Affiliated Covered Entity
An Affiliated Covered Entity (ACE) is a group of legally separate HIPAA covered entities that share common ownership or control and choose to treat themselves as a single covered entity for HIPAA compliance purposes. This designation lets organizations under the same corporate umbrella coordinate their privacy practices as one unit rather than managing each entity entirely separately. The designation is optional, and only entities that are themselves covered entities may participate.
Under the HIPAA regulations (generally addressed at 45 CFR 164.105(b)), an Affiliated Covered Entity refers to legally separate covered entities that are affiliated by common ownership or control and that designate themselves as a single covered entity for purposes of the applicable regulatory requirements. Only entities that independently qualify as covered entities may be included in an ACE designation; business associates and non-covered organizations cannot be brought into an ACE for this purpose. The ACE construct affects how affiliated entities may operate as a unit for compliance, but it does not eliminate the underlying obligations of the covered entities, and each participating entity generally remains subject to HIPAA. Readers should verify the specific requirements, designation mechanics, and citation against the current text of the regulation, and should note that the HITECH Act, state law, or other frameworks may impose additional obligations beyond HIPAA.
Why it matters
Large healthcare organizations frequently operate as networks of legally distinct entities, separate hospitals, clinics, physician practices, or pharmacies, that nonetheless share common ownership or control. Without the Affiliated Covered Entity designation, each of these entities would generally have to manage its HIPAA Privacy Rule obligations in isolation, maintaining separate privacy notices, policies, and administrative structures even when they function as parts of a single enterprise. The ACE construct allows such affiliated entities to designate themselves as a single covered entity for compliance purposes, which can reduce duplication and support coordinated privacy practices across the corporate umbrella.
The designation matters most for how it streamlines compliance while preserving accountability. An ACE does not dissolve the legal separateness of its members, nor does it eliminate the underlying HIPAA obligations of any participating entity. Each covered entity that joins an ACE generally remains subject to HIPAA in its own right. Organizations sometimes misunderstand the ACE as a way to sweep vendors, contractors, or other non-covered organizations into a shared compliance arrangement; that is not permitted. Only entities that independently qualify as covered entities may participate, and business associates cannot be brought into an ACE through this mechanism.
Because the ACE designation affects how privacy responsibilities are structured across an enterprise, getting it wrong can create gaps in accountability or lead to inaccurate assumptions about which entity bears responsibility for a given obligation. The designation is optional, and organizations should weigh whether it fits their structure. Readers should also note that the HITECH Act, state law, or other frameworks may impose additional obligations beyond what the HIPAA ACE provisions address, and the specific mechanics of designation should be confirmed against the current regulatory text.
Who it's relevant to
Inside ACE
Common questions
Answers to the questions practitioners most commonly ask about ACE.