A covered entity is one of the three kinds of organisation HIPAA applies to directly: health plans, healthcare clearinghouses, and providers who bill electronically.
The short answer
HIPAA does not apply to everyone holding health data. It applies to covered entities: health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with a standard transaction such as a claim. Everyone else falls under HIPAA only indirectly, as a business associate working for a covered entity.
Most software companies in health are not covered entities. They are business associates, which brings nearly all of the same security obligations by a different route.
On this page
The three categories
The electronic transaction test
A healthcare provider becomes a covered entity by transmitting health information electronically in connection with a HIPAA standard transaction. Claims, eligibility checks, referral authorisations, claim status enquiries and remittance advice all count.
| Scenario | Covered entity? |
|---|---|
| Clinic submitting insurance claims electronically | Yes |
| Cash-only therapist who never bills insurance | No, though state law may still apply |
| Provider whose billing service submits claims for them | Yes, transmission on their behalf still counts |
| Telehealth platform employing its own clinicians and billing | Yes, as a provider |
| Software vendor selling to clinics | No, business associate instead |
The distinction most health startups get wrong
Building software used by clinicians does not make you a covered entity. It usually makes you a business associate, which still means the full Security Rule, direct liability and a BAA with every customer.
Hybrid entities and edge cases
Hybrid entity
An organisation with both covered and non-covered functions can designate which components are in scope, in writing.
Affiliated covered entity
Legally separate entities under common ownership may elect to be treated as one for HIPAA purposes.
Employers
Not covered entities as employers, even holding health data. Their group health plan can be.
What a covered entity must do
| Obligation | Source |
|---|---|
| Limit uses and disclosures, honour patient rights, publish a privacy notice | Privacy Rule |
| Implement administrative, physical and technical safeguards over ePHI | Security Rule |
| Notify individuals, HHS and sometimes media after a breach | Breach Notification Rule |
| Execute a BAA with every vendor touching PHI | Privacy and Security Rules |
| Apply the minimum necessary standard to most disclosures | Privacy Rule |
How Osto helps
Covered entity or business associate, the Security Rule obligations are near identical and they are technical. Osto deploys the controls behind them, access management, encryption, logging and monitoring, endpoint control and testing, and maps evidence to HIPAA alongside 200+ other frameworks in one dashboard.
Free security assessment
Same Security Rule, one platform
Covered entity or business associate, the technical obligations are near identical. Osto deploys and evidences them.
Get a free security assessment Book a platform walkthroughHIPAA mapped · SOC 2 and ISO 27001 too · One platform, everything
Frequently asked questions
What is a covered entity under HIPAA?
A health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with a HIPAA standard transaction. These three categories are the organisations HIPAA applies to directly.
Is a health tech startup a covered entity?
Usually not. Selling software to providers or plans makes you a business associate, not a covered entity. If you employ clinicians and bill insurers directly, you may be a provider and therefore covered.
What is the difference between a covered entity and a business associate?
A covered entity is subject to HIPAA directly by virtue of what it is. A business associate is subject because it handles PHI on a covered entity’s behalf, under a contract. Both carry Security Rule obligations.
Are employers covered entities?
Not in their capacity as employers. Employment records are excluded from PHI even when they contain health information. An employer-sponsored group health plan can itself be a covered entity.
What is a hybrid entity?
An organisation that performs both covered and non-covered functions and formally designates which components are in scope. The designation must be documented, and PHI flowing between components must be controlled.

