Skip to content

Covered Entity

Definition

Under HIPAA, a healthcare provider that transmits health information electronically, a health plan, or a healthcare clearinghouse. Covered entities are directly subject to HIPAA Privacy and Security Rule requirements.

Governing law
HIPAA (US)
Categories
Healthcare provider, health plan, healthcare clearinghouse
Trigger
Electronic transmission of health information
Subject to
HIPAA Privacy Rule and Security Rule

Common questions

How does a covered entity differ from a business associate under HIPAA?+

A covered entity is the healthcare provider, health plan, or clearinghouse that directly handles patient health information as part of delivering care or processing claims, while a business associate is a separate contractor, such as a billing company or cloud storage vendor, that handles that information on the covered entity's behalf under a written agreement.

Why does classification as a covered entity matter forensically in a data breach investigation?+

Only covered entities and their business associates carry HIPAA's specific breach notification and security obligations, so establishing whether an organisation involved in an incident meets the covered entity definition determines which legal notification timelines and regulatory reporting duties apply to the breach.

Related terms

Addressable Implementation Specification
A HIPAA Security Rule specification that organisations must assess for reasonableness and appropriateness. If reasonable and appropriate, it must be implemented; if...
Business Associate
A person or entity that performs services for a HIPAA covered entity that involve creating, receiving, maintaining, or transmitting protected health information...
Cardholder Data Environment (CDE)
The people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data. PCI-DSS requirements apply to the CDE...
Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium. PHI includes...
Qualified Security Assessor (QSA)
An individual certified by the PCI Security Standards Council to perform on-site PCI-DSS assessments for merchants and service providers that cannot self-certify....

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.