HIPAA names exactly three kinds of covered entity: providers (hospitals, clinics, physicians, pharmacies) that transmit the standard electronic healthcare transactions, health plans (insurers, HMOs, employer group plans), and clearinghouses that translate health data between formats. The definition is functional, not aspirational — an organization either fits a category or it doesn’t, and “we work in healthcare” doesn’t make you one.
If you sell software or services to providers or plans and touch PHI along the way, you’re a business associate: bound primarily through the business associate agreements you sign, and directly accountable under HIPAA’s Security Rule. Your subcontractors who touch the same data become business associates too, one BAA further down the chain. The label matters practically — it tells you which obligations are yours by law, which arrive by contract, and what your healthcare customers will expect you to evidence.
Covered entities carry the full weight of the Privacy Rule — patient rights, notices, disclosure accounting — while business associates mostly inherit narrower, contract-shaped duties plus the Security Rule’s safeguard requirements. Build to the role you actually occupy: a business associate’s program centers on securing ePHI, honoring BAA terms, and proving both. What that looks like on a startup stack is the subject of HIPAA for startups.