Covered Entity
What is Covered Entity?
Under HIPAA, a health plan, healthcare clearinghouse, or healthcare provider that transmits any health information electronically. Covered entities must comply with all HIPAA Administrative Simplification rules.
Terms that appear alongside covered entity
Each of these is named in at least one of the same controls as covered entity. The number is how many controls name both.
- business associate 12 shared controls
- hipaa 11 shared controls
- cisa 9 shared controls
- cyber incident 8 shared controls
- breach notification 7 shared controls
- compliance 6 shared controls
- ransomware 6 shared controls
- nist 5 shared controls
Frameworks that govern covered entity
What the standards actually require on covered entity
Requirements naming covered entity across 6 standards, quoted from the control text.
Defines the operative scope: a covered entity is an entity in a critical infrastructure sector (PPD-21) meeting the criteria set by the CISA final rule;
CIRCIA-2240 · Definitions: Covered Entity, Covered Cyber Incident, Ransom Payment →HITECH Act statutory scope + structure. ENACTMENT: Title XIII of the American Recovery and Reinvestment Act of 2009 (ARRA, Public Law 111-5) signed 17 February 2009 + entered into force phased;
HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles · HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D) →When a covered entity and its business associate are both governmental entities, the requirements may be met through an MOU or other law that accomplishes the objectives of paragraph (a)(2)(i).
164.314(a)(2)(ii) · Other Arrangements (Government) →Implement controls including encryption to protect Nonpublic Information held or transmitted by the Covered Entity in transit over external networks and at rest.
§500.15 · Encryption of Nonpublic Information →Global CBPR Forum US multi-state adequacy mechanism. US STATE PRIVACY LAW RECOGNITION OF CBPR/PRP: as of 2026, many US state privacy laws explicitly recognize CBPR or binding/enforceable cross-border programs as adequacy mechanism + reducing compliance complex...
CBPR-Implementation-MultiState-AdequacyMechanism · Global CBPR Forum: US Multi-State Adequacy Mechanism, State-by-State Recognition →Implement the HIPAA Security Rule Security Management Process Administrative Safeguard at 45 CFR 164.308(a)(1) per NIST SP 800-66 Rev 2.
NISTSP66-1 · Security Management Process: Risk Analysis and Risk Management for ePHI →Questions people ask about covered entity
What is Covered Entity?
Why is Covered Entity important for compliance?
Which compliance frameworks address Covered Entity?
Where can I learn more about Covered Entity?
See how Covered Entity applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.