Covered Entity
A Covered Entity is a type of organization or individual that must follow the rules of the U.S. Health Insurance Portability and Accountability Act (HIPAA). In general, this means health plans, healthcare clearinghouses, and healthcare providers such as doctors, clinics, dentists, pharmacies, and nursing homes that handle health information electronically. Because HIPAA is a U.S. federal regulation, the Covered Entity concept applies within the United States and does not carry the same meaning under other jurisdictions' privacy laws.
Under HIPAA, a Covered Entity is defined as one of the following: (1) a health plan; (2) a healthcare clearinghouse; or (3) a healthcare provider who transmits any health information in electronic form in connection with a covered transaction. Covered Entities are the primary regulated parties directly subject to HIPAA's requirements, and should be distinguished from Business Associates, which are third parties that perform functions or services involving protected health information on a Covered Entity's behalf. An organization that performs both HIPAA-covered and non-covered functions may operate as a hybrid entity, designating and 'walling off' its healthcare components so that HIPAA obligations attach only to those covered functions. Specific classification is fact-specific; readers should verify status against the current official HIPAA regulatory text and HHS guidance, which are periodically amended.
Why it matters
The Covered Entity classification is the threshold question that determines whether HIPAA's obligations apply to an organization at all. If an organization qualifies as a health plan, healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with a covered transaction, it is directly subject to HIPAA's requirements. Misjudging this status can lead an organization either to overlook obligations it is legally bound to meet or to expend resources on requirements that may not apply in the way assumed.
The distinction also matters because HIPAA allocates responsibilities differently among the parties in the healthcare data ecosystem. Covered Entities are the primary regulated parties, while Business Associates—third parties handling protected health information on a Covered Entity's behalf—carry related but distinct obligations, typically governed through contractual arrangements. Treating these roles as interchangeable can produce gaps in compliance programs, misassigned accountability, and flawed contractual protections. Compliance officers and counsel therefore need to establish, as a factual matter, which role an organization occupies before designing controls around it.
Because HIPAA is a U.S. federal regulation, the Covered Entity concept is specific to the United States and does not carry the same meaning under other jurisdictions' privacy regimes. Organizations operating across borders should not assume that qualifying (or not qualifying) as a Covered Entity resolves their obligations under other frameworks. Classification is fact-specific and the underlying regulatory text is periodically amended, so determinations should be verified against the current official HIPAA text and HHS guidance rather than treated as settled once and for all.
Who it's relevant to
Inside Covered Entity
Common questions
Answers to the questions practitioners most commonly ask about Covered Entity.

