Covered Entities and Business Associates
- Document
- 23 November 2015
- Event
- no single event
- Retrieved
- 16 September 2026
The workload
Before writing a single security control, a SaaS founder handling any health-adjacent data has a threshold question to answer: does HIPAA apply at all. The Department of Health and Human Services' own guidance states that a covered entity is one of three things: a health care provider that transmits information electronically in connection with a standard transaction, a health plan, or a health care clearinghouse. A company that is none of those, and that is not handling protected health information on behalf of one of those as a 'business associate,' is outside HIPAA's reach regardless of how sensitive the data feels.
What the documents show
Verified: the same HHS page states that the definitions of business associate and covered entity are set out at 45 CFR 160.103, and that if an entity does not meet either definition, it does not have to comply with the HIPAA Rules. Verified: where a covered entity does engage a business associate, HHS states the covered entity must have a written business associate contract, and that business associates are, separately, directly liable for compliance with certain HIPAA provisions. Verified: HHS's own summary of the Privacy Rule traces it to sections 261 through 264 of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, enacted 21 August 1996, enforced by the Office for Civil Rights. Neither document applies the test to a hypothetical SaaS product; that reading depends on the specific facts of what data a product touches and on whose behalf.
The operating cost
Neither source states a compliance fee; the practical cost is legal and product-design time to determine status, and, if a company is a business associate, the cost of a business associate agreement and the security and breach-notification obligations that come with it. No dollar figure for that work is stated in either document, and none is estimated here since it depends entirely on the specific product.
The stop condition
Editorially, since the guidance describes a test rather than an exit: the question is not one to answer once. It should be re-asked whenever a product adds a new data type, a new customer segment such as clinics or insurers, or a new integration that puts it in a data flow it was not in before, since any of those can turn a company that was outside HIPAA's definitions into one that is inside them.
- Does the product touch protected health information on behalf of a health care provider, health plan or clearinghouse, or only adjacent wellness data those entities do not generate?
- If the answer is close, has the 45 CFR 160.103 definition been checked directly, rather than inferred from how sensitive the data feels?
- If the company is a business associate, is there a signed business associate agreement in place before, not after, the data starts flowing?
HIPAA is a threshold statute before it is a security checklist. Getting the covered-entity and business-associate test right decides whether the rest of the framework applies at all.
Sources & reading trail
HHS's own three-part definition of a covered entity, the business associate contract requirement, and the 45 CFR 160.103 citation for both definitions.
Source published: 23 November 2015 · Retrieved: 16 September 2026
HHS's own summary tracing the Privacy Rule to sections 261-264 of HIPAA (1996) and naming the Office for Civil Rights as enforcer.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.