All Courses HIPAA HIPAA Training Who is required to comply with HIPAA laws?

Who is required to comply with HIPAA laws?

Video 4 of 14
1 min 37 sec
English
English

In this lesson, we'll go over who is required to comply with HIPAA laws and the two key groups the law directly applies to: covered entities and business associates.

Who Must Comply with HIPAA Laws?

HIPAA applies directly to two main groups that handle, transmit, or support operations involving Protected Health Information (PHI):

  • Covered Entities: Include health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction.
  • Business Associates: Perform services for covered entities and require direct or incidental access to PHI in support of business operations.

What is a Covered Entity?

A covered entity is any provider of medical or other health services, or an organization that handles PHI. Key examples include:

  • Healthcare Providers: Physicians, nurses, hospitals, clinics, and allied health professionals.
  • Health Plans: Any individual or group plan that provides or pays the cost of healthcare, such as an HMO, insurance company, Medicaid, or Medicare.
  • Billing & Payment Entities: Organizations and individuals that provide billing services or receive payment in connection with healthcare services in the normal course of business.

Pro Tip #1: Repetition is a key part of mastering HIPAA standards. While you may notice some overlap with previous lessons on general HIPAA guidelines, reinforcing these core definitions ensures clear compliance across your organization.

What is a Business Associate?

A business associate is any company or individual with direct or incidental access to PHI or ePHI while supporting a covered entity. Business associates must maintain strict operational safeguards, often documented in what is known as a book of evidence.

Examples of business associates include:

  • IT vendors
  • Call centers
  • Court reporters
  • Cloud providers
  • Legal services providers
  • Suppliers and manufacturers with access to PHI and ePHI

Business Associate Requirements & Breach Reporting

Business associates are held to strict standards under HIPAA law. They are required to maintain risk assessments, employee training, and formal policies and procedures. Furthermore, business associates are legally required to notify covered entities of any potential or active data breaches to ensure PHI is protected at all times.

Pro Tip #2: Business associates must sign a formal Business Associate Agreement (BAA) with covered entities before gaining access to PHI. This contract legally binds them to safeguard patient information under federal law.