Skip to content

Covered Entity

What is Covered Entity?

Under HIPAA, a health plan, healthcare clearinghouse, or healthcare provider that transmits any health information electronically. Covered entities must comply with all HIPAA Administrative Simplification rules.

Compliance

Each of these is named in at least one of the same controls as covered entity. The number is how many controls name both.

What the standards actually require on covered entity

Requirements naming covered entity across 6 standards, quoted from the control text.

Defines the operative scope: a covered entity is an entity in a critical infrastructure sector (PPD-21) meeting the criteria set by the CISA final rule;

CIRCIA-2240 · Definitions: Covered Entity, Covered Cyber Incident, Ransom Payment
HITECH Act6 controls

HITECH Act statutory scope + structure. ENACTMENT: Title XIII of the American Recovery and Reinvestment Act of 2009 (ARRA, Public Law 111-5) signed 17 February 2009 + entered into force phased;

HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles · HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)

When a covered entity and its business associate are both governmental entities, the requirements may be met through an MOU or other law that accomplishes the objectives of paragraph (a)(2)(i).

164.314(a)(2)(ii) · Other Arrangements (Government)

Implement controls including encryption to protect Nonpublic Information held or transmitted by the Covered Entity in transit over external networks and at rest.

§500.15 · Encryption of Nonpublic Information

Global CBPR Forum US multi-state adequacy mechanism. US STATE PRIVACY LAW RECOGNITION OF CBPR/PRP: as of 2026, many US state privacy laws explicitly recognize CBPR or binding/enforceable cross-border programs as adequacy mechanism + reducing compliance complex...

CBPR-Implementation-MultiState-AdequacyMechanism · Global CBPR Forum: US Multi-State Adequacy Mechanism, State-by-State Recognition
NIST SP 800-662 controls

Implement the HIPAA Security Rule Security Management Process Administrative Safeguard at 45 CFR 164.308(a)(1) per NIST SP 800-66 Rev 2.

NISTSP66-1 · Security Management Process: Risk Analysis and Risk Management for ePHI

Questions people ask about covered entity

What is Covered Entity?
Under HIPAA, a health plan, healthcare clearinghouse, or healthcare provider that transmits any health information electronically. Covered entities must comply with all HIPAA Administrative Simplification rules.
Why is Covered Entity important for compliance?
Covered Entity is a key concept in Compliance. Understanding covered entity helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Covered Entity?
Covered Entity appears in the requirement text of CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act), HITECH Act, HIPAA Security Rule, NY DFS 23 NYCRR 500, Global Cross-Border Privacy Rules (Global CBPR) Forum. Across these standards we have identified 27 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Covered Entity?
Explore our compliance framework pages to see how covered entity applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Covered Entity applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.