A wellness startup emails your front desk asking for a data feed. A billing company sends you a 14-page contract with a business associate agreement stapled to the back. A physician joining your group runs a cash-only aesthetics side practice and insists HIPAA doesn't touch it. Every one of those conversations turns on the same regulatory text: the covered entity definition at 45 CFR 160.103.

This article is for the person who has to answer those questions in writing. You will get the three-part test, the electronic transaction trigger that decides most provider questions, the structural elections available when only part of your organization is in scope, and the documentation that survives an Office for Civil Rights inquiry. No patient-facing generalities.

The Covered Entity Definition, Verbatim and in Practice

HIPAA regulates three categories of organizations directly. The regulation names them plainly: health plans, health care clearinghouses, and health care providers who transmit any health information in electronic form in connection with a covered transaction.

That third clause is where practices live or die. Being a provider does not make you a covered entity. Being a provider who bills electronically — or who has a third party do it on your behalf — does.

Health Plans

Group health plans with 50 or more participants or that are administered by a third party, health insurance issuers, HMOs, Medicare, Medicaid, Medicare supplement issuers, and long-term care policies that cover medical services. If your practice sponsors a self-funded group health plan for your own employees, that plan is a separate covered entity from your clinic, with its own obligations. Most administrators miss this entirely.

Health Care Clearinghouses

Entities that translate nonstandard health data into standard transactions, or the reverse. Billing services that reformat claims, repricing companies, value-added networks. A clearinghouse that only handles data as a business associate of a covered entity operates under a narrower set of obligations, but it is still a covered entity in its own right.

Health Care Providers Who Transmit Electronically

Physicians, dentists, chiropractors, nursing homes, pharmacies, labs, therapists, DME suppliers. The status hinges on whether the provider conducts one of the HHS-adopted standard transactions electronically: claims, eligibility inquiries, claim status requests, referral certification and authorization, coordination of benefits, remittance advice, premium payments, or enrollment.

HHS maintains a plain-language overview of these three categories on its covered entities and business associates page. Read it alongside the regulatory text, not instead of it.

Am I a Covered Entity? A Three-Question Test

Answer these in order. Stop at the first yes.

  1. Do you furnish, bill for, or get paid for health care in the normal course of business? If no, you are not a provider and the analysis ends unless you are a plan or clearinghouse.
  2. Does your organization — or anyone acting on your behalf — transmit any of the HHS-adopted standard transactions in electronic form? Submitting a claim through a clearinghouse counts. Checking eligibility through a payer portal counts. Faxing a paper claim does not. A billing company doing it for you counts as you doing it.
  3. If yes to both, you are a covered entity for the entirety of your provider operations — not just the electronic ones. The transaction is the trigger, not the boundary.

That last point is the one practices get wrong most often. A dermatology group that submits one electronic eligibility check per year for one insured patient is a covered entity for all of its patients, including the cash-pay cosmetic ones. There is no per-patient carve-out.

The Electronic Transaction Trigger Explained With Real Scenarios

Cash-only concierge internal medicine. No insurance billing, no eligibility checks, no electronic remittance. Patients pay a membership fee directly. This practice is not a covered entity under the covered entity definition. It still faces state medical privacy law, FTC Section 5 authority over deceptive privacy claims, and the FTC Health Breach Notification Rule if it operates a consumer health app. HIPAA is not the only rulebook.

Same practice, one year later. The physician starts accepting Medicare and submits claims through a clearinghouse. Covered entity as of the first electronic transaction. Every prior chart is now protected health information subject to the Privacy Rule.

Solo therapist who submits superbills to patients on paper. The patient files with their own insurer. The therapist transmits nothing electronically. Not a covered entity — until the therapist starts verifying benefits through a payer web portal.

Physical therapy clinic that uses a billing service. The clinic itself never touches a claim file. The billing service transmits electronically on the clinic's behalf. The clinic is a covered entity, and the billing service is its business associate.

Covered Entity vs. Business Associate: Different Labels, Different Paperwork

A business associate creates, receives, maintains, or transmits protected health information to perform a function on behalf of a covered entity. Since the 2013 Omnibus Rule, business associates are directly liable for Security Rule compliance, for breach notification to the covered entity, and for impermissible uses and disclosures under the Privacy Rule.

The labels are not exclusive. A clearinghouse is a covered entity and a business associate at the same time. A hospital is a covered entity that acts as a business associate when it provides billing services to an unaffiliated physician group. Your status changes with the transaction, not with your NPI.

What matters operationally: once you land inside the covered entity definition, every vendor with access to PHI needs a signed business associate agreement before the access begins. Your IT managed service provider. Your shredding company. Your answering service. Your cloud storage host. Your transcription vendor. HHS spells out the required contract elements in its business associate guidance, including sample contract provisions.

If your vendor list is longer than your signed-agreement folder, close that gap now. You can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you need three agreements this quarter and none next quarter.

When Only Part of Your Organization Is In Scope

Hybrid Entity Designation

A single legal entity performing both covered and non-covered functions may designate itself a hybrid entity and formally identify its health care components. A university with a student health clinic, an academic research arm, and a general admissions office is the classic case. So is a corporation with a self-funded health plan and 900 employees doing unrelated work.

The designation is not automatic. You must document it in writing, list the components, and firewall PHI flows between covered and non-covered parts. Undocumented, the entire legal entity is in scope. That documentation is a two-page memo signed by leadership with a dated component list — not a slide in an orientation deck.

Affiliated Covered Entities

Legally separate covered entities under common ownership or control may designate themselves a single affiliated covered entity for HIPAA purposes. Useful for multi-site groups that want one notice of privacy practices and one policy set. The election must be documented, and all members share liability for the group's compliance posture.

Organized Health Care Arrangements

An OHCA lets clinically integrated entities — a hospital and its medical staff, for example — share PHI for joint operations and publish a joint notice without executing business associate agreements with each other. Different tool, different documentation, same requirement: write it down.

Who Is Not a Covered Entity (and Still Has Duties)

  • Employers. Your practice as an employer is not a covered entity. Employment records held in your employer capacity — FMLA files, drug screen results for hiring, workers' compensation claims — are not PHI, even when they contain medical detail. Store them separately from the personnel file and separately from any group health plan records.
  • Life, disability, and property casualty insurers. Outside the definition. They can request records; you disclose only with a valid authorization.
  • Workers' compensation carriers. Not covered entities. State law governs the disclosure, and the Privacy Rule permits disclosures as authorized by and necessary to comply with workers' comp laws.
  • Direct-to-consumer health apps, wearables, and most wellness platforms. Not covered entities unless they contract with one. The FTC's Health Breach Notification Rule reaches many of these instead.
  • Schools, most law enforcement, and government agencies in their non-health functions.

None of this means the data is unregulated. It means HIPAA is not the regulator. Say that precisely when a vendor claims exemption — ask which framework does apply to them and get the answer in the contract.

What Documented Evidence of Your Status Looks Like

OCR does not accept "we assumed we were covered." Neither does a payer audit or an acquisition diligence checklist. Build a status file and keep it current. Six years is the retention floor for HIPAA documentation.

Your file should contain:

  • A dated status determination memo. One page. Names the legal entity, TIN, NPI, and the specific standard transactions you conduct electronically. Signed by the privacy officer.
  • A list of the covered transactions in use — 837 claims, 270/271 eligibility, 835 remittance — with the system or vendor performing each.
  • Hybrid entity or ACE designation documents, if elected, with the component list and effective date.
  • A vendor inventory flagging which vendors touch PHI, the BAA execution date for each, and the renewal or review date.
  • Your notice of privacy practices with its posting and distribution log.
  • The current security risk analysis, which the Security Rule requires of every covered entity and business associate.

Assign owners. The privacy officer owns the status memo and the NPP. The practice administrator owns the vendor inventory. The security officer owns the risk analysis. If one person holds all three hats — common in a five-provider group — write the role assignments down anyway, because the audit question is "who is responsible," not "how many people work here."

A 30-Day Sequence If You Are Confirming Status Right Now

Days 1–5. Pull a list of every electronic transaction your practice or its vendors submitted in the last 12 months. Ask your billing lead directly; do not rely on memory. Apply the three-question test and draft the status memo.

Days 6–15. Build or refresh the vendor inventory. Every entity with PHI access — including the ones with incidental access, like your cleaning service in a clinical area — gets a row. Mark BAA status: signed, missing, expired, or not required.

Days 16–25. Execute the missing agreements. Do not let a vendor keep working with PHI while the agreement sits in legal review; document the date access began and the date the agreement was signed, because that gap is exactly what an investigator asks about. Review OCR's public breach portal to see how often vendor incidents drive reportable events at practices your size.

Days 26–30. Confirm the risk analysis is current and covers every system named in the vendor inventory. If it predates your current EHR, scheduling platform, or telehealth tool, it is stale. Tools that automate the risk analysis and the supporting policy set shorten this considerably, but the review and sign-off remain yours.

The One Sentence to Keep on File

Write it now, in your own words, and date it: "[Entity name] is a covered health care provider under 45 CFR 160.103 because it transmits [list transactions] in electronic form in connection with covered transactions, effective [date]." That sentence, supported by the file above, answers the covered entity definition question for every payer, vendor, attorney, and investigator who asks it.

If the gap you found is unsigned business associate agreements — and for most practices running this exercise, it is — build the agreements you need through the BAA wizard, export them, and get signatures before the next vendor onboarding. It is the fastest item on this list to close, and the one OCR asks about first.