A $4.3 Million Penalty — Because They Didn't Think They Were a CE
In 2014, New York Presbyterian Hospital and Columbia University collectively paid $4.8 million to the Office for Civil Rights after a breach exposed the ePHI of 6,800 patients. Part of the problem? Confusion about which entity bore responsibility for what. When organizations don't understand the concept of a CE in HIPAA — the covered entity — they fumble the most basic compliance obligations.
I've watched this play out for over a decade. The term "covered entity" sounds bureaucratic, but misunderstanding it is the single fastest path to an OCR investigation. If you run a healthcare organization, bill for health services, or transmit health data electronically, you need to know exactly where you stand.
This post breaks down who qualifies as a CE in HIPAA, what obligations come with that designation, and the specific enforcement patterns OCR is following in 2026.
What Does CE in HIPAA Actually Mean?
A CE, or covered entity, is any organization or individual that falls under HIPAA's regulatory umbrella. The law defines three categories of covered entities: health plans, healthcare clearinghouses, and healthcare providers who transmit any health information electronically in connection with certain transactions.
That last part trips people up. You don't have to be a hospital. A solo chiropractor who submits electronic claims to Medicare is a covered entity. A dental office that sends electronic referrals is a covered entity. A small employer health plan covering 50 employees is a covered entity.
The Department of Health and Human Services spells this out in its official guidance on covered entities. If your organization touches PHI and conducts standard electronic transactions, you're almost certainly a CE.
The Three Categories of Covered Entities
- Health Plans: Health insurance companies, HMOs, employer-sponsored group health plans, Medicare, Medicaid, and military health programs like TRICARE.
- Healthcare Clearinghouses: Entities that process nonstandard health information into standard formats. Billing services and repricing companies often fall here.
- Healthcare Providers: Any provider — physician, hospital, pharmacy, nursing home — that transmits health information electronically for transactions like claims, benefit eligibility inquiries, or referral authorizations.
Notice the word "transactions." Simply using email doesn't make you a covered entity. But submitting an electronic claim to an insurer does. The distinction matters.
Why the CE Designation Carries So Much Weight
The moment you qualify as a CE in HIPAA, every provision of the Privacy Rule, Security Rule, and Breach Notification Rule applies to you. There's no partial compliance. There's no grace period for small organizations.
Here's what that means in practical terms:
- You must designate a Privacy Officer and a Security Officer (can be the same person in smaller organizations).
- You must conduct a thorough risk analysis of all systems that create, store, or transmit ePHI.
- You must implement administrative, physical, and technical safeguards.
- You must train every member of your workforce — not just clinicians, but front desk staff, billing teams, and volunteers.
- You must execute Business Associate Agreements (BAAs) with every vendor that handles PHI on your behalf.
- You must have a documented breach notification process ready to deploy within 60 days of discovering a breach.
Skip any one of those, and you're vulnerable. OCR doesn't care whether you knew you were a covered entity. Ignorance has never been a defense.
The Penalty Structure Is Not Hypothetical
OCR enforces HIPAA through a tiered penalty system. At the low end, violations where the entity "did not know" can cost $137 to $68,928 per violation. At the high end — willful neglect left uncorrected — penalties reach $2,067,813 per violation, per year. These numbers are adjusted annually and published on HHS's enforcement page.
In 2018, Anthem Inc. paid $16 million — still the largest HIPAA settlement in history — after a breach affecting nearly 79 million people. Anthem was a health plan, a textbook covered entity, and OCR found systemic noncompliance: no enterprise-wide risk analysis, insufficient procedures to review information system activity, and failure to identify and respond to a suspected breach.
CE vs. BA: The Line That Gets Blurred Every Day
One of the most common questions I hear: "Are we a covered entity or a business associate?" The answer determines which rules apply directly to you and which flow through a contractual agreement.
A business associate (BA) is a person or organization that performs a function or activity on behalf of a covered entity that involves access to PHI. Cloud storage providers, billing companies, IT managed service providers, and EHR vendors are common examples.
BAs have direct liability under HIPAA since the HITECH Act of 2009. But the scope of obligations differs. CEs carry the full weight of the Privacy Rule. BAs are primarily bound by the Security Rule and specific Privacy Rule provisions outlined in their BAA.
Here's the critical point: if you're a CE, you're responsible for ensuring your BAs are compliant. You can't outsource accountability. When a BA causes a breach, OCR investigates the CE too.
Training Requirements for Covered Entities Are Not Optional
Section 164.530(b) of the Privacy Rule requires covered entities to train all workforce members on HIPAA policies and procedures. Section 164.308(a)(5) of the Security Rule requires security awareness training. These aren't suggestions.
I've seen organizations treat training as a checkbox — a 10-minute video once a year. Then a staff member falls for a phishing email, or a receptionist hands records to the wrong patient, and suddenly the lack of documented, role-specific training becomes Exhibit A in an OCR investigation.
If your workforce hasn't completed updated training this year, start with the HIPAA Introduction Training 2026 course. It covers the foundational rules every workforce member at a covered entity needs to understand.
For clinical staff who handle PHI daily, the HIPAA Training for Nurses course addresses the specific workflow scenarios where breaches actually happen — bedside conversations, EHR access, and patient handoffs.
What Counts as "Workforce" Under HIPAA?
More than you think. HIPAA defines workforce as employees, volunteers, trainees, and any other person whose conduct is under the direct control of the covered entity — whether or not they are paid. That includes medical students doing clinical rotations, temporary administrative staff, and even board members with access to PHI.
Every one of those people needs training. Every one of those people needs to be included in your compliance program.
The 2026 Landscape: Heightened Scrutiny on CEs
HHS has proposed significant updates to the HIPAA Security Rule, including more prescriptive requirements around encryption, multi-factor authentication, and network segmentation. While the final rule is still working through the regulatory process, covered entities should be preparing now.
OCR has also continued its Right of Access Initiative, which has produced over 45 enforcement actions since 2019. These cases target covered entities that fail to provide patients with timely access to their records. Penalties have ranged from $3,500 to $240,000 — and every single respondent has been a CE.
The message is clear: if you're a covered entity, OCR expects you to know your obligations thoroughly and execute them consistently.
How to Confirm Your CE Status and Lock Down Compliance
If you're unsure whether your organization qualifies as a covered entity, HHS provides a covered entity decision tool on CMS.gov. Answer the questions honestly. If the tool says you're a CE, act accordingly.
Once confirmed, here's a practical compliance sequence:
- Step 1: Appoint your Privacy and Security Officers.
- Step 2: Complete a comprehensive risk analysis. Document everything.
- Step 3: Develop or update your policies and procedures.
- Step 4: Execute BAAs with every vendor touching PHI.
- Step 5: Train your entire workforce with role-appropriate courses. The HIPAA Fundamentals course covers the regulatory framework in detail.
- Step 6: Test your breach notification procedures annually.
- Step 7: Reassess annually. Compliance isn't a one-time project.
The Bottom Line for Every CE in HIPAA
Being a covered entity under HIPAA isn't a label. It's a legal status that triggers a comprehensive set of obligations — obligations that OCR actively enforces with real financial penalties and corrective action plans that can consume years of organizational energy.
I've consulted with organizations that didn't realize they were covered entities until they received a complaint letter from OCR. By then, the cost of catching up was ten times what proactive compliance would have been.
Don't be that organization. Know your status, train your people, document your safeguards, and take the CE designation as seriously as OCR does.