Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.
In this lesson, we'll go over who is required to comply with HIPAA laws and the two key groups the law directly applies to: covered entities and business associates.
HIPAA applies directly to two main groups that handle, transmit, or support operations involving Protected Health Information (PHI):
A covered entity is any provider of medical or other health services, or an organization that handles PHI. Key examples include:
Pro Tip #1: Repetition is a key part of mastering HIPAA standards. While you may notice some overlap with previous lessons on general HIPAA guidelines, reinforcing these core definitions ensures clear compliance across your organization.
A business associate is any company or individual with direct or incidental access to PHI or ePHI while supporting a covered entity. Business associates must maintain strict operational safeguards, often documented in what is known as a book of evidence.
Examples of business associates include:
Business associates are held to strict standards under HIPAA law. They are required to maintain risk assessments, employee training, and formal policies and procedures. Furthermore, business associates are legally required to notify covered entities of any potential or active data breaches to ensure PHI is protected at all times.
Pro Tip #2: Business associates must sign a formal Business Associate Agreement (BAA) with covered entities before gaining access to PHI. This contract legally binds them to safeguard patient information under federal law.