HIPAA Covered Entity and Business Associate Checker
Find out whether HIPAA actually applies to you.
Most organizations that ask this question already have a hunch and no citation to back it. Answer up to four questions and this tool names the definition your facts match: covered entity by one of three prongs, business associate, subcontractor, conduit, or outside HIPAA entirely. Every result shows the rule it came from. Free, private, and no account required.
The checker
Walk the definitions, one question at a time
This checker walks the definitions in 45 CFR 160.103 and related HHS guidance. It runs entirely in your browser, stores nothing, and sends nothing anywhere. It reports which definition a set of answers matches. It does not determine whether an organization is compliant, it is not legal advice, and it is not a government determination. Complex structures, mixed functions, and state law questions deserve review by qualified counsel.
What it shows
Six things this checker makes clear
Three prongs
Which covered entity definition you actually meet
Health plan, health care clearinghouse, and health care provider are three separate tests in 45 CFR 160.103. Only the provider prong depends on electronic transactions, and the checker keeps them apart.
The transaction test
Why almost every provider is covered
Claims are the famous trigger, but eligibility checks, claim status inquiries, referral authorizations, and enrollment all count. A transaction your billing service sends is still your transaction.
Business associates
Whether a vendor relationship crosses the line
Creating, receiving, maintaining, or transmitting protected health information on behalf of a covered entity is the test. Maintaining counts even when nobody at your company ever reads a record.
The conduit exception
How narrow that exception really is
HHS reserves it for organizations that only transport data with random or infrequent access. Storage ends it. Encryption does not create it. The checker asks the question that decides it.
Subcontractors
That the chain keeps going downstream
A subcontractor handling the same information on behalf of a business associate is itself a business associate, with its own agreement and its own direct liability.
Outside HIPAA
Which law applies when this one does not
Employers, schools, life insurers, and direct-to-consumer apps usually sit outside HIPAA. The result explains what governs them instead, from the ADA to FERPA to the FTC Health Breach Notification Rule.
The full picture
Who HIPAA covers, and who it quietly does not
HIPAA regulates organizations, not information
The single most useful thing to understand about HIPAA is that it does not protect health information generally. It regulates a specific, closed list of organizations, and it protects health information only while that information sits with one of them. This is why your pharmacy cannot discuss your prescriptions with your employer, while a fitness app can sell inferences about your sleep and your heart rate to an advertiser. Same category of information, entirely different legal position, because one organization is on the list and the other is not.
The list appears at 45 CFR 160.102, which states that the HIPAA rules apply to health plans, health care clearinghouses, and health care providers who transmit any health information in electronic form in connection with a covered transaction. The 2009 HITECH Act and the 2013 Omnibus Rule added business associates and their subcontractors as directly regulated parties. That is the whole population. There is no residual category for organizations that hold sensitive health information for their own purposes, and no test based on how much data you hold or how sensitive it is. Either you fit a definition or you do not.
The practical consequence is that the question "does HIPAA apply to us" has a precise answer that turns on definitions rather than on judgment, and the definitions live in a single section: 45 CFR 160.103. What follows is a walk through the ones that matter, in the order the checker asks them.
Prong one: health plans
A health plan is an individual or group plan that provides, or pays the cost of, medical care. The definition then lists the specific programs included, which covers far more ground than commercial insurance: health insurance issuers, health maintenance organizations, employer-sponsored group health plans, Medicare, Medicaid, Medicare supplemental policies, long-term care policies, the military and veterans health care programs, the Indian Health Service program, the Federal Employees Health Benefits Program, state child health plans, and high-risk pools, among others.
Two limits matter more than the rest. First, the definition excludes any policy, plan, or program to the extent it provides or pays for excepted benefits, a category that includes accident-only coverage, disability income, liability insurance, workers compensation, automobile medical payment coverage, and credit-only insurance. A life insurer is not a health plan. A workers compensation carrier is not a health plan. They receive medical records constantly, and they are still outside this definition, which is why 45 CFR 164.512(l) exists to authorize the disclosures that get records to them in the first place.
Second, and this is the one that trips up small employers, the term group health plan reaches an employee welfare benefit plan providing medical care only where the plan has 50 or more participants, or is administered by an entity other than the employer that established and maintained it. Both prongs are alternatives, and the second one swallows most of the exception. A plan with fifteen participants that runs through an insurer or a third-party administrator is administered by an entity other than the employer, so it is a group health plan regardless of headcount. Genuinely self-administered small plans exist, but they are uncommon, and an employer that assumes it has one without checking who actually processes the claims is usually wrong.
Notice what the health plan prong does not require: any electronic transaction at all. Plans are covered by status. Only providers face the transaction test.
Prong two: health care clearinghouses
This is the smallest of the three categories and the least ambiguous. A health care clearinghouse is a public or private entity that processes or facilitates the processing of health information received from another entity in a nonstandard format or containing nonstandard data content into standard data elements or a standard transaction, or that does the reverse: takes a standard transaction and converts it into nonstandard format or content for a receiving entity. The definition explicitly names billing services, repricing companies, community health management information systems, community health information systems, and value-added networks and switches that perform those functions.
Clearinghouses are covered by status like plans, with no transaction test to satisfy. One nuance is worth knowing: a clearinghouse that creates or receives protected health information as a business associate of another covered entity is subject to a specific rule at 45 CFR 164.500(b) rather than the full set of Privacy Rule obligations, which is an unusual dual posture. Most organizations in this category run some business as a clearinghouse in its own right and other business as a business associate, and they need to know which is which.
Prong three: providers, and the transaction test that catches nearly all of them
A health care provider is defined broadly: a provider of services as defined in the Medicare statute, a provider of medical or health services as defined there, and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business. That sweeps in physicians, hospitals, dentists, chiropractors, pharmacies, laboratories, nursing facilities, home health agencies, therapists, and a long tail of others.
But being a health care provider does not by itself make you a covered entity. The covered entity definition adds a condition: the provider must transmit any health information in electronic form in connection with a transaction covered by the HIPAA rules. This is the only prong with a conduct test, and it is the source of most of the confusion on this topic.
The confusion comes from assuming the test is about submitting claims. It is not. The transaction definition lists health care claims or equivalent encounter information, health care payment and remittance advice, coordination of benefits, health care claim status, enrollment and disenrollment in a health plan, eligibility for a health plan, health plan premium payments, referral certification and authorization, first report of injury, health claims attachments, and electronic funds transfers. A practice that never submits a claim but checks a patient's coverage electronically before the appointment has transmitted health information in electronic form in connection with an eligibility transaction. That practice is a covered entity.
It also does not matter who presses the button. A transaction conducted on your behalf by a billing company, a practice management platform, or a clearinghouse still counts as your transaction. A solo therapist who never touches a claim form but whose billing service files electronically is a covered entity, with every obligation that implies. Cash-only and direct-pay practices that are genuinely outside the definition do exist, particularly in concierge medicine and some psychotherapy practices, but the number of practices that believe they are outside it substantially exceeds the number that are.
Two more things about this prong. It is not a one-time determination. The day a practice starts filing electronically, or hires a service that does, it becomes a covered entity, and nothing announces this. And falling outside the federal definition does not leave a practice unregulated: state medical privacy statutes, licensing board rules, professional ethics obligations, hospital privileging requirements, and payer contracts all impose privacy and training duties that owe nothing to HIPAA.
Business associates: regulated for what you do, not what you are
The fourth path into HIPAA is the one that has grown fastest. A business associate is a person or organization that, on behalf of a covered entity and other than as a member of its workforce, creates, receives, maintains, or transmits protected health information for a function or activity the rules regulate, or that provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services to a covered entity where the service involves disclosure of that information.
Four verbs carry the weight: creates, receives, maintains, transmits. Maintains is the one organizations underestimate. HHS has stated plainly that an entity maintaining electronic protected health information on behalf of a covered entity is a business associate even if it cannot view the information, and that a cloud service provider holding encrypted records without the decryption key does not escape the definition. The reasoning is that custody creates exposure to loss, corruption, and unavailability, which the Security Rule addresses alongside confidentiality. A hosting company offering what the industry calls no-view services is a business associate.
The definition also names categories that were once argued about and are now settled: health information organizations, e-prescribing gateways, other persons that provide data transmission services with respect to protected health information and require routine access to it, and vendors offering a personal health record on behalf of a covered entity. And it includes subcontractors, which is where the chain gets long.
Subcontractors and the chain that does not end
A subcontractor that creates, receives, maintains, or transmits protected health information on behalf of a business associate is itself a business associate. The analysis at every tier is the same analysis, including the conduit question, so the chain continues as far down as the information actually travels.
A hospital hires an electronic health record vendor, which is a business associate. The vendor hosts the system on a cloud provider, which is a business associate of the vendor. The cloud provider is not required to have an agreement with the hospital, but the vendor is required to have one with the cloud provider that provides the same protections its own agreement requires. If the cloud provider hires a firm to destroy decommissioned drives, that firm becomes a business associate too. Nobody is exempt for being three steps removed, and each tier is directly liable to the Office for Civil Rights for specific obligations rather than merely answerable to the tier above it.
The four exceptions, and the one people invent
The definition of business associate carves out four specific relationships. A health care provider is not a business associate of another covered entity with respect to disclosures concerning the treatment of an individual, which is why a hospital referring a patient to a specialist needs no agreement to send the chart. A plan sponsor receiving protected health information from the group health plan it sponsors is excluded where the requirements of 45 CFR 164.504(f) are met, which depends on amended plan documents and a certification rather than on the relationship alone. A government agency determining eligibility for or enrollment in a government health plan is excluded where that determination is a statutory function. And a covered entity participating in an organized health care arrangement is excluded when performing the function for that arrangement.
The exception that does not appear on that list, and that vendors invoke most, is the conduit exception. It is real but it is guidance rather than regulatory text, described by HHS in the January 2013 Omnibus Rule at 78 FR 5566 and in the agency's business associate guidance. It covers organizations whose only role is transporting information, with access that is random or infrequent and needed only as required to perform the transport: the postal service, private couriers, internet service providers, telecommunications carriers.
HHS has drawn the line with unusual clarity. Entities that access protected health information on a regular or frequent basis to perform a service are not conduits. Persistence is the test rather than intent. A vendor that stores a copy of the data, even briefly, even encrypted, even without ever looking at it, has left the exception. A support tool that lets an engineer view customer records to troubleshoot ends it too. Most technology companies that reach for this exception do not qualify, and the finding that settles the question is usually made by a customer's security reviewer rather than by the vendor.
The health information HIPAA never reaches
A great deal of American health information sits outside this framework entirely, and knowing that is as useful as knowing what is inside it.
Employers are the biggest category. HIPAA does not regulate an employer holding employee health information, and the definition of protected health information expressly excludes employment records held by a covered entity in its role as employer. A hospital is a covered entity for its patients and is not handling protected health information when it keeps a nurse's occupational health file. What governs employee medical information is other law: the Americans with Disabilities Act, which requires medical information from employment-related examinations to be kept in separate files and treated as confidential, the Family and Medical Leave Act regulation at 29 CFR 825.500(g) with a parallel requirement for medical certifications, the Genetic Information Nondiscrimination Act, and a growing body of state law. The popular belief that HIPAA prevents an employer from asking about an employee's health is simply wrong, though other laws may limit it.
Schools are the second category. The definition of protected health information excludes education records covered by the Family Educational Rights and Privacy Act, along with the treatment records described in that statute. Student health records held by most schools follow FERPA rather than HIPAA. University health centers and school-based clinics can straddle the line, and HHS and the Department of Education have issued joint guidance on exactly where it falls.
Direct-to-consumer health technology is the third and fastest-growing. An app, wearable, or website that collects health information straight from a member of the public, without any covered entity in the relationship, is generally not regulated by HIPAA at all. That space belongs to the Federal Trade Commission, which enforces the Health Breach Notification Rule at 16 CFR Part 318 against vendors of personal health records not covered by HIPAA, and Section 5 of the FTC Act against privacy representations that turn out to be false. Several states now regulate consumer health data directly. The important caveat for anyone building in this space is that a single contract with a covered entity converts that part of the business into a business associate relationship, agreement and all.
Hybrid entities, when only part of you is covered
Some organizations perform both covered and non-covered functions inside one legal entity. A university with a medical center, a corporation with an on-site clinic, a government agency with a health program. The rules provide for this at 45 CFR 164.103 and 164.105 through the hybrid entity designation, which lets a single legal entity designate its health care components so that the requirements apply to those components rather than to the whole organization.
The designation is not automatic and it is not retroactive. It has to be made and documented, the components have to be identified, and information flowing between the health care component and the rest of the organization has to be handled as though the components were separate legal entities. Organizations that assume they are hybrid without doing the paperwork get the worst of both outcomes: the full scope applies and nobody has treated it that way.
What to do once you know
For a covered entity, the work is the Privacy Rule, the Security Rule, and the Breach Notification Rule together: a written risk analysis under 45 CFR 164.308(a)(1), a designated privacy official and security official, workforce training under 45 CFR 164.530(b) and a security awareness and training program under 45 CFR 164.308(a)(5), a notice of privacy practices under 45 CFR 164.520, processes for individual access and amendment requests, the minimum necessary standard, business associate agreements with every vendor that qualifies, and a breach response capable of meeting the 60-day outer limit.
For a business associate, the Security Rule applies in full, breach reporting to the covered entity runs under 45 CFR 164.410, direct liability attaches for specific obligations, and the chain of agreements has to continue to every subcontractor. Your customers will ask for evidence of all of it during vendor review, usually before they sign.
Training is where most organizations start, for a practical reason: it applies immediately, it produces dated records a reviewer can ask for, and it is the requirement most likely to be raised by a customer, a payer, or an auditor first. It is worth being precise about what it proves. Completing training demonstrates that named individuals received instruction on a date. It does not make an organization compliant, and no training provider can certify that it is. Organizational compliance is the whole program described above. The federal government does not accredit or endorse training providers, and anyone telling you otherwise is describing something that does not exist. What good training does is make sure the people handling protected health information know what the rules require of them, and leave you able to prove it.
Keep going
What to read once you know your status
Guide
HIPAA training requirements
Once you know your status, this guide covers who must be trained, what the Privacy and Security Rules each require, and what documentation you need to keep.
Read the requirementsGuide
HIPAA business associate agreement
The required elements of a BAA, what it must say about permitted uses, breach reporting, and subcontractors, and where the HHS sample provisions fit.
Read the BAA rulesFree tool
Free HIPAA BAA generator
If the checker names you a business associate, build the agreement from the HHS sample provisions rather than starting from a blank page.
Generate a BAAGuide
HIPAA certification for organizations
How organizational training proof works, what a certificate does and does not demonstrate, and how to roll training out across a team.
See the org pathFree tool
Free HIPAA risk assessment tool
Covered entity or business associate, the Security Rule safeguards apply. Work through the cited standards and get a prioritized follow-up list.
Review safeguardsGuide
HIPAA vendor risk assessment
The other side of this question: how to evaluate the vendors you hire and decide which relationships need a written agreement.
Assess your vendorsFree tool
Free HIPAA practice test
Check whether your team can tell a covered entity from a business associate, and what the rules require of each, with scored answer explanations.
Take the testGuide
HIPAA compliance checklist
A cited walkthrough of the administrative, physical, and technical work that follows once you know the rules apply to you.
Work the checklistFree tool
HIPAA certification cost calculator
Estimate what training the people who need it will cost, by headcount and role, before you take a number to a budget conversation.
Estimate the costCovered entity FAQ
Common questions about who HIPAA covers
Is this covered entity checker free?
Yes. It is free, requires no account or email address, and runs entirely in your browser. Nothing you select is stored or transmitted. The tool walks the definitions in 45 CFR 160.103 and names the one your answers match, with the citation attached to every step.
How do I know if I am a covered entity?
There are exactly three ways in. You are a health plan, you are a health care clearinghouse, or you are a health care provider who transmits health information in electronic form in connection with a HIPAA standard transaction. The first two are status tests with no transaction requirement. The third depends on what you transmit, not on how large you are or how much money you make. If none of the three describes you, the next question is whether you handle protected health information on behalf of someone who does, which would make you a business associate instead.
Does HIPAA apply to a cash-only practice that never bills insurance?
Sometimes not, but the test is broader than claim submission and the exception is rarer than people expect. The transaction definition in 45 CFR 160.103 covers eligibility inquiries, claim status inquiries, referral certification and authorization, coordination of benefits, enrollment, premium payment, and remittance advice, not just claims. A single electronic eligibility check for one patient meets the test. So does a transaction sent by a billing company or practice management platform on your behalf. Practices that are genuinely outside the definition should still expect state medical privacy law, licensing board rules, and payer or hospital contracts to impose obligations of their own.
What is the difference between a covered entity and a business associate?
A covered entity is regulated because of what it is: a health plan, a clearinghouse, or a transacting provider. A business associate is regulated because of what it does for one of them, namely creating, receiving, maintaining, or transmitting protected health information for a regulated function. Since the 2013 Omnibus Rule, business associates are directly liable to the Office for Civil Rights for specific obligations, including Security Rule compliance and impermissible uses and disclosures, rather than being answerable only to the covered entity through a contract.
Is my software company a business associate?
It depends on whether your product creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Software installed entirely on a customer's own systems, with no access by you, usually does not. Software you host does, and so does software where your support team can reach customer records. HHS has stated that a cloud service provider that maintains encrypted electronic protected health information without holding the decryption key is still a business associate, because custody rather than readability is what the definition turns on.
What is the conduit exception and does it apply to us?
It is a narrow carve-out HHS described in the 2013 Omnibus Rule at 78 FR 5566 for organizations whose only role is transporting information, with access that is random or infrequent and needed only to complete the transport. The postal service, private couriers, and telecommunications carriers are the classic examples. HHS has been explicit that an entity accessing protected health information on a regular or frequent basis to perform a service is not a conduit, and that persistent storage takes an organization outside the exception. Most technology vendors that reach for this exception do not qualify for it.
Are employers covered by HIPAA?
Not in their role as employer. The definition of protected health information at 45 CFR 160.103 excludes employment records held by a covered entity in its role as employer, which is why a hospital that is unquestionably covered for patient records is not handling protected health information when it keeps a nurse's occupational health file. Employee medical information is governed by other law instead, including the confidentiality requirements of the Americans with Disabilities Act and the Family and Medical Leave Act, plus state statutes. Separately, the group health plan an employer sponsors can itself be a covered entity, which is a different question with a different answer.
Does a group health plan with fewer than 50 participants have to comply?
Only if someone other than the employer administers it. The definition of group health plan in 45 CFR 160.103 reaches plans with 50 or more participants and plans administered by an entity other than the employer that established and maintained the plan. Both prongs matter. A plan with a dozen participants that uses an insurer or a third-party administrator is inside the definition, because administration by an outside entity satisfies the second prong on its own. Genuinely self-administered small plans are unusual.
What happens to my obligations once the checker says HIPAA applies?
Covered entities take on the Privacy, Security, and Breach Notification Rules, including workforce training under 45 CFR 164.530(b), a security awareness and training program under 45 CFR 164.308(a)(5), a written risk analysis, a notice of privacy practices, individual rights processes, and written agreements with every business associate. Business associates take on the Security Rule in full, breach reporting to the covered entity under 45 CFR 164.410, direct liability for specific obligations, and agreements with their own subcontractors. Training obligations are where most organizations start, because they apply immediately and produce records a reviewer can ask for.
Does completing HIPAA training make my organization compliant?
No, and the distinction matters. Training satisfies specific requirements in the Privacy and Security Rules and produces documentation you can show. Organizational compliance is a much larger program that includes a written risk analysis, safeguards, policies and procedures, business associate agreements, breach response, and ongoing oversight. Nobody can certify an organization as HIPAA compliant, and the federal government does not accredit or endorse any training provider. What training gives you is proof that named people completed instruction on a date, which is one required piece of a much bigger picture.
If the checker says the rules reach you, training is the fastest requirement to satisfy. Start with HIPAA certification or plan a team rollout for everyone who touches PHI.
Now train the people it applies to