1. The two definitions
A covered entity is one of three things: a health plan, a health care clearinghouse, or a health care provider who transmits health information in electronic form in connection with a transaction covered by the HIPAA rules. A business associate is a person or organisation that creates, receives, maintains or transmits protected health information on behalf of a covered entity, in order to perform a function for it. Your EMR vendor is one. So is your billing service, your shredding company, and anyone else handling records for you.The relationship is directional and it matters. A covered entity must have a BAA with each of its business associates. The paper flows from the clinic outward to its vendors — not the other way round.
2. The test most clinics never apply
Read the provider limb of the covered-entity definition again, because the operative clause is easy to miss: a provider who transmits health information in electronic form in connection with a covered transaction.
Those covered transactions are a specific, enumerated set — the standard electronic exchanges that exist in the insurance world. Claims. Eligibility enquiries. Claim status. Remittance advice. Enrolment.
Which produces a result that surprises people: a purely cash-pay clinic that never conducts any of those electronic transactions may not meet the definition of a covered entity at all. Not because it is exempt, but because it never crossed the threshold.
This is a technical reading of a federal definition, not a recommendation to stop protecting patient data. See the next section — the practical consequences of concluding “we are not covered” are much smaller than they first appear.
3. How clinics become covered without noticing
The threshold is low and easy to cross by accident. The most common route in an optimization clinic is not submitting claims — it is running an electronic eligibility check.
A clinic that has decided to be cash-pay forever will still, sooner or later, want to tell a patient whether their labs might be covered. If that check is run electronically as a standard transaction, the clinic has conducted a covered transaction, and the analysis changes from that moment. The same applies the first time anyone submits a claim on a patient’s behalf, or sends a superbill through a clearinghouse rather than handing over a PDF.
The practical instruction: if you ever intend to touch insurance in any electronic form, assume you are a covered entity and build accordingly. Retrofitting compliance after the fact is materially harder than starting with it.
4. Why the answer changes less than you would hope
If you conclude you are not a covered entity, four things remain true.
State law does not care. Many states impose medical-records privacy and breach-notification duties on providers independent of HIPAA, and some are stricter than the federal rules. Your contracts may not care. Labs, pharmacies and platform partners routinely require HIPAA-equivalent terms as a condition of working with you, whatever your federal status. Patients definitely do not care. A breach is a breach. “We were outside the definition” is not a thing anyone wants to say to a patient, a journalist, or a plaintiff. And the status can change on a Tuesday. See above. A clinic built to the standard is unaffected by crossing the threshold; a clinic that was not has a project.So the useful conclusion is rarely “we are exempt”. It is: know which side you are on, do not claim a status you have not tested, and build to the higher standard because the cost difference is smaller than the cost of being wrong.
5. You can be both — and vendors get this backwards
The two categories are not exclusive. An entity can be a covered entity for its own patients and a business associate to someone else for work it performs on their behalf.
This is where vendors most often misdescribe themselves, and it is worth being precise about your own status when you sign paper. A software company serving clinics is a business associate — it handles PHI on behalf of the clinics, which are the covered entities. It is not a covered entity itself, and saying otherwise on a contract creates an agreement that does not describe reality.
If you are the clinic, you should expect your software vendor to sign a BAA as your business associate. If a vendor proposes the reverse, or describes itself as a covered entity, that is a signal worth pausing on — not necessarily disqualifying, but they should be able to explain it.
This is not legal advice. It is what we have learned building software for prescribing clinics, written down plainly because almost nobody publishes it. Fee schedules and federal rules change — every figure here was checked on 6 August 2026 and linked to its source. Confirm the live position with the regulator, the vendor, or your own counsel before you act on it.
6. Frequently asked questions
Is a cash-pay clinic a covered entity?
Not automatically. A provider is a covered entity only if it transmits health information electronically in connection with a HIPAA standard transaction — claims, eligibility, claim status, remittance and similar. A clinic that never conducts one may fall outside the definition, though state law and contractual duties still apply.
Does running an eligibility check make me a covered entity?
If it is conducted electronically as a standard transaction, yes — that is a covered transaction, and it is the most common way an otherwise cash-pay clinic crosses the threshold without realising.
Is my EMR vendor a covered entity or a business associate?
A business associate. It handles PHI on behalf of your clinic, which is the covered entity. A software vendor describing itself as a covered entity has it backwards.
Who has to sign the BAA?
The covered entity executes a BAA with each business associate that handles PHI on its behalf. The obligation flows outward from the clinic to its vendors.
If I am not a covered entity, can I skip HIPAA entirely?
In practice, no. State privacy and breach-notification law may apply regardless, contracts with labs and pharmacies commonly require equivalent terms, and the status can change the first time you touch an electronic insurance transaction.
Do I need a BAA with a lab?
Usually the lab is acting as a covered entity in its own right rather than as your business associate, so the arrangement is often different. Ask what they propose and why — the answer varies by relationship.