itlaw

Definition

HIPAA

A covered entity (CE) is one of three basic groups of individual or corporate entities: health plans, health care providers, and health care clearinghouses.

Overview

Each of these groups, in turn, is given an expansive regulatory definition, summarized roughly as follows:

In short, an organization that routinely handles protected health information in any capacity is in all probability a covered entity.[1] In turn, the behavior of any person in the covered entity's workforce is covered by extension.

Organizations performing functions involving personal health information on behalf of covered entities would be reached under the business associate contracts that HIPAA requires for such relationships. Behavior of individuals in the business associates' workforces would be covered in turn.

The Department of Health and Human Services' "First Guidance" on the Final Privacy Rule lists the following generic requirements for covered entities:

References

  1. See 45 C.F.R. 160.103 for the few statutory exemptions.