respect teamwork conversation scale security like value security-breach question delivery-truck dog accident folder slippery wheelchair Lifted Logic Web Design in Kansas City clock location phone play chevron-down chevron-left chevron-right chevron-up facebook checkbox checkbox-checked radio radio-selected instagram google plus pinterest twitter youtube send linkedin computer phone-call play-button quote-end quote-start pin call-answer envelope clock fax-machine right-arrow left-arrow mail-envelope-outlined

What is a “Covered Entity”?

When you visit a doctor, fill a prescription, or enroll in health insurance, you trust that your personal medical information will remain private. Unfortunately, data breaches and HIPAA violations happen every day, exposing sensitive information and leaving victims vulnerable to identity theft, financial fraud, and emotional distress.

One of the most important concepts under the Health Insurance Portability and Accountability Act (HIPAA) is the term “covered entity.” Understanding what a covered entity is—and the legal responsibilities these organizations have—can help you better understand your rights if your protected health information (PHI) is compromised.

What Is a Covered Entity?

covered entity is an individual or organization that must comply with HIPAA’s Privacy Rule and Security Rule because it creates, receives, maintains, or transmits protected health information as part of providing healthcare services or administering health benefits.

Covered entities are legally required to safeguard your medical information by implementing administrative, technical, and physical safeguards designed to prevent unauthorized access or disclosure.

If a covered entity fails to protect your information, it may face federal penalties and, in many cases, affected individuals may have legal claims arising from the breach or negligence.

The Three Types of Covered Entities

HIPAA recognizes three primary categories of covered entities.

  1. Healthcare Providers

Healthcare providers are perhaps the most recognized covered entities. This includes organizations and professionals that provide medical or healthcare services and electronically transmit health information in connection with certain transactions, such as hospitals, doctors, medical practices, dentists, pharmacies, and nursing homes.

Whether you receive treatment at a large hospital system or a small physician’s office, these providers are generally responsible for protecting your medical records.

  1. Health Plans

Health plans also qualify as covered entities because they collect and maintain large amounts of sensitive health information, including health insurance companies, HMOs, Medicare, Medicaid, and employer-sponsored health plans.

These organizations maintain extensive records about diagnoses, treatments, prescriptions, and claims, making them frequent targets for cybercriminals. 

  1. Healthcare Clearinghouses

Healthcare clearinghouses are organizations that process healthcare information between providers and insurers.

These are often businesses that process insurance claims, oversee electronic medical record transactions, and convert billing information into standardized formats.

Although many patients never interact directly with a clearinghouse, these organizations handle enormous volumes of protected health information and must comply with HIPAA.

What Is Protected Health Information (PHI)?

Covered entities are responsible for protecting Protected Health Information (PHI).

PHI includes information that identifies you and relates to your health, healthcare, or payment for healthcare, such as medical records, treatment plans, lab results, prescriptions, address, telephone number, Social Security number, and date of birth.

If this information is improperly disclosed or stolen, the consequences can extend well beyond medical privacy.

What Are Covered Entities Required to Do?

HIPAA requires covered entities to take reasonable steps to protect patient information.

Failure to meet these obligations may increase the risk of unauthorized disclosure or cyberattacks.

Covered entities often work with outside vendors or contractors, known as business associates, that handle PHI on their behalf. This can include billing companies, IT providers, or medical transcription services. Business associates must also comply with HIPAA through Business Associate Agreements (BAAs), although the covered entity often remains responsible for ensuring that patient information is properly protected.

Common HIPAA Violations by Covered Entities

The most common HIPAA violations include:

  • Data breaches due to hackers or ransomware attacks
  • Improper disposal of medical records
  • Employees accessing medical records without proper authorization
  • Poor cybersecurity practices
  • Devices that are not encrypted

Many of these incidents are preventable with proper safeguards.

What Happens If a Covered Entity Experiences a Data Breach?

When a covered entity experiences a qualifying breach involving unsecured protected health information, HIPAA generally requires it to notify affected individuals without unreasonable delay and within the timeframes established by federal law.

Depending on the size of the breach, the organization may also have reporting obligations to federal regulators and, in some cases, the media.

Unfortunately, breach notifications often arrive weeks or months after criminals have already obtained sensitive information.

What Can You Do If Your Medical Information Has Been Compromised?

If you receive a HIPAA breach notification letter:

  • Read the notice carefully.
  • Determine what information was exposed
  • Monitor your bank and credit accounts
  • Place a fraud alert or credit freeze if appropriate
  • Watch for suspicious medical bills or insurance claims
  • Keep copies of all correspondence
  • Contact McShane & Brady and let us help you to understand your legal rights

Many victims are surprised to learn that medical identity theft can continue for years after a breach.

How McShane & Brady Helps Victims of HIPAA Violations and Data Breaches

At McShane & Brady, we represent individuals whose personal and medical information has been exposed due to data breaches, cybersecurity failures, and HIPAA-related incidents.

Healthcare organizations and other covered entities have a legal responsibility to protect your private information. When they fail to do so, you may suffer identity theft, financial loss, invasion of privacy, and countless hours spent protecting your identity.

Our attorneys investigate data breaches, evaluate potential claims, and help individuals understand their legal options after their information has been compromised.

Contact McShane & Brady

You trust covered entities to protect your personal information, and when that trust is broken, you deserve answers. If you’ve received a notice that your medical information was exposed in a healthcare data breach or believe a covered entity failed to protect your personal information, contact McShane & Brady at 816-888-8010 to discuss your situation.