Skip to content

Covered Entity / Business Associate

Definition

Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that handle protected health information on their behalf. Both carry breach notification obligations under the HIPAA Breach Notification Rule (45 CFR Parts 160 and 164).

Governing framework
US HIPAA
Covered entity examples
Healthcare providers, health plans, healthcare clearinghouses
Business associate role
Contractors handling PHI on the entity's behalf
Breach rule citation
HIPAA Breach Notification Rule, 45 CFR Parts 160 and 164

Common questions

Why does HIPAA extend breach notification duties to business associates and not just covered entities?+

Because business associates such as billing services, IT vendors, or cloud hosts routinely hold or process protected health information on a covered entity's behalf, limiting the obligation to the covered entity alone would leave a large share of actual data handling outside any breach reporting requirement, so the rule reaches both parties through the business associate agreement.

What must happen when a business associate, rather than the covered entity itself, suffers a breach?+

The business associate is required to notify the covered entity of the breach, and the covered entity in turn carries the ultimate responsibility for notifying affected individuals and regulators within the timelines set by the Breach Notification Rule, so the obligation flows through the entity even when the associate caused the incident.

Related terms

Data Fiduciary
The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
Notification Trigger
The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
Personal Data Breach
Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
Safe Harbour (Encryption)
A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
Supervisory Authority
The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.