Skip to main content
Category: Regulatory Framework

Affiliated Covered Entity

Also known as: ACE, Affiliated Covered Entities
Simply put

An Affiliated Covered Entity (ACE) is a group of legally separate HIPAA covered entities that share common ownership or control and choose to treat themselves as a single covered entity for HIPAA compliance purposes. This designation lets organizations under the same corporate umbrella coordinate their privacy practices as one unit rather than managing each entity entirely separately. The designation is optional, and only entities that are themselves covered entities may participate.

Formal definition

Under the HIPAA regulations (generally addressed at 45 CFR 164.105(b)), an Affiliated Covered Entity refers to legally separate covered entities that are affiliated by common ownership or control and that designate themselves as a single covered entity for purposes of the applicable regulatory requirements. Only entities that independently qualify as covered entities may be included in an ACE designation; business associates and non-covered organizations cannot be brought into an ACE for this purpose. The ACE construct affects how affiliated entities may operate as a unit for compliance, but it does not eliminate the underlying obligations of the covered entities, and each participating entity generally remains subject to HIPAA. Readers should verify the specific requirements, designation mechanics, and citation against the current text of the regulation, and should note that the HITECH Act, state law, or other frameworks may impose additional obligations beyond HIPAA.

Why it matters

Large healthcare organizations frequently operate as networks of legally distinct entities, separate hospitals, clinics, physician practices, or pharmacies, that nonetheless share common ownership or control. Without the Affiliated Covered Entity designation, each of these entities would generally have to manage its HIPAA Privacy Rule obligations in isolation, maintaining separate privacy notices, policies, and administrative structures even when they function as parts of a single enterprise. The ACE construct allows such affiliated entities to designate themselves as a single covered entity for compliance purposes, which can reduce duplication and support coordinated privacy practices across the corporate umbrella.

The designation matters most for how it streamlines compliance while preserving accountability. An ACE does not dissolve the legal separateness of its members, nor does it eliminate the underlying HIPAA obligations of any participating entity. Each covered entity that joins an ACE generally remains subject to HIPAA in its own right. Organizations sometimes misunderstand the ACE as a way to sweep vendors, contractors, or other non-covered organizations into a shared compliance arrangement; that is not permitted. Only entities that independently qualify as covered entities may participate, and business associates cannot be brought into an ACE through this mechanism.

Because the ACE designation affects how privacy responsibilities are structured across an enterprise, getting it wrong can create gaps in accountability or lead to inaccurate assumptions about which entity bears responsibility for a given obligation. The designation is optional, and organizations should weigh whether it fits their structure. Readers should also note that the HITECH Act, state law, or other frameworks may impose additional obligations beyond what the HIPAA ACE provisions address, and the specific mechanics of designation should be confirmed against the current regulatory text.

Who it's relevant to

Privacy Officers at Multi-Entity Health Systems
Privacy officers responsible for organizations composed of several legally separate covered entities under common ownership or control are the primary audience for the ACE construct. They evaluate whether designating an ACE would allow their affiliated entities to coordinate privacy practices as a single unit, and they must ensure that the designation does not create false assumptions about eliminated obligations, each participating entity generally remains subject to HIPAA.
Compliance and Legal Counsel
In-house and external counsel advising healthcare enterprises need to assess whether the common ownership or control test is met and whether every proposed member independently qualifies as a covered entity. They should confirm designation mechanics against the current text of 45 CFR 164.105(b) and flag that business associates and non-covered organizations cannot be included, as well as any additional obligations arising under the HITECH Act or state law.
Corporate Governance and Enterprise Risk Teams
Teams managing governance across a corporate umbrella of healthcare organizations use the ACE designation to structure coordinated compliance while preserving the legal separateness of member entities. They should understand that the ACE affects how entities may operate as a unit for compliance but does not dissolve the individual accountability of each covered entity.
Auditors and Assessors
Auditors reviewing an organization's HIPAA Privacy Rule posture should verify whether an ACE designation exists, confirm that all included entities qualify as covered entities, and check that the designation is documented in line with current regulatory requirements. They should not treat an ACE as a substitute for confirming that each participating entity meets its underlying HIPAA obligations.

Inside ACE

Legally Separate Covered Entities Under Common Ownership or Control
An affiliated covered entity (ACE) consists of two or more covered entities that are legally distinct but are under common ownership or control. Common ownership or control generally refers to one entity having an ownership or equity interest in the others, or the power to direct their actions or policies, as defined in the HIPAA Privacy Rule. Readers should verify the specific definitions against the current regulatory text.
Designation as a Single Covered Entity for Privacy Rule Compliance
The affiliation allows the participating legally separate covered entities to designate themselves as a single covered entity for purposes of complying with the HIPAA Privacy Rule. This is a Privacy Rule construct and its primary effect is to permit the affiliated entities to be treated as one entity for those compliance purposes.
Documentation of the Designation
The designation of an affiliated covered entity generally must be documented in writing. Practitioners should confirm the current documentation requirements against the applicable regulatory text, as specific content and retention expectations may be detailed in the Privacy Rule.
Continued Individual Liability
Even when entities operate as an affiliated covered entity, each participating covered entity generally remains responsible and can be held liable for the acts of the other members related to the joint compliance efforts. The designation does not eliminate individual accountability under HIPAA as enforced by HHS OCR.
Scope Limited to HIPAA and Distinct from Related Concepts
An ACE is a specific HIPAA Privacy Rule mechanism and differs from related concepts such as an organized health care arrangement (OHCA) or a hybrid entity. It should not be confused with business associate relationships, which attach obligations through business associate agreements rather than through common ownership or control.

Common questions

Answers to the questions practitioners most commonly ask about ACE.

Does designating an affiliated covered entity mean the affiliated organizations become a single legal entity?
No. An affiliated covered entity (ACE) designation does not merge the participating organizations into one legal entity. The organizations generally remain legally separate; the ACE designation allows legally separate covered entities under common ownership or control to designate themselves as a single covered entity for purposes of complying with the HIPAA Privacy Rule (and, where applicable, related Security Rule obligations). Each participant typically retains its own separate legal identity, liabilities, and corporate governance. You should verify the current regulatory text for the precise scope of the designation.
Does forming an affiliated covered entity eliminate the need for business associate agreements or shift liability entirely?
No. An ACE designation addresses how legally separate covered entities under common control may treat themselves as a single covered entity for compliance purposes; it does not by itself remove obligations that attach through other defined relationships. Where a vendor or other party meets the definition of a business associate, a business associate agreement is generally still required. In addition, participants in an ACE may share responsibility for compliance failures, so the designation does not simply shift or eliminate liability. Confirm specific obligations against the current regulation and consult counsel for your arrangement.
What is the threshold requirement for organizations to designate an affiliated covered entity?
The core prerequisite is generally that the participating covered entities be under common ownership or common control. If that relationship does not exist, the organizations typically cannot use the ACE designation. Because the precise definitions of common ownership and common control have specific regulatory meanings that differ from common business usage, you should verify the current regulatory text before relying on this designation.
How should an affiliated covered entity be documented?
Organizations generally document the ACE designation in writing, identifying the covered entities that are included. As a practical matter, maintaining clear documentation of the designation, the entities covered, and the effective scope supports demonstrating your compliance posture. Because documentation requirements and any specific content elements are set by the regulation, confirm the current requirements against the applicable regulatory text rather than relying on a fixed template.
Can an affiliated covered entity share protected health information freely among its participants?
Because an ACE may treat itself as a single covered entity for Privacy Rule compliance purposes, uses and disclosures of PHI among the participating entities are generally handled as they would be within a single covered entity. However, this does not remove other applicable requirements, and state law, the HITECH Act, or other frameworks may impose additional restrictions. You should verify how the current regulation treats intra-ACE uses and disclosures for your specific situation.
Does an affiliated covered entity designation change obligations under the HIPAA Security Rule for ePHI?
The ACE concept originates in the context of the Privacy Rule, which covers PHI in all forms including oral and paper. The Security Rule, by contrast, applies only to electronic protected health information (ePHI). Where participants create, receive, maintain, or transmit ePHI, Security Rule obligations, including administrative, physical, and technical safeguards and their required and addressable implementation specifications, continue to apply. The designation does not by itself relieve any participant of Security Rule responsibilities; confirm how these obligations apply to your arrangement against the current regulatory text.

Common misconceptions

Forming an affiliated covered entity means only one member has to comply with HIPAA and the others are off the hook.
The ACE designation allows legally separate covered entities to be treated as a single covered entity for Privacy Rule compliance purposes, but each participating entity generally remains individually responsible and can be held liable for compliance failures. The designation streamlines compliance; it does not remove accountability from any member.
Any group of companies that share data can designate themselves as an affiliated covered entity.
The ACE mechanism is available only to covered entities that are under common ownership or control, as defined in the HIPAA Privacy Rule. Entities that merely share data without qualifying ownership or control do not meet the criteria, and vendors that handle data typically fall under business associate rules instead, with obligations attaching through business associate agreements.
An affiliated covered entity is the same thing as an organized health care arrangement or a hybrid entity.
These are distinct HIPAA concepts. An ACE is based on common ownership or control and permits designation as a single covered entity for Privacy Rule compliance, whereas an OHCA and a hybrid entity address different arrangements and structures. Practitioners should apply the specific definition that matches their situation and verify each against the current regulatory text.

Best practices

Confirm that all entities intended to be part of the affiliated covered entity genuinely meet the common ownership or control criteria under the HIPAA Privacy Rule before making a designation, and verify the specific definitions against the current regulatory text.
Document the affiliated covered entity designation in writing and retain that documentation, confirming the current content and retention requirements against the applicable Privacy Rule provisions.
Recognize that the ACE designation applies to HIPAA Privacy Rule compliance, and do not assume it alters obligations under other rules; separately address Security Rule requirements for ePHI and any Breach Notification Rule obligations.
Maintain internal accountability structures across all member entities, since each participating covered entity generally remains individually liable; do not rely on the designation to shift responsibility away from any member.
Distinguish the ACE arrangement from business associate relationships, OHCAs, and hybrid entity structures, and select the mechanism that accurately reflects your organizational relationships.
Check whether state law or the HITECH Act may impose additional requirements beyond the federal HIPAA framework, and confirm current guidance with HHS OCR resources or qualified counsel.