
A HIPAA covered entity is an organization or person that fits one of three HIPAA categories: a health plan, a health care clearinghouse, or a health care provider that conducts certain financial or administrative transactions electronically. HHS summarizes these categories in its guidance on who must comply with HIPAA privacy standards.
Put more plainly, covered-entity status is based on role and regulated activity, not just whether an organization handles health-related information. This guide helps you apply the categories, distinguish covered entities from business associates and non-covered entities, and document the reasoning behind your classification. It is educational guidance, not legal advice.
What Is a HIPAA Covered Entity?
A HIPAA covered entity is an organization or individual that falls into one of HIPAA’s covered-entity categories. The category test.
- Health plans.
- Health care clearinghouses.
- Health care providers that transmit health information electronically in connection with transactions for which HHS has adopted HIPAA standards.
The important practical point is that “we handle health data” is not the same as “we are a covered entity.” A software vendor, wellness service, employer program, or health-data platform may need HIPAA analysis, but classification depends on its function, relationships, data source, and transactions, not the presence of health-related data alone.
The Three Types of HIPAA Covered Entities
1. Health plans
Health plans generally provide or pay the cost of medical care. HHS examples include health insurers, HMOs, Medicare, Medicaid, and employer-sponsored group health plans, some exceptions still apply, such as certain small employer-administered plans and certain government programs or insurance lines. HHS explains these categories in its Summary of the HIPAA Privacy Rule.
Use this test:
Does the organization provide or pay for the cost of medical care as a health plan?
If yes, it is likely a covered entity, subject to confirmation of any applicable exception.
2. Health care clearinghouses
A health care clearinghouse processes health information between nonstandard and standard formats or data content, or the reverse. In practical terms, this category applies to entities that convert health transaction data so it can move between systems or parties in the required format.
Use this test:
Does the organization process or convert health information between standard and nonstandard transaction formats or data content?
If yes, it is likely a covered entity as a clearinghouse.
3. Health care providers that conduct standard electronic transactions
A health care provider is a covered entity when it transmits health information electronically in connection with a transaction for which HHS has adopted a HIPAA standard. HHS is clear that using email or other electronic technology alone does not establish covered-entity status. A provider may also transmit through a billing service or another third party acting on its behalf.
Use this test:
Does the provider transmit health information electronically in connection with an HHS-adopted standard transaction?
If yes, the provider is likely a covered entity.
Why Not Every Health Care Provider Is Automatically a Covered Entity
A provider can deliver health care services and still need to evaluate whether it conducts covered electronic transactions. The trigger is not having a website, using email, maintaining an electronic record system, or communicating through an app. The trigger is transmitting health information electronically in connection with a HIPAA standard transaction.
That is the basic rule. More precisely, the question is whether the provider or someone acting for the provider is sending one of those standard transactions electronically.
HHS-adopted electronic transaction standards include, for example, health claims and eligibility-and-benefit verification. HHS also identifies claims, benefit-eligibility inquiries, and referral-authorization requests as examples of relevant provider transactions in its Adopted Standards and Operating Rules.
For classification, ask:
- Do we submit health claims electronically?
- Do we conduct eligibility or benefits inquiries electronically?
- Do we submit referral authorization requests electronically?
- Does a billing service or other third party transmit these transactions on our behalf?
If the answer is unclear, do not assume either outcome. Document the known facts, identify the systems or third parties involved, and seek legal or compliance review.
Covered Entity vs Business Associate vs Non-Covered Entity
An organization that handles protected health information may be a covered entity, a business associate, both in different contexts, or neither. The classification depends on what the organization is doing and for whom.
HHS describes a business associate as generally a person or organization, other than a covered entity’s workforce member, that performs specified functions or services for a covered entity involving protected health information. When a covered entity uses a business associate, HIPAA generally requires written protections through a business associate agreement or other permitted arrangement, as described in the Summary of the HIPAA Privacy Rule.
| Classification | Main test | Simple example | Next step |
|---|---|---|---|
| Covered entity | Fits one of the three HIPAA categories | Health plan, clearinghouse, or provider conducting standard electronic transactions | Assess applicable HIPAA obligations |
| Business associate | Performs specified services or functions for a covered entity involving PHI | A service provider handling PHI for a covered-entity customer | Confirm role, scope, and written protections |
| Non-covered entity | Does not fit a covered-entity category and is not acting as a business associate | Fact-specific; do not classify by data type alone | Assess other privacy, security, contractual, or sector obligations |
| Needs review | Facts are mixed, unclear, or changing | Multi-function organization or uncertain transaction path | Obtain legal/compliance review |
A business associate agreement does not, by itself, make the classification analysis complete. It documents a relationship and the protections for that relationship, but the organization still needs to understand whether it is acting as a covered entity, business associate, or in another role.
Some organizations also need hybrid-entity analysis. Under 45 CFR § 164.105, a covered entity that is a single legal entity and performs both covered and non-covered functions may elect hybrid-entity treatment; HIPAA requirements generally apply to its designated health care component or components. Do not assume hybrid status automatically; treat it as a legal/compliance review item.
A Practical HIPAA Covered Entity Decision Flow
Use this as an internal classification workflow based on the official categories. It is not an official HHS decision tool or a legal opinion.
The most common mistake in this flow is stopping at “we are a provider” or “we handle health data.” For providers, the electronic standard-transaction condition is central. For vendors and service providers, the business-associate relationship may be the more relevant analysis.
How to Document Your Covered Entity Decision
As an operational practice, record the facts and assumptions behind the classification and revisit them when those facts materially change, such as services, customers, vendors, transaction types, systems, or data flows. This worksheet is not a HIPAA-required form, legal advice, or a conclusive classification, so keep that in mind.
| Field | Notes to capture |
|---|---|
| Organization name | Legal entity and business unit, if relevant |
| Organization type | Plan, provider, clearinghouse, vendor, service provider, employer program, platform, or other |
| Services offered | What the organization actually does |
| Health plan analysis | Whether it provides or pays for the cost of medical care; note any exceptions to review |
| Clearinghouse analysis | Whether it converts health information between standard and nonstandard formats or data content |
| Provider analysis | Whether it furnishes health care services |
| Standard electronic transactions | Claims, eligibility-and-benefit verification, referral authorization, or other HHS-adopted transactions, if any |
| Transmission path | Direct transmission, billing service, clearinghouse, customer system, or other third party |
| PHI handled | What PHI is handled and where it comes from |
| Covered-entity customers or partners | Any customer or partner asserting covered-entity status |
| Vendor relationships involving PHI | Vendors, subcontractors, platforms, or processors involved |
| Initial classification | Covered entity, business associate, non-covered entity, hybrid/partial entity, or needs review |
| Supporting evidence | Contracts, transaction logs, payer enrollment materials, system diagrams, policies, counsel notes, or source links |
| Open questions | Ambiguous facts, changing services, uncertain transaction types, or hybrid-entity issues |
| Reviewer | Name and role |
| Review date | Date of classification decision |
| Revisit trigger | Events that should reopen the analysis |
Ciphrix’s perspective is that this kind of classification record should not sit apart from the compliance program. Once an organization determines that it is likely a covered entity or business associate, the same facts should connect to controls, evidence, vendor oversight, and ongoing compliance workflows. Ciphrix can support the operational work of documenting controls and compliance evidence; it does not determine legal classification.
What to Do Next If You Are a HIPAA Covered Entity
If your organization appears to be a covered entity, take the classification into a structured compliance review rather than basically treating the decision as the finish line.
Prioritize these steps:
- Confirm the classification with qualified legal or compliance advisers.
- Identify PHI systems, data flows, vendors, and workforce access.
- Assess the HIPAA Privacy, Security, and Breach Notification Rules with qualified advisers. HHS summarizes the Security Rule and Breach Notification Rule; Security Rule administrative safeguards include risk analysis for electronic PHI and assigned security responsibility under 45 CFR § 164.308.
- Identify business associate relationships and whether written protections are needed.
- Establish appropriate policies, controls, training, evidence collection, and review cycles.
- Revisit the classification when services, transactions, customer relationships, vendors, or data flows materially change.
Classify using the official categories, pay special attention to provider electronic transactions, separate covered-entity status from business-associate relationships, and preserve the evidence behind the decision. Where facts are ambiguous, document the uncertainty and get review before relying on the classification.

