Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Free tool

Every HIPAA decision starts with one question: what are you?

Covered Entity, Business Associate, Hybrid Entity, or Vendor — your HIPAA classification determines which rules apply, what documentation you need, and how severe the penalties are if something goes wrong. Most practices assume they know. This tool makes sure.

Free·No login required·3–4 questions·Instant result

4

Classifications

Covered Entity, Business Associate, Hybrid Entity, Vendor

7

Questions

Branching logic — you only answer 3–4 based on your path

%

Confidence score

Each result includes a likelihood rating based on your answers

100%

Free

No login, no credit card, no trial expiration

Sample result

What a completed classification looks like.

Example output for a small independent medical practice that transmits claims electronically. Your obligations are itemized and mapped to the specific 45 CFR provision that creates each one.

Sample classification

Your classification

You are a Covered Entity — Healthcare Provider

Confidence: 96%

A healthcare provider that transmits health information electronically in connection with a HIPAA transaction meets the covered-entity definition under 45 CFR 160.103.

Your obligations

  • Enterprise-wide administrative safeguards

    45 CFR Part 160 · 45 CFR Part 164 Subpart C

    Documented risk analysis, workforce sanction policy, information system activity review, and workforce security processes across every operational surface that touches ePHI.

  • Signed BAAs with every downstream vendor touching PHI

    45 CFR §164.308(b)(1)

    Written business associate agreements executed before any vendor creates, receives, maintains, or transmits ePHI on your behalf.

  • Notice of Privacy Practices and patient rights

    45 CFR §164.520

    Current notice provided at first patient encounter and made available on request, with acknowledged patient access, amendment, and accounting-of-disclosures workflows.

  • Breach notification within 60 days

    45 CFR Part 164 Subpart D

    Individual, media (if 500+ affected), and HHS Secretary notification obligations under the Breach Notification Rule, plus documented risk-assessment methodology for suspected disclosures.

Sample data. Your result populates from your own answers below.

Question 1

Question 1

Does your organization provide healthcare services directly to patients?

Your obligations are now clear. Patient Protect satisfies them continuously.

Know the landscape

Four classifications. Four different compliance obligations.

New to the covered-entity and business-associate framework? The free HIPAA Fundamentals training module walks through both terms — and the rest of the core HIPAA vocabulary — in five minutes.

Covered Entity

Healthcare providers who transmit health information electronically, health plans, and healthcare clearinghouses. Subject to the full scope of HIPAA — Privacy Rule, Security Rule, and Breach Notification Rule. Definition at 45 CFR 160.103.

Examples

Medical practices, dental offices, hospitals, pharmacies, health insurance companies, Medicare/Medicaid programs.

Full HIPAA compliance required

Business Associate

Organizations that create, receive, maintain, or transmit PHI on behalf of a covered entity. Must sign a BAA and comply with the Security Rule. Directly liable for breaches since the 2013 Omnibus Rule. Definition at 45 CFR 160.103; BAA requirement at 45 CFR §164.308(b)(1).

Examples

IT vendors, cloud hosting providers, billing companies, EHR vendors, shredding companies, consultants with PHI access.

Security Rule + BAA required

Hybrid Entity

Organizations where only part of the business performs HIPAA-covered functions. The covered component must comply fully; non-covered components may operate under different standards but must maintain information barriers. Governed by 45 CFR §164.105.

Examples

Universities with medical centers, corporations with employee health clinics, retailers with in-store pharmacies.

Partial — covered components must fully comply

Vendor (Not Covered)

Organizations that sell products or services to healthcare but never create, receive, maintain, or transmit PHI. No direct HIPAA obligations, though customers may require contractual security assurances. Falls outside the covered-entity and business-associate definitions at 45 CFR 160.103.

Examples

Office supply vendors, building maintenance, food service providers, general IT hardware suppliers.

No direct HIPAA obligations

Why classification matters

Get this wrong and every compliance decision that follows is built on the wrong foundation.

Entity classification is the first decision in HIPAA compliance because it determines which rules apply to your organization. A covered entity has Privacy Rule obligations that a business associate does not. A business associate has Security Rule requirements that a vendor does not. Get the classification wrong, and you either over-invest in controls you do not need or under-invest in protections you are legally required to have.

OCR enforcement actions regularly cite misclassification as an aggravating factor. Organizations that believed they were vendors when they were actually business associates have faced penalties for operating without BAAs, failing to conduct risk assessments, and lacking breach notification procedures — all obligations they did not know they had because they started from the wrong assumption.

This tool uses branching logic to narrow your classification in 3–4 questions. It is not a legal determination — that requires counsel. But it eliminates the ambiguity that causes most classification errors and gives you a working frame for every compliance decision that follows.

Next step

HIPAA Compliance Roadmap

Now that you know your classification, work through the 17-step operational roadmap to see where your practice has real coverage and where the gaps are hiding. Entity classification is Step 1 — there are 16 more.

See the Full Roadmap

Get a full picture

Unified Risk Assessment

Entity determination is one input. The Unified Risk Assessment combines it with compliance readiness, practice profile, and ePHI data flow analysis for a unified risk score — all in one evaluation.

Take the Free Assessment

Know your classification. Now act on it.

Classification tells you which rules apply. Patient Protect implements them — automated risk assessments, policy management, vendor oversight, and breach response built for your entity type and practice size.

Part of the HIPAA Foundation · 15+ free tools

See the full collection
AssessFree · proprietary

Assess risk

Now you know your obligations. The platform maps them to the specific policies, BAAs, and safeguards your entity type requires — and tracks the work.

Next in the sequence

Risk Assessment

Assessments, classification tools, and an AI assistant that reveal your actual compliance standing and starting point.