should generally be treated as something to revisit rather than a permanent designation. Changes in an organization's functions, transactions, or relationships can alter whether it falls within the defined categories. In addition, the underlying regulation is periodically amended and interpretive guidance evolves, so a determination that was accurate at one point may need reassessment. Organizations commonly review their status when their operations change materially and verify the analysis against the latest official source rather than relying on a prior conclusion.

Common misconceptions

Any organization that handles health or medical data is a covered entity.
The term is narrowly defined under HIPAA and generally applies only to health plans, health care clearinghouses, and qualifying health care providers. Many organizations that touch health data—such as certain apps, employers, or vendors—may not meet the definition, though they can be regulated under other regimes or as business associates. Application to specific circumstances requires professional judgment.
"Covered entity" is a universal or international concept.
It is a U.S. HIPAA term with a specific statutory meaning. Other jurisdictions—such as the EU under the GDPR or the UK under its data protection regime—use different concepts (for example, controllers and processors) that should not be equated with covered entities.
Being a covered entity is a certification or accredited status.
Covered entity status is a legal classification that follows from the nature of an organization's activities, not a voluntary certification or a credential that is granted. Compliance obligations attach by operation of law rather than through a certification scheme.

Best practices

Determine covered entity status by analyzing your organization's actual functions and transactions against the current statutory and regulatory definitions, rather than assuming status based on whether health data is present.
Distinguish clearly between covered entity and business associate roles in your documentation, since the obligations, though related, differ.
Verify the applicable definition and any exceptions against the latest authoritative official text, as regulations are periodically amended or superseded.
Do not treat HIPAA covered entity status as equivalent to obligations under other jurisdictions' regimes; map each relevant law separately where operations cross borders.
Reassess status when business activities change—such as beginning to conduct covered electronic transactions—since classification can shift with operational changes.
Engage qualified legal or compliance professionals for fact-specific determinations, as classification and its consequences depend on the particular circumstances.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.