Get certified in HIPAA for Leaders for just $49.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
Who is required to comply with HIPAA laws? HIPAA applies directly to covered entities and business associates. As a reminder, covered entities include health plans, health care clearinghouses, and health care providers that transmit protected health information (or PHI) electronically in connection to a covered transaction, while a business associate performs services for covered entities and needs access to PHI. So what’s a Covered Entity? A Covered Entity is any provider of medical or other health services, or a person that has PHI (also known as Protected Health Information). They are Healthcare Providers, Health Plans, and organizations and individuals that provide bills or are paid in connection with services in the normal course of business. What is a Health Plan? A Health Plan is any individual or group plan that provides or pays the cost of healthcare, such as an HMO, insurance company, Medicaid, or Medicare. What is a Business Associate? A business associate is any company or individual with direct or incidental access to PHI in support of your business. Business associates are required to have risk assessments, training, policies and procedures which we call the book of evidence, just like covered entities. They are required to notify covered entities of any potential and active data breaches to ensure and protect PHI at all times.
In this lesson, we'll go over who is required to comply with HIPAA laws and the two key groups the law directly applies to: covered entities and business associates.
HIPAA applies directly to two main groups that handle, transmit, or support operations involving Protected Health Information (PHI):
A covered entity is any provider of medical or other health services, or an organization that handles PHI. Key examples include:
Pro Tip #1: Repetition is a key part of mastering HIPAA standards. While you may notice some overlap with previous lessons on general HIPAA guidelines, reinforcing these core definitions ensures clear compliance across your organization.
A business associate is any company or individual with direct or incidental access to PHI or ePHI while supporting a covered entity. Business associates must maintain strict operational safeguards, often documented in what is known as a book of evidence.
Examples of business associates include:
Business associates are held to strict standards under HIPAA law. They are required to maintain risk assessments, employee training, and formal policies and procedures. Furthermore, business associates are legally required to notify covered entities of any potential or active data breaches to ensure PHI is protected at all times.
Pro Tip #2: Business associates must sign a formal Business Associate Agreement (BAA) with covered entities before gaining access to PHI. This contract legally binds them to safeguard patient information under federal law.