Covered entity or business associate? The HIPAA question small firms get wrong
HIPAA sorts businesses into two roles with different duties, and a lot of small firms cannot tell which one they are. The test that actually decides it, what each role owes, and why “we are not sure” is the answer worth acting on.
HIPAA does not have one set of rules for everybody who touches health information. It sorts businesses into two roles — covered entity and business associate — and gives them different duties, different paperwork and different things to do when something goes wrong. Almost every small firm that runs into HIPAA runs into it through this question, usually because a client or a vendor asked them to sign something and they were not sure why.
The uncomfortable part is that getting the answer wrong is not neutral. The two roles are not a spectrum, and neither of them is excused by nobody having checked.
What a covered entity actually is
The intuitive test — “we see patients, so we are a covered entity” — is close enough to the right answer to be dangerous, because it is not the test. For a healthcare provider, the operative question is whether the provider transmits health information electronically in connection with a transaction HIPAA covers. Claims, eligibility checks and payment are the usual ones.
In practice, nearly every provider that bills insurance meets that test, which is why the shortcut usually lands in the right place. But it lands there for a reason worth knowing, because the reason is what decides the edge cases — a strictly cash-pay practice that files nothing electronically is in a genuinely different position from the one next door that bills a health plan, and the difference is not how much they care about privacy.
What a business associate actually is
A business associate is a business that creates, receives, maintains or transmits protected health information on behalf of a covered entity. You never see a patient. You may never think of yourself as being in healthcare at all. The role attaches to what you do with the information, not to what industry you say you are in.
Firms that commonly turn out to be business associates include medical billing and coding companies, transcription services, IT providers and managed service providers with access to clinical systems, cloud and hosting providers holding clinical data, shredding and records-storage companies, and accountants or consultants whose work puts patient information in front of them.
There is one carve-out that matters and is regularly misapplied in both directions. A pure conduit — one that only carries information, in the way a courier or a telecoms provider does, without accessing it other than incidentally — is not a business associate on that basis. The carve-out is narrow. A vendor that stores your data is not a conduit merely because it does not read it, and storage is where most of these arguments actually happen.
Which role a business falls into is a legal determination about that specific business, and this article does not make it. It describes what the roles are; the answer for you is one for you and your counsel, or for the healthcare organization you work for. Holding any document — this article, or a policy generated from it — is not the same as being compliant with HIPAA.
What changes depending on the answer
It is worth being clear that business associates are not simply covered entities with lighter obligations. Since the 2013 rule changes, business associates are directly subject to the Security Rule’s safeguard requirements — and to parts of the Privacy Rule — and can be enforced against directly, not only sued by the covered entity for breach of contract. “We just follow whatever the contract says” has not been the position for over a decade.
The practical differences show up in three places:
- Agreements. A covered entity needs a signed business associate agreement with every vendor that handles protected health information on its behalf. A business associate needs one with each covered entity it works for — and a written subcontractor agreement, on the same terms, before it passes that information to anyone else.
- Risk analysis. Both roles owe a written security risk analysis in their own right. This is the requirement most often assumed to be satisfied by having a policy document, and it is not — they are two different things, and the analysis is the one enforcement actions tend to ask for first.
- Breach notification. A covered entity notifies affected individuals in writing without unreasonable delay and no later than 60 days from discovery, with additional filings depending on how many people are involved. A business associate instead notifies the covered entity it works for, within the same outside limit — but the agreement very often sets a shorter deadline, and where it does, the contract governs. Read it before the incident, not during one.
One duty catches business associates out repeatedly: a breach at your own subcontractor is yours to report upward. It does not stop when the subcontractor tells you.
If the honest answer is “we are not sure”
This is a more common position than either the guidance or the vendors selling into it tend to admit, and it is not a shameful one. It is only a problem if it stays unresolved, because both roles carry obligations that were running the whole time nobody had checked.
The useful thing to notice is that the question is cheap to settle and expensive to leave open. It is usually one conversation — with counsel, or with the healthcare organization that sends you the work, who generally knows exactly what they consider you to be and may already have an unsigned agreement waiting. Meanwhile, nothing stops you from doing the parts that are the same either way: know where health information lives, restrict who can reach it, turn on multi-factor authentication, and write down what you do when something goes wrong.
That is also how Coverwright handles it. The intake asks which role applies and offers “not sure” as a real answer rather than forcing a guess — and where you choose it, your documents say the question is open, name confirming it as a priority action, and set out the duties that attach either way. A generator that quietly picked a side for you would be making a legal determination it is in no position to make.