Blog post
Blog post

Who Does HIPAA Apply To? Covered Entities Explained

HIPAA applies to covered entities, meaning health plans, healthcare clearinghouses, and providers that transmit health information electronically in standard transactions, plus the business associates that handle PHI on their behalf. This plain-language explainer defines each term so you can tell in minutes whether HIPAA applies to your practice.

If you’ve ever done a search for HIPAA compliance, you’ll know that there is a lot of information available on various HIPAA regulations and violations, including some directly from the government.

So what’s the issue? Most of it is dense, and there is little guidance on how it impacts emerging care models and the use of new digital tools, such as email, texting, and apps.

To help combat this confusion, we’re going to spend the next few blog posts covering some essential, need-to-know HIPAA tips and explanations, hopefully in a way that won’t make your eyes glaze over.

HIPAA Compliance: Does It Matter for Me?

This is the #1 important question in all matters HIPAA. First, it is essential to understand that HIPAA is federal law and is therefore administered by a national department, the Department of Health and Human Services (HHS). The final word on HIPAA rests with HHS, and the law potentially applies to everybody in the United States.

With that said, the actual scope of HIPAA for people providing healthcare is much smaller. From HHS: “The HIPAA Rules apply to covered entities and business associates.”

This by itself is not very useful until you substitute in the meanings of “covered entity” and “business associate,” both of which are technical terms in the law.

HIPAA Compliance: What Is a “Covered Entity”?

A “covered entity” is any healthcare provider that conducts certain transactions in electronic form (45 CFR §160.103). Health plans and healthcare clearinghouses are also covered entities, but that’s not relevant for most doctors.

What Is a “Business Associate”?

“Business associate” also has a specific definition, but the essential point is that anybody conducting business with a covered entity is also subject to HIPAA if that business includes exposure to protected health information (PHI) from the covered entity.

HIPAA requires covered entities to obtain written assurance of compliance from potential business associates before disclosing PHI to them, so if you’re a doctor storing patient information on Gmail, and Google hasn’t signed a business associate contract for you, you might be afoul of the law already.

What Are “Transactions in Electronic Form”?

You may have noticed a strange bit of language in the definition for covered entity: “…any healthcare provider that conducts certain transactions in electronic form.” What is that about?

Technically, HIPAA only applies to providers who are transmitting financial or administrative healthcare information electronically, such as computerized insurance claims or eligibility checks.

In modern practice, almost everybody is doing at least some type of electronic transaction, but if you somehow aren’t, then HIPAA won’t apply to you. That sounds strange, but the Centers for Medicare and Medicaid Services (CMS) provides a confirmatory flowchart, if you want to check our math.

Important note: If another entity does your electronic transactions for you, then for HIPAA compliance and coverage purposes, that still counts as you doing it.

Do the HITECH Act and Omnibus Rule Impact HIPAA Compliance?

HIPAA (Health Insurance Portability and Accountability Act) was passed into federal law in 1996, and parts of it were updated by the HITECH Act, which was passed in 2009. HHS develops federal regulations based on these laws, and these are the actual rules that health care providers must follow. HHS initially wrote such rules after the passage of HIPAA, and they recently updated them with an “Omnibus Rule.”

The only important take-away is to follow the current regulations and guidance that HHS has published; they will have already taken all of the relevant legislation into account.

HIPAA Compliance: What About State Law

Great question, glad you asked. In general, HIPAA provides a “floor” of privacy protection, meaning that states cannot have laws that are more lenient than HIPAA. States can, however, have laws that are more strict or far-reaching than HIPAA, and many do. Understanding HIPAA is a good starting point, but it’s also important to be informed about health privacy law in each state in which you practice.

HIPAA Compliance Is Intricate!

Yes, even the bare-bones version is still complicated. Time for an executive summary.


Does HIPAA Compliance Apply to Me?

YES. If you are providing healthcare in the United States, you can safely assume, with a high degree of certainty, that HIPAA compliance is important for you.

Frequently Asked Questions

Who does HIPAA apply to?

HIPAA applies to covered entities (health plans, healthcare clearinghouses, and providers that transmit health information electronically in standard transactions) and to their business associates, the vendors that handle PHI for them. Most practicing clinicians and the companies serving them fall under one of the two categories.

What is a covered entity under HIPAA?

A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically as part of standard transactions like billing. If your practice bills insurance electronically, you are almost certainly a covered entity.

What is a business associate under HIPAA?

A business associate is any outside company that creates, receives, maintains, or transmits PHI on a covered entity’s behalf, such as billing services, EHR vendors, communication platforms, and IT or cloud providers. They are bound by HIPAA through a signed BAA.

If HIPAA applies to me, does my communication vendor need a BAA?

Yes. Any vendor that handles PHI on your behalf is a business associate and needs a signed BAA. Every eligible Spruce organization automatically receives a HIPAA Business Associate Agreement as part of the terms of service, with no separate agreement, opt-in, or additional fees, so your phone, text, fax, and messaging are covered.

This article is part of a series of posts relating to HIPAA law and regulation. The information provided is meant as general guidance only and is not intended to be legal advice.

Related Articles