HIPAA Covered Entity vs. Business Associate: What Is the Difference

Understanding which category your organization falls into is the first step in knowing what HIPAA actually requires of you.

One of the most persistent sources of confusion in HIPAA compliance is the question of whether a given organization is a covered entity or a business associate. The question matters because the answer determines which HIPAA obligations apply directly to your organization, what documentation you need to have in place, and what your liability looks like in the event of an enforcement action.

This article explains how HIPAA defines each category, works through common examples that cause confusion, and clarifies what the compliance obligations look like for each type of organization.

How HIPAA Defines a Covered Entity

Under HIPAA, a covered entity is an organization that falls into one of three categories: a healthcare provider that transmits health information electronically, a health plan, or a healthcare clearinghouse. The definitions come from 45 CFR 160.103.

Healthcare providers are covered entities if they transmit any health information in electronic form in connection with transactions for which the Secretary of HHS has adopted standards. In practical terms, this captures virtually every provider that bills insurance electronically, submits claims, checks eligibility, or processes remittance advice. Physician practices, hospitals, dental offices, behavioral health providers, home health agencies, physical therapy clinics, pharmacies, and clinical laboratories all fall within this definition if they conduct covered electronic transactions.

Health plans include individual and group health plans, including employer-sponsored health plans that have 50 or more participants or are administered by a third party. Medicare, Medicaid, Medicare supplement issuers, health maintenance organizations, and long-term care insurers are also covered health plans. A self-insured employer health plan that is administered by the employer and has fewer than 50 participants is exempt, but this is a narrow carve-out.

Healthcare clearinghouses are entities that process nonstandard health information into standard formats or vice versa. This category includes billing services, repricing companies, and community health management information systems that translate between formats.

How HIPAA Defines a Business Associate

A business associate is a person or entity that performs functions or activities on behalf of a covered entity that involve the use or disclosure of protected health information, or that provides certain services to a covered entity where the performance of those services involves access to PHI. The definition also extends to subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate.

The functions and activities that trigger business associate status include claims processing, data analysis, utilization review, quality assurance, billing, benefit management, practice management, and repricing. Legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, and financial services also trigger business associate status when they require the service provider to access PHI to do their work.

Common categories of organizations that are business associates include:

Medical billing and revenue cycle management companies that process claims and remittances on behalf of provider practices.

IT managed service providers and technical support vendors that have access to systems where ePHI is stored or processed.

Cloud service providers and SaaS vendors whose platforms host, store, or process ePHI on behalf of covered entities, including EHR vendors, patient portal providers, telehealth platforms, and document management systems.

Healthcare attorneys and consultants who access PHI in the course of providing legal or advisory services.

Transcription and coding companies that handle clinical documentation containing patient information.

Shredding and records destruction companies that have access to PHI in physical or electronic form during the destruction process.

What Does Not Make an Organization a Business Associate

Not every vendor that has incidental contact with PHI is a business associate. HIPAA draws a distinction between organizations that use or disclose PHI to perform services for a covered entity and organizations that provide services to covered entities in ways that do not involve substantive access to PHI.

A janitorial service that cleans exam rooms is not a business associate even though employees enter spaces where PHI may be visible. A UPS driver delivering a package to a medical practice is not a business associate. A utility company providing electricity to a hospital is not a business associate. The defining test is whether the vendor creates, receives, maintains, or transmits PHI to perform the services in question, not whether the vendor is ever physically near PHI.

Workforce members of a covered entity, including employees, volunteers, trainees, and others under the direct control of the covered entity, are also not business associates. They are governed by the covered entity’s own privacy and security policies and training program, not by a Business Associate Agreement.

What Each Category Is Required to Do

Covered entities and business associates share a substantial set of HIPAA obligations, but there are meaningful differences in how the rules apply to each.

Privacy Rule obligations apply directly to covered entities. Business associates must comply with the Privacy Rule requirements specified in their Business Associate Agreements and are directly liable for the specific Privacy Rule provisions that apply to them under the HITECH Act, including the prohibition on using or disclosing PHI in ways that violate the Privacy Rule.

Security Rule obligations apply to both covered entities and business associates. Both must complete a Security Risk Analysis, implement administrative, physical, and technical safeguards, maintain written security policies and procedures, and train their workforce on security requirements. A business associate cannot satisfy its Security Rule obligations by pointing to its covered entity clients. Each organization must maintain its own independent compliance program.

Breach Notification Rule obligations differ by category. Covered entities must notify affected individuals, HHS, and in some cases the media following a breach of unsecured PHI. Business associates must notify the covered entity of a breach without unreasonable delay and within 60 days of discovery, and their Business Associate Agreement typically specifies a shorter contractual deadline. The covered entity then carries the obligation to notify individuals and HHS.

Business Associate Agreements are required whenever a business associate relationship exists. The covered entity has the obligation to enter into BAAs with its business associates. Business associates have the obligation to enter into BAAs with their own subcontractors who access PHI on their behalf. A missing BAA is a direct compliance violation for the covered entity regardless of whether a breach ever occurs.

Organizations That Are Both

An organization can be both a covered entity and a business associate simultaneously. A hospital that provides billing services for affiliated physician practices is a covered entity for its own operations and a business associate in its role providing billing services to those practices. In that capacity it would need a Business Associate Agreement with each practice it serves.

Healthcare clearinghouses occupy a similar dual position. A clearinghouse that processes claims for health plans is a covered entity in its own right, and it is also likely a business associate of the covered entities whose data it processes. The compliance obligations stack, not substitute.

When the Classification Is Unclear

Technology companies and SaaS vendors frequently struggle with whether they qualify as business associates. The analysis turns on whether the platform creates, receives, maintains, or transmits PHI on behalf of a covered entity as part of its core function. A practice management platform that stores patient demographics and appointment history is almost certainly maintaining ePHI on behalf of covered entities. A general-purpose project management tool that a medical practice’s administrative staff uses without uploading patient records is probably not.

When the classification is genuinely unclear, the conservative approach is to treat the relationship as a business associate relationship and execute a BAA. OCR has been clear that the burden of demonstrating an organization is not a business associate falls on the organization making that claim, not on the covered entity asking for a BAA.

Documentation for Covered Entities and Business Associates

Whether your organization is a covered entity or a business associate, the HIPAA Essentials Library has the policy and documentation templates you need. The Security Bundle covers Security Rule requirements that apply to both categories. The Privacy Bundle covers Privacy Rule documentation for covered entities. The Business Associate Agreement template gives covered entities a professionally written, attorney-style BAA ready for customization and immediate use.

For organizations that need complete coverage across all compliance areas, the Compliance Essentials Bundle includes every core document your program requires. All templates are provided in editable Microsoft Word format, available immediately after purchase.


If you work with a business associate, you need a signed BAA. Our Business Associate Agreement template is a professionally drafted, HIPAA-compliant BAA covering all required provisions under 45 CFR 164.504(e) — formatted in Microsoft Word so you can customize it for each vendor relationship and execute it immediately.