The covered-entity test: when HIPAA applies to a cash practice
Summary
You are a HIPAA covered entity only if you are a health care provider who transmits health information electronically in connection with a standard transaction — most commonly billing a claim electronically. A true cash practice that never does so may not be covered at all. But 'not a covered entity' is not 'unregulated': the FTC's Health Breach Notification Rule and your state's privacy laws still reach your patient data. Find your trigger first.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
Am I a HIPAA covered entity?
Only if you cross a specific line, and many solo cash practices assume they have when they have not. A health care provider is a covered entity only when the provider transmits health information in electronic form in connection with a standard transaction — the definitions and applicability that decide this live in 45 CFR Part 160 1Ref 1Office of the Federal Register (2026).45 CFR Part 160 — General Administrative Requirements.The HIPAA administrative-simplification definitions and applicability that define a covered entity by electronic standard transactions, plus the civil-money-penalty framework scaled to culpability.. It is not the practice of medicine that pulls you in and it is not simply using a computer; it is conducting one of the named electronic transactions, above all submitting claims electronically. The full landscape of the Privacy, Security, Breach Notification, and Enforcement rules — the thing people mean by 'HIPAA' — only attaches once you meet that test 2Ref 2HHS Office for Civil Rights (2026).HIPAA for Professionals.The OCR hub orienting the four HIPAA rules — Privacy, Security, Breach Notification, and Enforcement — used to frame what attaches once a provider meets the covered-entity test.. So the first task is not to build a compliance binder; it is to determine, honestly, whether you are covered at all.
The transaction trigger, in plain terms
The trigger is a defined set of standard electronic transactions: electronic claims, eligibility and benefit inquiries, claim-status checks, remittance advice, and the other administrative exchanges named in the administrative-simplification rules 1Ref 1Office of the Federal Register (2026).45 CFR Part 160 — General Administrative Requirements.The HIPAA administrative-simplification definitions and applicability that define a covered entity by electronic standard transactions, plus the civil-money-penalty framework scaled to culpability.. The practical reality for a solo practice is that you almost certainly cross the line the moment you bill any payer electronically — directly or through a clearinghouse or billing service acting for you. Sending a paper superbill to a patient who files their own out-of-network claim generally does not make you a covered entity; running a single electronic eligibility check or claim through software does. Because most 'cash' practices still verify benefits or submit an occasional electronic claim, assume you are covered unless you can show that no electronic standard transaction ever leaves your office.
What 'not a covered entity' does not mean
Concluding that HIPAA does not reach you is not a finding that your patient data is unregulated — it only narrows which rulebook applies. The FTC's Health Breach Notification Rule covers identifiable health information held by apps and vendors that fall outside HIPAA, so the scheduling app, symptom tracker, or direct-pay platform a non-covered practice relies on can carry its own federal breach-notice duties 3Ref 3Federal Trade Commission (2026).Health Breach Notification Rule.That the FTC's Health Breach Notification Rule reaches identifiable health data held by non-HIPAA apps and vendors, used to show 'not a covered entity' is not 'unregulated.'. On top of that sits the state layer: state privacy and confidentiality statutes apply regardless of covered-entity status, and several are stricter than HIPAA. The honest posture for a non-covered practice is to identify which of these actually governs your tools rather than treating 'not a covered entity' as a clean exit from privacy law.
If HIPAA applies: the four rules you are now under
Once you meet the covered-entity test, four rules apply together, and it helps to see them as a set rather than a single obligation 2Ref 2HHS Office for Civil Rights (2026).HIPAA for Professionals.The OCR hub orienting the four HIPAA rules — Privacy, Security, Breach Notification, and Enforcement — used to frame what attaches once a provider meets the covered-entity test.. The Privacy Rule governs how you may use and disclose protected health information, permitting treatment, payment, and health-care-operations uses while limiting the rest to the minimum necessary. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, anchored in a risk analysis and scalable to a practice of one. The Breach Notification Rule sets what you must do when unsecured PHI is exposed. The Enforcement Rule defines investigations and penalties. The operative regulatory text sits in 45 CFR Part 164 — including the six-year documentation-retention requirement and the individual access provisions — so it is the section to cite when a policy or auditor asks for chapter and verse 4Ref 4Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The operative Privacy and Security Rule text, including six-year documentation retention and the individual access provisions, cited as chapter-and-verse for the obligations that apply once covered..
Business associates: the vendors that carry PHI out of your office
The most common gap in a small covered practice is not a policy — it is an unsigned vendor contract. Any outside person or company that creates, receives, maintains, or transmits PHI on your behalf is a business associate, and you must have a business associate agreement in place before they touch that data 5Ref 5HHS Office for Civil Rights (2026).Business Associates.That vendors creating, receiving, maintaining, or transmitting PHI on the practice's behalf are business associates requiring a signed BAA, applied to the solo practice's EHR, billing, email, answering, and telehealth vendors.. For a solo practice the usual business associates are your EHR vendor, your billing service, your cloud storage or email provider handling PHI, your answering or transcription service, and your telehealth platform. The BAA is the contract that pushes your safeguard obligations downstream and defines each side's breach duties; a handshake or a generic terms-of-service page is not one. Inventory every vendor that could see PHI, then confirm a signed BAA exists for each before real patient data flows 5Ref 5HHS Office for Civil Rights (2026).Business Associates.That vendors creating, receiving, maintaining, or transmitting PHI on the practice's behalf are business associates requiring a signed BAA, applied to the solo practice's EHR, billing, email, answering, and telehealth vendors..
The individual rights you must honor
Being covered means patients gain enforceable rights, and the one most likely to generate an OCR complaint is the right of access. Patients may inspect and obtain a copy of their records, generally within thirty days (with one thirty-day extension), for a reasonable cost-based fee, in the form and format they request where you can produce it 6Ref 6HHS Office for Civil Rights (2026).Individuals' Right under HIPAA to Access their Health Information.That patients may access records within thirty days (one extension) for a reasonable cost-based fee in the requested format, and that psychotherapy notes are excluded from the access right.. A crucial carve-out for behavioral-health practices: psychotherapy notes — the clinician's separately-kept process notes — are excluded from the access right and carry their own heightened protection, so they are not part of the standard records copy you must hand over 6Ref 6HHS Office for Civil Rights (2026).Individuals' Right under HIPAA to Access their Health Information.That patients may access records within thirty days (one extension) for a reasonable cost-based fee in the requested format, and that psychotherapy notes are excluded from the access right.. Build a simple, dated request-handling routine now: log the date received, the date produced, the fee charged, and the format delivered, so a fast, documented response is your default rather than a scramble.
Enforcement reality for a very small practice
The assumption that a one-person practice is too small to enforce against is wrong and has been expensive for the clinicians who relied on it. OCR investigates complaints, conducts compliance reviews, enters resolution agreements, and imposes civil money penalties, and its published enforcement record includes actions against very small practices 7Ref 7HHS Office for Civil Rights (2026).HIPAA Compliance and Enforcement.That OCR enforces HIPAA through complaint investigations, compliance reviews, resolution agreements, and civil money penalties, with published outcomes including actions against very small practices.. The civil-money-penalty framework itself is set out in the administrative-simplification rules, and the amounts scale with culpability — from a genuinely unknowing violation up to willful neglect that went uncorrected 1Ref 1Office of the Federal Register (2026).45 CFR Part 160 — General Administrative Requirements.The HIPAA administrative-simplification definitions and applicability that define a covered entity by electronic standard transactions, plus the civil-money-penalty framework scaled to culpability.. What consistently distinguishes a survivable investigation from a ruinous one is not perfection but evidence of good faith: a completed risk analysis, signed BAAs, a records-access log, and dated proof you acted on what you found. Enforcement rewards the documented effort and punishes willful neglect.
Where state law and other rules layer on top
HIPAA is a federal floor, not a ceiling, so the last step of the covered-entity analysis is to map what stacks on top of it. HIPAA does not preempt a state law that is more protective of the patient, which means the state layer routinely controls sensitive-record categories, minor consent, and specific disclosure rules — and behavioral-health data is where state statutes most often go beyond the federal baseline. Even a non-covered practice remains inside that state framework and, for its non-HIPAA tools, inside the FTC's health-breach regime 3Ref 3Federal Trade Commission (2026).Health Breach Notification Rule.That the FTC's Health Breach Notification Rule reaches identifiable health data held by non-HIPAA apps and vendors, used to show 'not a covered entity' is not 'unregulated.'. The practical sequence is: settle whether you are a covered entity, then identify your strictest applicable rule for each type of data, and write your policies to that stricter standard rather than to HIPAA alone.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.Office of the Federal Register (2026). 45 CFR Part 160 — General Administrative Requirements. eCFR. link ✓The HIPAA administrative-simplification definitions and applicability that define a covered entity by electronic standard transactions, plus the civil-money-penalty framework scaled to culpability.
- 2.HHS Office for Civil Rights (2026). HIPAA for Professionals. U.S. Department of Health and Human Services. linkThe OCR hub orienting the four HIPAA rules — Privacy, Security, Breach Notification, and Enforcement — used to frame what attaches once a provider meets the covered-entity test.
- 3.Federal Trade Commission (2026). Health Breach Notification Rule. Federal Trade Commission (FTC). link ✓That the FTC's Health Breach Notification Rule reaches identifiable health data held by non-HIPAA apps and vendors, used to show 'not a covered entity' is not 'unregulated.'
- 4.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The operative Privacy and Security Rule text, including six-year documentation retention and the individual access provisions, cited as chapter-and-verse for the obligations that apply once covered.
- 5.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat vendors creating, receiving, maintaining, or transmitting PHI on the practice's behalf are business associates requiring a signed BAA, applied to the solo practice's EHR, billing, email, answering, and telehealth vendors.
- 6.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat patients may access records within thirty days (one extension) for a reasonable cost-based fee in the requested format, and that psychotherapy notes are excluded from the access right.
- 7.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR enforces HIPAA through complaint investigations, compliance reviews, resolution agreements, and civil money penalties, with published outcomes including actions against very small practices.
https://www.gale.care/for-providers/hip-does-hipaa-apply · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.