A covered entity refers to a health plan, a healthcare clearinghouse, or a healthcare provider that is involved in the transmission of health information electronically with respect to normal transactions, as stated in 45 CFR 160.103 (HHS). Simply put, in case an organization has patient data and transmits it electronically to make billing, eligibility, or claims, HIPAA is probably in force. This definition matters because it determines who should comply with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, and who has the potential to be subject to enforcement in the event of any violation.
These rules are actively enforced by regulators. In 2024, the HHS Office for Civil Rights settled 22 cases with financial fines, with numerous cases being related to simple compliance violations such as the absence of risk assessments and poor protection (HHS OCR, HIPAA Journal). Consequently, the covered entity status influences the legal exposure, financial risk, and patient trust. It also influences the organizational approach to PHI and ePHI, collaboration with vendors, and documentation of compliance.
This article breaks down the types of covered entities, explains the electronic transmission requirement, and walks through responsibilities and risks so business owners can clearly understand where they stand and what steps to take next. If you are unsure how federal rules apply to your operations, this breakdown of entities covered by HIPAA provides additional clarity on classifications and obligations:
Are You a HIPAA Covered Entity?
Find out in minutes and understand your compliance obligations.
Legal Definition Under 45 CFR 160.103
The official HIPAA covered entity definition comes from 45 CFR §160.103, issued by the Department of Health and Human Services (HHS). Under this regulation, a covered entity is any health plan, healthcare clearinghouse, or healthcare provider that transmits health information in electronic form in connection with transactionsto which HHS has established standards, including claims, eligibility inquiries, payment requests, or referral authorizations (45 CFR §160.103, HHS).
The size of the organization is not of importance here, but the activity. A small clinic, a solo practitioner, or even a startup turns into a covered entity as soon as the first standard electronic transaction is performed. The minimum number of patients or revenue requirement is nonexistent. HIPAA comes into play in case electronic transmission is made in the event of covered transactions.
When this status becomes activated, an organization is deemed to be legally bound by the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule. Since then, the covered entity should safeguard PHI and ePHI, adhere to the minimum required standard, carry out risk assessment, and act to address breaches as required by the federal law. Lack of knowledge or lateness of knowledge does not warrant enforcement or punishment.
Healthcare Providers
The providers of healthcare are individuals or organizations that offer medical or health-related services and charge for such services. In HIPAA, a provider is a covered entity only when health information is sent electronically in relation to the usual dealings like claims, checking eligibility, referrals, or payment enquiries, as specified by HHS.
This is a vital requirement. Being a provider does not make one a covered entity just because one is treating patients or keeping paper records. The covered entity status is initiated as soon as the electronic transactions are made. This means utilizing electronic health records, making a claim to the insurers, or third-party billing platforms. After activation, HIPAA is applicable in totality.
Since then, the provider has to abide by the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. This covers the protection of PHI and ePHI; access should be limited to the minimum, staff should be trained, and the response to breaches should be adequate. Notably, the HIPAA compliance requirements do not lessen when the electronic transactions are eventually discontinued.
Examples of Healthcare Providers Covered by HIPAA
1 - Hospitals and hospital systems
Hospitals and hospital systems are covered entities as they regularly transfer electronic health information in a bid to make billing, referral, and care coordination. They handle high numbers of electronic health records and communicate with insurers, laboratories, and experts via standardized electronic transactions.
2 - Physician practices and clinics
Physician practices and outpatient facilities will become covered entities when they submit electronic claims or eligibility verifications to the health plans. Small practices are also subject to HIPAA when they are under electronic billing or EHR.
3 - Dentists, orthodontists, and oral surgeons
Dental providers are covered entities that send patient information electronically to make an insurance claim or coordinate treatment. This encompasses general dentists and those who are experts, like the orthodontists and oral surgeons.
4 - Pharmacies (retail and mail-order)
Retail and mail-order pharmacies are considered covered entities since they receive electronic prescriptions and insurance transactions. They process ePHI on a regular basis in regard to medication dispensing and billing of patients.
5 - Psychologists, therapists, and counselors
Mental health professionals are covered entities that transfer health information electronically for payment or administrative purposes. This is in the case of individual practices, group therapy clinics, and behavioral health providers.
6 - Chiropractors and physical therapists
When chiropractic and physical care providers transmit treatment data electronically or exchange the information via computer networks with insurers, the providers turn into covered entities.
7 - Nursing homes and home health agencies
The long-term care homes and home health agencies are covered entities because they have continuous electronic interaction with the health plans, physicians, and care teams.
8 - Laboratories and diagnostic imaging centers
Covered entities Llabs and imaging centers are covered entities since they send electronic test results, reports, and billing information as routine healthcare activities.
9 - Telemedicine providers
The providers of telemedicine are nearly always covered entities because the process of delivering care is based on the electronic transfer of health information with the help of digital platforms and remote communication tools.
10 - Urgent care centers and ambulatory surgery centers
Urgent care clinics and ambulatory surgery centers are covered entities when they file electronic claims, have EHRs, or share patient information electronically when giving treatment and follow-up.
Key clarification
Cash-only healthcare providers who do not send health information electronically to complete routine transactions are not termed as covered entities under HIPAA. But when electronic transmission comes, HIPAA requirements take effect in their entirety.
Running a Healthcare Practice?
Ensure your systems, staff, and workflows meet HIPAA requirements.
Health Plans
A health plan, according to HIPAA, is an individual or group plan that covers or reimburses medical care. The covered entity in this category is the health plan and not the employer that is sponsoring the health plan. This is significant since HIPAA requirements would be relevant to the activities, information management, and release of Protected Health Information of the plan.
Health plans regularly receive, process, and transmit health information to support enrolment, claims, and payment processes. These transactions are electronic in nature, and therefore HIPAA is automatic. Consequently, the Privacy Rule, Security Rule, and Breach Notification Rule have to be adhered to by health plans. They also have to restrict access to PHI, use the least possible standard, and have clear policies on member rights and disclosures.
To understand how HIPAA applies beyond hospitals and clinics, it helps to look at the broader ecosystem of vendors and partners involved in healthcare operations. Many organizations underestimate their responsibilities until they review how HIPAA compliance service providers are defined and regulated. This becomes especially important for IT vendors, cloud platforms, and consultants that touch ePHI at any stage.
Examples of Health Plans Covered by HIPAA
1 - Health insurance companies
Health insurance companies are covered entities since they handle claims, coverage determinations, and payment through electronic systems that contain PHI.
2 - Health Maintenance Organizations (HMOs)
HMOs are covered entities since they coordinate care and process electronic health information for both treatment and payment purposes.
3 - Preferred Provider Organizations (PPOs)
PPOs communicate the health information through electronic means so as to administer networks, claims, and reimbursements. This activity puts them under the HIPAA coverage.
4 - Employer-sponsored group health plans
Employer-provided group health plans are covered entities. Although the plan is the responsibility of the employer, HIPAA compliance is taken care of by the plan.
5 - Self-funded employer health plans
Plans that are self-funded are entities covered even in cases where the employer makes direct payments on claims. HIPAA is applicable in the administration and treatment of data in the plan.
6 - Medicare and Medicare Advantage
Medicare programs can be considered covered entities since they handle high amounts of electronic health information to service and pay beneficiaries.
7 - Medicaid and CHIP
Covered entities include State Medicaid programs and the Children’s Health Insurance Program. They handle payments, claims, and eligibility using electronic systems that deal with PHI.
8 -TRICARE (military health system)
TRICARE is a covered entity since it covers health benefits to the active-duty services, retirees, and their families. The program processes electronic claims, eligibility data, and treatment information, and this makes it subject to full HIPAA requirements.
9 - Veterans Health Administration programs
The programs at Veterans Health Administration qualify as covered entities because they provide and reimburse healthcare services using electronic systems. These programs process huge amounts of PHI regarding treatment, billing, and care coordination.
10 -Federal Employees Health Benefits Program
The Federal Employees Health Benefits Program is a covered entity since it provides health coverage to the federal employees and retirees. Electronic communication of enrollment information, claims, and payments elicits HIPAA requirements.
11 -Long-term care insurance
When they provide medical or custodial care and they transmit health information electronically, long-term care insurance plans are covered entities. HIPAA is relevant to the way such plans gather, store, and share PHI.
12 - Medicare Supplement (Medigap) policies
Medigap policies are covered entities as they are a supplement to the Medicare coverage, and they are based on electronic health information processing claims, and benefits coordination.
Exceptions
Workers’ compensation carriers
The workers' compensation insurers cannot be considered the covered entity as they offer benefits concerning workplace injuries and not healthcare coverage under HIPAA.
Auto and casualty insurers
HIPAA does not cover auto and casualty insurance companies because they do not deal with health plans as intended by the federal law, but with accident-related claims.
Life insurance companies
Life insurers are not covered entities since their products are not used to pay for healthcare services or even to undertake normal HIPAA transactions.
Disability income insurance
Disability income insurers do not qualify as covered entities since they consist of wage replacement benefits and not medical coverage, and are not described in HIPAA as a health plan.
Managing a Health Plan?
Reduce compliance risk and strengthen data protection frameworks.
Healthcare Clearinghouses
A healthcare clearinghouse is an organization that transforms health information that is received by another organization into a standard format. It can also transform normal electronic transactions into nonstandard forms. This definition is the direct result of 45 CFR 160.103, the publication of the Department of Health and Human Services (HHS).
Role as data format intermediaries
Healthcare clearinghouses are technical intermediaries. They do not tend to offer medical services and cover. They instead decode, authenticate, and direct health data so that it may flow between health plans and providers. Since this work is associated with the electronic transmission of PHI and ePHI, the clearinghouses are considered covered entities when it comes to HIPAA. Size does not matter. The coverage is caused by the mere presence of the function.
Clearinghouses are also essential in claims processing as well as payment processes. Consequently, they are forced to adhere to the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. They also need to exercise effective technical protection and have elaborate audit controls.
Examples of Healthcare Clearinghouses
1 - Medical billing clearinghouses
Healthcare providers submit claims to these organizations, which subsequently transform them into standard electronic formats and send them to health plans.
2 - Claims repricing companies
Claims repricing entities modify bills in accordance with contract requirements. They serve as healthcare clearinghouses when they process this data electronically under HIPAA.
3 - Value-added networks (VANs)
VANs also safely convey electronic healthcare transactions among payers and providers. HIPAA is applicable because it deals with PHI in a standard format.
4 - Community health information systems
The systems help in electronic data sharing between various healthcare institutions. Their translation or routing of standardized transactions can qualify them as meeting the definition of the clearinghouse and they are considered a covered entity under HIPAA.
5 - EDI (Electronic Data Interchange) gateways
EDI gateways are classified as healthcare clearinghouses when they transform healthcare data, and put it in standard transaction formats. These gateways allow providers and health plans to transmit claims, eligibility requests and payment data electronically. HIPAA is applicable to the full extent of the operations of EDI gateways because they process PHI during such transactions.
6 - Health Information Exchanges (format conversion function)
Health Information Exchanges are covered entities that conduct format conversion between standard and nonstandard data. An exchange that merely archives or directs information without exchanging it can be a business partner. Nonetheless, it becomes a healthcare clearinghouse once it converts data formats.
Functions of Healthcare Clearinghouses
Data standardization and format conversion
Healthcare clearinghouses transform health data into standardized formats to allow it to be transported through various systems. This measure will enable providers and health plans to communicate without compatibility problems. The processing delays and errors are also minimized by standardization. Since PHI is actively processed during conversion, it needs powerful technical protection.