Every HIPAA decision starts with one question: what are you?
Covered Entity, Business Associate, Hybrid Entity, or Vendor — your HIPAA classification determines which rules apply, what documentation you need, and how severe the penalties are if something goes wrong. Most practices assume they know. This tool makes sure.
Four classifications. Four different compliance obligations.
Covered Entity
Healthcare providers who transmit health information electronically, health plans, and healthcare clearinghouses. Subject to the full scope of HIPAA — Privacy Rule, Security Rule, and Breach Notification Rule.
Examples
- Medical practices
- Dental offices
- Hospitals
- Pharmacies
- Health insurance companies
- Medicare/Medicaid programs.
Full HIPAA compliance required
Business Associate
Organizations that create, receive, maintain, or transmit PHI on behalf of a covered entity. Must sign a BAA and comply with the Security Rule. Directly liable for breaches since the 2013 Omnibus Rule.
Examples
- IT vendors
- Cloud hosting providers
- Billing companies
- EHR vendors
- Shredding companies
- Consultants with PHI access.
Security Rule + BAA required
Hybrid Entity
Organizations where only part of the business performs HIPAA-covered functions. The covered component must comply fully; non-covered components may operate under different standards but must maintain information barriers.
Examples
- Universities with medical centers
- Corporations with employee health clinics
- Retailers with in-store pharmacies.
Partial — covered components must fully comply
Vendor (Not Covered)
Organizations that sell products or services to healthcare but never create, receive, maintain, or transmit PHI. No direct HIPAA obligations, though customers may require contractual security assurances.
Examples
- Office supply vendors
- Building maintenance
- Food service providers
- General IT hardware suppliers.
No direct HIPAA obligations
Why classification matters
Entity classification is not a formality. It is the first decision in HIPAA compliance because it determines which rules apply to your organization. A covered entity has Privacy Rule obligations that a business associate does not. A business associate has Security Rule requirements that a vendor does not. Get the classification wrong, and you either over-invest in controls you do not need or under-invest in protections you are legally required to have.
Next step
HIPAA Compliance Roadmap
Now that you know your classification, work through the 17-step operational roadmap to see where your practice has real coverage and where the gaps are hiding. Entity classification is Step 1 — there are 16 more.