Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.
In this lesson, we'll go over the basics of covered entities, including what covered entities are, common examples across the healthcare industry, and the core requirements all covered entities share.
As a reminder, a covered entity is one of three things: a health plan, a healthcare clearinghouse, or a healthcare provider that transmits Protected Health Information (PHI) electronically in connection with a covered transaction.
Common examples of covered entities include:
Call centers present a unique caveat under HIPAA regulations based on ownership and operations:
All covered entities are legally required to comply with HIPAA regulations to ensure patient data remains protected. Every covered entity must maintain:
Pro Tip #1: The defining characteristic of all covered entities is that they directly handle or transmit PHI electronically in connection with healthcare transactions. When evaluating an organization, always look at how data is transmitted to determine regulatory status.
First, let's define what a business associate is.
A business associate is any business or person that provides a service for a covered entity, or a certain function or activity, when that service, function or activity involves the access to PHI that is maintained by the covered entity.
Examples of business associates include, but aren't limited to:
The key phrase from above that really defines a business associate is this: the access to PHI that is maintained by the covered entity.
Pro Tip #2: So, what is the Difference? Covered entities have PHI (protected health information) while business associates merely have access to PHI. It's a bit of an ambiguous distinction, but an important distinction, nonetheless.