Get certified in HIPAA for Leaders for just $49.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
What is a Covered Entity? As a reminder, a covered entity is one of three things: a health plan, a health care clearinghouse, or a health care provider that transmits PHI electronically in connection with a covered transaction. Some examples of covered entities include: doctors, dentists, nurses, social workers, laboratories, pharmacies, durable medical equipment providers, hospitals, and ambulance companies. One interesting caveat is call centers. If the call center is owned and operated by the covered entity, they must follow HIPAA as a covered entity. However, if they are a third-party call center handling PHI for a covered entity, they must follow HIPAA as a business associate. A Covered Entity is required to comply with HIPAA regulations. They are required to have a risk assessment, compliance training for their staff, and a book of evidence containing policies and procedures on how to handle PHI.
In this lesson, we'll go over the basics of covered entities, including what covered entities are, common examples across the healthcare industry, and the core requirements all covered entities share.
As a reminder, a covered entity is one of three things: a health plan, a healthcare clearinghouse, or a healthcare provider that transmits Protected Health Information (PHI) electronically in connection with a covered transaction.
Common examples of covered entities include:
Call centers present a unique caveat under HIPAA regulations based on ownership and operations:
All covered entities are legally required to comply with HIPAA regulations to ensure patient data remains protected. Every covered entity must maintain:
Pro Tip #1: The defining characteristic of all covered entities is that they directly handle or transmit PHI electronically in connection with healthcare transactions. When evaluating an organization, always look at how data is transmitted to determine regulatory status.
First, let's define what a business associate is.
A business associate is any business or person that provides a service for a covered entity, or a certain function or activity, when that service, function or activity involves the access to PHI that is maintained by the covered entity.
Examples of business associates include, but aren't limited to:
The key phrase from above that really defines a business associate is this: the access to PHI that is maintained by the covered entity.
Pro Tip #2: So, what is the Difference? Covered entities have PHI (protected health information) while business associates merely have access to PHI. It's a bit of an ambiguous distinction, but an important distinction, nonetheless.