Which Option Below Is Not A Covered Entity Under Hipaa

6 min read

So you're trying to figure out which option isn't a covered entity under HIPAA. Let me cut right to it — this is one of those questions that pops up in compliance trainings, certification classes, and late-night Google searches by people who just need to get their paperwork straight It's one of those things that adds up..

HIPAA covers a lot of ground, but not everything that touches health data falls under its umbrella. Get it wrong? The distinction matters because it determines who needs to follow those strict privacy and security rules. You could be overcomplying or, worse, undercomplying and exposing protected health information (PHI) without the proper safeguards Small thing, real impact..

Some disagree here. Fair enough.

Let’s break this down so you can spot the odd one out with confidence.

What Is a Covered Entity Under HIPAA?

First, let’s ground ourselves in what HIPAA actually says. A covered entity under HIPAA is an organization that handles protected health information in certain ways. The law specifically lists four types of covered entities:

  1. Health plans – like insurance companies, HMOs, and employer-sponsored health plans
  2. Health care clearinghouses – entities that process nonstandard health data into standardized formats
  3. Health care providers who transmit health information electronically in connection with health care transactions covered by federal regulations

And then there’s the fourth piece that often confuses people: business associates of these entities. While not covered entities themselves, business associates can be held accountable under HIPAA if they create, receive, maintain, or transmit PHI on behalf of a covered entity.

So when we ask, “Which option is not a covered entity?” we’re really asking: Does this entity fall into one of those four buckets?

Why This Matters

This isn’t just academic. If you’re working in healthcare IT, compliance, or even medical billing, knowing who’s covered under HIPAA affects everything from vendor contracts to data handling procedures. On top of that, you can’t sign a Business Associate Agreement (BAA) with someone who isn’t a covered entity or business associate. And if you treat a non-covered entity like one, you’re either wasting time or risking non-compliance.

Let’s look at some common examples of what is a covered entity and what isn’t.

Common Covered Entities vs. Non-Covered Entities

Here are some typical examples:

Covered Entities:

  • A private hospital
  • A doctor’s office that electronically submits claims
  • A Medicare Advantage plan
  • A medical lab that sends electronic test results to physicians
  • A pharmacy benefit manager (PBM)

Not Covered Entities:

  • A fitness center
  • A wellness coach who doesn’t transmit health data electronically
  • A medical device manufacturer (unless they’re also a provider transmitting data)
  • A health-related social media platform
  • A research institution acting independently (though they may still be subject to HIPAA in some cases)

Wait — what about that last one? Research institutions are tricky. But they can be covered entities if they function as health care providers or plans. But often, they fall under the National Research Council exception, meaning they’re not covered entities unless they transmit information electronically in connection with health care transactions.

That nuance is exactly why this question trips people up.

What Most People Get Wrong

Here’s where confusion usually creeps in:

Mistake #1: Assuming all health-related entities are covered. Nope. Just because someone works in health doesn’t mean they’re under HIPAA. A nutrition blogger, a meditation app, or a gym trainer generally aren’t covered entities unless they’re transmitting health data electronically as part of a covered transaction Simple, but easy to overlook..

Mistake #2: Thinking business associates are covered entities. They’re related, but not the same thing. A billing company that works with doctors is a business associate — they’re not a covered entity themselves, but they must comply with HIPAA through a BAA That's the part that actually makes a difference..

Mistake #3: Forgetting about electronic transmission. This is key. If a provider never transmits health information electronically in connection with standard transactions, they’re not a covered entity under HIPAA. That means many paper-based practices, small clinics that don’t bill electronically, or solo practitioners who only use cash-pay models might not technically be covered entities — though in practice, most modern providers do Most people skip this — try not to..

Practical Tips to Identify Covered Entities

Here’s a quick checklist to help you decide:

  • Does this entity bill insurance electronically? If yes → likely a covered entity.
  • Is it a health plan or insurer? If yes → definitely a covered entity.
  • Does it function as a clearinghouse? If yes → covered entity.
  • Is it a vendor working for a covered entity (like a cloud storage provider)? If yes → business associate, not covered entity.
  • Does it just collect health data without electronic transmission? If yes → probably not covered.

FAQ

Q: Is a hospital a covered entity under HIPAA?

Yes. Hospitals are classic examples of covered entities because they provide health care and typically transmit information electronically The details matter here..

Q: Are fitness apps covered by HIPAA?

Generally, no. Unless the app is transmitting health data electronically on behalf of a covered entity (like a doctor’s office), it’s not a covered entity.

Q: What about Amazon or Google if they offer health tools?

Same rule applies. If they’re not transmitting data electronically in connection with health care transactions, they’re not covered entities under HIPAA.

Q: Can a covered entity stop being one?

Yes, if it stops performing electronic transactions covered under HIPAA. But in practice, once an entity is a covered entity, it usually stays one.

Q: Are universities covered under HIPAA?

Only if they function as health care providers or plans. Many research universities aren’t covered unless they’re transmitting health data electronically.

The Short Version

If you’re looking at a list of options and need to pick the one that’s not a covered entity under HIPAA, look for the entity that:

  • Does not act as a health plan, clearinghouse, or health care provider
  • Does not transmit health information electronically in connection with standard transactions
  • Is not a business associate acting on behalf of a covered entity

That’s the litmus test.

Honestly, this is the part most guides get wrong. They make it sound like a memorization exercise, but it’s really about understanding the functional roles these entities play in the health care system. HIPAA isn’t about size or specialty — it’s about function and electronic data flow.

So if you’re staring at options like “insurance company,” “hospital,” “fitness app,” and “medical billing service,” and you need to pick the one that’s not covered — go with the fitness app. Unless it’s transmitting data electronically for a doctor, it’s not in the HIPAA covered entity club.

At the end of the day, the covered entities are the ones moving health information through electronic systems as part of the business of health care. Everything else? Not so much.

Understanding the distinction between covered entities and non-covered entities is the foundation of health information privacy law. While the landscape of data collection is expanding through wearable technology and consumer-grade apps, the legal boundaries of HIPAA remain strictly tied to the professional healthcare ecosystem.

The bottom line: the goal of HIPAA is to protect the privacy and security of Protected Health Information (PHI) as it moves through the official channels of medical care. Here's the thing — by focusing on the function of an organization—whether they are providing care, paying for care, or processing transactions—rather than the type of data they hold, you can figure out even the most complex regulatory questions with confidence. Whether you are a compliance officer, a student, or a tech developer, remembering that HIPAA follows the transaction, not just the data, is the key to mastering the framework And it works..

Just Went Online

Brand New Stories

You'll Probably Like These

What Others Read After This

Thank you for reading about Which Option Below Is Not A Covered Entity Under Hipaa. We hope the information has been useful. Feel free to contact us if you have any questions. See you next time — don't forget to bookmark!
⌂ Back to Home