A HIPAA covered entity is a business or organization that is subject to the rules of the Health Insurance Portability and Accountability Act (HIPAA). This set of legislation provides protections for personal health information (PHI), which includes certain kinds of patient medical records and identifiers.


The original HIPAA rule applied only to the covered entities themselves, such as health-care provider offices and some insurance companies. Now, the Health Information Technology for Economic and Clinical Health (HITECH) Act requires “business associates” to be HIPAA compliant also. Business associates are third parties that somehow have access to patient data from covered entities. These include companies that provide archives, handle records or utilize PHI from a doctor’s office or hospital.


