What is a covered entity?
A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with a transaction such as an insurance claim.
This is the definition that decides whether HIPAA applies to your organisation at all, and for most ABA clinics the answer arrives through the third limb. If you provide treatment and you bill a health plan electronically, you are a covered entity, and the obligations follow from that regardless of what your premises look like.
It is worth separating this from the intuition that HIPAA is about hospitals. The statute is about the flow of health information through the payment system. A small clinic billing one insurer is as covered as a hospital network, with the same duties around safeguards, access and disclosure accounting.
The distinction also explains why guidance about schools does not transfer. HHS has said HIPAA generally does not reach schools, because a school is either not a covered entity or holds health information only in FERPA education records. Neither limb describes a clinic delivering a prescribed medical treatment.
In an ABA clinic specifically.
An ABA clinic that bills insurance is a covered entity even though it may share a building with a preschool, serve the same age group and look identical from the car park. The test is what you do and how you are paid, never what the room looks like.
Questions people ask about covered entities.
Which of the following are considered covered entities?
Three categories, and only three: health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with a covered transaction. Health plans include insurers, HMOs, Medicare, Medicaid and most employer group health plans. Providers include hospitals, physicians, dentists, pharmacies, psychologists and ABA clinics. Clearinghouses are the intermediaries that translate claims data between formats.
What is an example of a covered entity?
An ABA clinic that submits claims electronically to a health plan for the therapy it delivers. So is the health plan receiving that claim, and so is the billing clearinghouse in between. All three are covered entities in the same transaction, each with its own obligations.
Which of the following is not a covered entity?
Employers, schools, life insurers, workers’ compensation carriers, most law enforcement agencies, and consumer apps that collect health data directly from a user are not covered entities. Nor is a vendor that handles PHI for a clinic: that is a business associate, which carries its own HIPAA obligations through a different route. A provider who never transmits health information electronically in connection with a covered transaction also falls outside the definition, which is a narrow and shrinking category.
What are covered entities required to do?
At a minimum: limit uses and disclosures of PHI to what the Privacy Rule permits, apply the minimum necessary standard, give individuals access to their own records, maintain administrative, physical and technical safeguards for ePHI, execute business associate agreements before a vendor touches PHI, notify affected individuals and HHS of breaches, appoint privacy and security officials, train the workforce, and keep the documentation that shows all of it happened.
Is an ABA clinic a covered entity?
If it bills insurance electronically for treatment, yes. Almost all do. A private-pay-only clinic that never transmits an electronic covered transaction may fall outside the definition, but it is worth checking with counsel rather than assuming, because eligibility verification and prior authorisation are covered transactions too — not just the claim.
What is the difference between a covered entity and a business associate?
A covered entity is regulated because of what it is: a plan, a clearinghouse or a billing provider. A business associate is regulated because of what it does for a covered entity: creating, receiving, maintaining or transmitting PHI on its behalf. Your clinic is the former. The software you send parent updates through is the latter, and a covered entity can also be a business associate of another covered entity.
May a covered entity use or disclose PHI without authorisation?
Yes, in defined circumstances — most importantly for treatment, payment and healthcare operations, and to the individual themselves. Beyond that the Privacy Rule sets out a specific list of permitted disclosures, such as certain public health activities, and everything outside those categories needs a valid authorisation. The minimum necessary standard still applies to most permitted uses.
Written by Abdihafid, a behavior technician working in an in-person ABA clinic. This is a plain-language explanation for people evaluating software, not legal advice, and it is not a substitute for your own compliance counsel.
Other terms
Sources
Claims about another product on this page are quotes from that product’s own documentation. Claims about what the law says are quotes from the regulation itself, not from anybody’s summary of it. Both are linked below with the date we last read them there.
- [1] 45 CFR 160.103 — Definitions — “Covered entity” · checked August 31, 2026
- [2] 45 CFR 160.103 — Definitions — “Business associate”, paragraph (1)(i) · checked August 31, 2026
- [3] brightwheel — brightwheel Security FAQs · checked August 26, 2026
Show us what you are using now.
Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.