Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.

In this lesson, we'll go over the basics of covered entities, including what covered entities are, common examples across the healthcare industry, and the core requirements all covered entities share.

What is a Covered Entity?

As a reminder, a covered entity is one of three things: a health plan, a healthcare clearinghouse, or a healthcare provider that transmits Protected Health Information (PHI) electronically in connection with a covered transaction.

Common examples of covered entities include:

  • Doctors, dentists, and nurses
  • Social workers
  • Laboratories and pharmacies
  • Durable medical equipment providers
  • Hospitals and ambulance companies

Call Centers: Covered Entity vs. Business Associate

Call centers present a unique caveat under HIPAA regulations based on ownership and operations:

  • Owned & Operated by a Covered Entity: Must follow HIPAA regulations as a covered entity.
  • Third-Party Call Center: If handling PHI on behalf of a covered entity, they must follow HIPAA regulations as a business associate.

Compliance Requirements for Covered Entities

All covered entities are legally required to comply with HIPAA regulations to ensure patient data remains protected. Every covered entity must maintain:

  • Risk Assessment: A comprehensive evaluation to identify potential vulnerabilities and risk gaps.
  • Staff Compliance Training: Ongoing education to ensure employees properly handle and protect PHI.
  • Book of Evidence: A customized set of written policies and procedures explaining how the organization handles and safeguards PHI.

Pro Tip #1: The defining characteristic of all covered entities is that they directly handle or transmit PHI electronically in connection with healthcare transactions. When evaluating an organization, always look at how data is transmitted to determine regulatory status.

A Word About the Differences Between Covered Entities & Business Associates

First, let's define what a business associate is.

What is a Business Associate?

A business associate is any business or person that provides a service for a covered entity, or a certain function or activity, when that service, function or activity involves the access to PHI that is maintained by the covered entity.

Examples of business associates include, but aren't limited to:

  • Lawyers
  • Accountants
  • IT contractors
  • Billing companies
  • Cloud storage services
  • Email encryption services

The key phrase from above that really defines a business associate is this: the access to PHI that is maintained by the covered entity.

Pro Tip #2: So, what is the Difference? Covered entities have PHI (protected health information) while business associates merely have access to PHI. It's a bit of an ambiguous distinction, but an important distinction, nonetheless.