A covered entity subject to the Privacy Rule is defined by the rule to mean:

An entity or organization that performs services for or on behalf of a health plan or group health plan or health care clearing house, or health care provider meeting one or more of the criteria defined below is defined as a business associate subject to the Privacy Rule.

Definition of Business Associate

(1) Except as provided in paragraph (2) of this definition, a business associate means, with respect to a covered entity, a person who:
- On behalf of such covered entity or of an organized health care arrangement in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement , performs, or assists in the performance of:
A) A function or activity involving the use or disclosure of individually identifiable health information, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, billing, benefit management, practice management, and repricing; or
B) any other function or activity regulated by the Privacy Rule, or
- Provides, other than in the capacity of a member of the workforce of such covered entity, legal, actuarial, accounting, consulting, data aggregation(as defined in the privacy rule), management, administrative, accreditation, or financial services to or for such covered entity, or to or for an organized health care arrangement in which the covered entity participates, where the provision of the service involves the disclosure of individually identifiable health information from such covered entity or arrangement, to the person.
(2) A covered entity participating in an organized health care arrangement that performs a function or activity as described by paragraph 1 of this definition for or on behalf of such organized health care arrangement, or that provides a service as described in paragraph 1 of this definition to or for such organized health care arrangement, does not, simply through the performance of such function or activity or the provision of such service, become a business associate of other covered entities participating in such organized health care arrangement.
(3) A covered entity may be a business associate of another covered entity.

What to do if your organization is subject to the Medical Privacy Rule




Hubbartt & Associates
Human Resource Management Consultants
P.O. Box 1355
1620 Jeanette Ave.
St. Charles IL 60174
(630) 513-9494