{"@context":"https://schema.org","@type":"Article","headline":"Part 2 covered-entity definition","description":"Learn how Part 2 adopts the HIPAA covered-entity definition and why health plan, clearinghouse, and provider status requires factual review.","url":"https://finnihealth.com/resources/glossary/part-2-covered-entity-definition","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 covered-entity definition","item":"https://finnihealth.com/resources/glossary/part-2-covered-entity-definition"}]}}
Glossary term

Part 2 covered-entity definition

Learn how Part 2 adopts the HIPAA covered-entity definition and why health plan, clearinghouse, and provider status requires factual review.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

HIPAA covered entity in Part 2 SUD program covered entity status

The covered-entity definition used by Part 2 is the HIPAA meaning in 45 CFR 160.103: a health plan, health care clearinghouse, or health care provider that transmits health information electronically in connection with a covered transaction. A Part 2 program may also be a covered entity, while another Part 2 program may fall outside that HIPAA status. Each classification needs current facts.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.11 gives covered entity the meaning in 45 CFR 160.103: a health plan, health care clearinghouse, or health care provider that transmits health information electronically in connection with a transaction covered by the HIPAA administrative-simplification rules. Part 2 program status and HIPAA covered-entity status are separate classifications.

Classify Part 2 and HIPAA separately

Current 42 CFR 2.11 incorporates the HIPAA term. Record the SUD program structure and federal assistance for Part 2, then evaluate plan, clearinghouse, provider, transaction, electronic-transmission, organizational, and hybrid-entity facts for HIPAA.

Use the current HIPAA definition

Current 45 CFR 160.103 lists the three covered-entity categories. For a provider, identify the actual covered transaction and electronic transmission, including activity performed through a billing service. Provider licensure or an NPI alone does not settle the test.

Connect status to the workflow

Document which Part 2 and HIPAA rules apply to consent, TPO, business associates, security, breach, patient rights, notices, complaints, and enforcement. Reassess after new services, transactions, entities, integrations, acquisitions, or payer routes.

Analyze Part 2 status independently

Document whether the organization, unit, or workforce function is a Part 2 program using the applicable program, holding-out, SUD diagnosis or treatment, and federal-assistance facts. Preserve organizational boundaries and services. Do not infer HIPAA status from Part 2 coverage or vice versa.

The same organization can have components and roles governed differently. Identify the entity and activity at issue.

Test each covered-entity category

Determine whether the entity is a health plan, health care clearinghouse, or qualifying provider. For a provider, identify the covered transaction and the electronic transmission, including transmission performed through a billing service or another party. Preserve transaction type, standard, system, sender, recipient, date, and reviewer.

Licensure, an NPI, accepting insurance, EHR use, or electronic communication alone does not establish the provider test. Apply the complete current definition.

Map organizational boundaries

Record legal entities, locations, components, ownership, shared services, workforce, hybrid-entity designation where relevant, affiliated relationships, and systems. Determine which component performs the covered function and which data and workflows are included. A corporate parent or brand may not be the operative covered entity.

Reassess acquisitions, divestitures, new sites, centralized billing, payer products, clearinghouse functions, and reorganizations.

Apply status to actual controls

Connect the classification to Part 2 consent and redisclosure pathways, HIPAA privacy and security, business associates, breach response, notices, patient rights, complaints, proceedings, state law, and contracts. A Part 2 rule may expressly distinguish covered entities, business associates, and non-HIPAA lawful holders.

Document which status the entity has for each workflow and why. Avoid one global flag when roles differ.

Monitor transactions and services

Inventory covered and noncovered transactions, transmission methods, billing vendors, clearinghouses, payer interfaces, and new services. Review changes before activation and test production configuration. Retain historical effective dates so earlier decisions can be reproduced.

Audit entity records, transactions, vendor routes, hybrid boundaries, misclassification, stale status, and access. Correct downstream agreements, notices, and workflows when the classification changes.

Preserve a classification record

Keep a dated entity diagram and written analysis showing legal entity, health plan or clearinghouse function where applicable, provider services, electronic covered transactions, billing or transmission agents, hybrid components, and responsible owners. Link contracts and production evidence rather than copying a yes-or-no status from a questionnaire. Record open factual or legal questions and the decision that controls while they are resolved.

Review the classification at least when a new payer route, transaction type, billing vendor, product, acquisition, or location is introduced. Tell privacy, security, contracting, and patient-rights teams about an effective change before relying on it. A status correction can require new notices, agreements, incident procedures, rights workflows, and redisclosure rules, not merely a database update.

Example

Twelve entity configurations are reviewed. Nine preserve Part 2 analysis, HIPAA category, transaction and transmission facts, organizational boundaries, owner, date, and change triggers; three infer status from an NPI. Classification completeness is 9 of 12 configurations.

Covered-entity checklist

  • determine Part 2 program status and HIPAA status as separate questions;
  • test health plan, clearinghouse, or provider category under the current definition;
  • identify the provider's electronic covered transaction and routing parties;
  • map legal entities, components, sites, systems, workforce, and shared services;
  • connect status to Part 2, HIPAA, vendor, notice, rights, and security controls; and
  • monitor transactions, services, reorganizations, routes, and classification changes.

Covered-entity status is a factual HIPAA classification. A provider label or Part 2 program designation does not answer it by itself.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni