Last year, a small chiropractic clinic in Indiana called me in a panic. They'd just received a letter from the Office for Civil Rights (OCR) requesting documentation of their HIPAA policies. The owner's first question floored me: "Does HIPAA even apply to us?" After twelve years in practice, he genuinely didn't know whether his office qualified as a covered entity.
He's not alone. I've seen this confusion at billing companies, solo dental practices, and even mid-size hospitals that assumed only "big healthcare" had to worry about federal privacy law. So let's define covered entity once and for all — and more importantly, explain why getting this wrong can cost you millions.
How Federal Law Defines a Covered Entity
Under the HIPAA Privacy Rule, a covered entity falls into exactly three categories. Not four. Not "it depends." Three.
- Health care providers who transmit any health information electronically in connection with a HIPAA-covered transaction. This includes doctors, clinics, psychologists, dentists, chiropractors, nursing homes, and pharmacies.
- Health plans, which include health insurance companies, HMOs, employer-sponsored group health plans, Medicare, and Medicaid.
- Health care clearinghouses, which are entities that process nonstandard health information into standard formats (or vice versa). Think billing services that convert claims into standard electronic formats.
That's the legal framework. You'll find the exact statutory language in 45 CFR § 160.103. But what trips people up isn't the definition — it's the application.
The Electronic Transaction Trigger Most Providers Miss
Here's what I tell every physician who asks: if your practice submits claims electronically — or has someone do it on your behalf — you're a covered entity. Period. It doesn't matter if you're a solo practitioner working out of a converted garage.
The key phrase is "in connection with a transaction covered by HIPAA." Those transactions include claims, eligibility inquiries, referral authorizations, and payment remittance. If you bill Medicare or any commercial insurer electronically, you've crossed the line.
I've worked with practices that assumed because they used a third-party billing company, the billing company was the covered entity and they weren't. Wrong. Both are. The practice is the covered health care provider. The billing company is likely a business associate — and possibly a clearinghouse. Each has distinct obligations under the law.
The $5.55 Million Mistake: Why Defining Your Status Matters
In 2017, Memorial Healthcare System paid $5.55 million to settle HIPAA violations with OCR. Among the issues: insufficient access controls that allowed employees to access protected health information (PHI) of 115,000 individuals. Memorial knew it was a covered entity. The problem was acting like the obligations were optional.
Now imagine an organization that doesn't even realize it qualifies. No risk assessment. No Notice of Privacy Practices. No workforce training. No breach notification procedures. When OCR comes knocking, ignorance of your covered entity status doesn't reduce the penalty — it amplifies it.
If your organization handles PHI and fits any of the three categories above, you need a training program in place yesterday. Our HIPAA training for physicians and clinical environments is built specifically for providers who need to get their teams compliant quickly and thoroughly.
What About Business Associates? Are They Covered Entities?
No. And this distinction matters more than most people realize.
A business associate is a person or organization that performs functions or activities on behalf of a covered entity that involve access to PHI. Examples include IT vendors who maintain your EHR, billing companies, shredding services, and cloud storage providers.
Business associates have their own obligations under the HIPAA Omnibus Rule of 2013 — including direct liability for certain violations. But they are not covered entities. They operate under business associate agreements (BAAs), not as independent actors under the Privacy Rule.
The confusion I see most often: a home health agency assumes its field nurses are business associates rather than workforce members. They're not. If those nurses are under the agency's direct control — whether employees or contractors — they're part of the covered entity's workforce. That means the agency bears full responsibility for their training and conduct.
If you run a home health operation, this distinction is critical. Our HIPAA training for home health care agencies addresses exactly these workforce classification issues.
Quick Answer: What Does "Covered Entity" Mean Under HIPAA?
A covered entity is any health care provider that transmits health information electronically in connection with covered transactions, any health plan, or any health care clearinghouse. These three categories of organizations must comply with the HIPAA Privacy, Security, and Breach Notification Rules. The definition comes from 45 CFR § 160.103, enforced by the U.S. Department of Health and Human Services (HHS) through its Office for Civil Rights.
Three Real Scenarios That Clarify the Gray Areas
Scenario 1: The Cash-Only Psychiatrist
A psychiatrist accepts only cash. No insurance billing. No electronic claims. Is she a covered entity? Probably not — unless she submits any covered electronic transaction. The moment she electronically verifies a patient's insurance eligibility, even once, she crosses the threshold. I've seen this happen with practices that are "mostly cash" but occasionally submit a claim for a patient who requests it.
Scenario 2: The Employer Who Self-Insures
A manufacturing company with 500 employees runs a self-insured health plan. That health plan is a covered entity. The company itself may not be. But the plan's administrators, the data they handle, and the ePHI flowing through their systems all fall under HIPAA. Many employers don't realize their HR departments are handling PHI subject to federal privacy law.
Scenario 3: The Medical Billing Startup
A tech startup builds software that processes insurance claims for small practices. If they're converting nonstandard data into standard electronic formats, they're a health care clearinghouse — and a covered entity. If they're just providing a platform that practices use to submit their own claims, they're more likely a business associate. The distinction hinges on whether the entity itself processes the transaction.
What OCR Actually Looks For When They Investigate
I've helped organizations respond to OCR investigations, and the first thing investigators establish is whether the entity is covered. Once they confirm that, they look for evidence of six core compliance elements:
- A completed and current risk assessment
- Written privacy and security policies
- Documented workforce training
- Business associate agreements with all applicable vendors
- Breach notification procedures
- A designated privacy officer and security officer
Missing any of these doesn't just invite a corrective action plan. It can trigger civil monetary penalties ranging from $100 to over $2 million per violation category, per year. HHS publishes its enforcement results on the OCR enforcement highlights page, and the numbers are sobering.
Your Covered Entity Status Isn't Optional — And Neither Is Training
Here's what I want you to take away from this. You don't get to decide whether you're a covered entity based on your size, your budget, or your comfort level with federal regulation. The law decides based on what you do and how you do it.
If you transmit electronic health transactions, offer a health plan, or process claims as a clearinghouse, you're in. And once you're in, HIPAA expects you to act like it — with trained staff, documented policies, and a culture that takes PHI seriously.
The organizations that get crushed by OCR enforcement aren't usually the ones who had a bad day. They're the ones who never built the foundation. They never trained their workforce. They never conducted a risk assessment. They operated for years under the assumption that HIPAA was someone else's problem.
Don't be that organization. Start with understanding your status. Then build from there. Our full training catalog gives you the tools to get every member of your workforce — from front desk to C-suite — aligned with what the law actually requires.
Because when OCR sends that letter, "I didn't know we were a covered entity" is the most expensive answer you can give.