Skip to main content
Category: Regulatory Framework

Health Care Clearinghouse

Also known as: Healthcare Clearinghouse, Medical Billing Clearinghouse, Medical Intermediary
Simply put

A health care clearinghouse is an organization that acts as a middleman between healthcare providers and health plans (insurance payers). It receives health information such as claims, checks and processes it, and translates it between nonstandard and standard formats so that providers and payers can exchange data. Under HIPAA, a clearinghouse is one of the three types of covered entities that must comply with HIPAA rules.

Formal definition

A health care clearinghouse is a public or private entity, including a billing service, repricing company, community health management information system or community health information network, or a value-added network or switch, that performs either of two functions: (1) processing or facilitating the processing of health information received from another entity in a nonstandard format or containing nonstandard data content into standard data elements or a standard transaction; or (2) receiving a standard transaction from another entity and processing or facilitating the processing of that information into nonstandard format or nonstandard data content for a receiving entity. As one of the three categories of HIPAA covered entities (alongside health plans and health care providers who transmit health information in connection with covered transactions), a clearinghouse is directly subject to the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Note that when a clearinghouse creates, receives, maintains, or transmits protected health information as a business associate of another covered entity, HIPAA imposes certain limitations on its use and disclosure of that PHI; practitioners should verify the specific regulatory definition and applicable requirements against the current text of 45 CFR (Part 160 and Part 164). This entry addresses the HIPAA regulatory meaning of the term, which may differ from broader industry usage describing any medical billing intermediary.

Why it matters

Health care clearinghouses occupy a pivotal position in the flow of health information between providers and payers, and their status as one of the three categories of HIPAA covered entities means they carry direct regulatory obligations rather than obligations that flow only through contracts. Because a clearinghouse handles large volumes of claims data that typically contain protected health information (PHI), it is directly subject to the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, and is accountable to HHS OCR for compliance. Understanding whether an organization meets the regulatory definition of a clearinghouse is therefore essential to determining the scope of its compliance responsibilities.

Who it's relevant to

Clearinghouse compliance and privacy officers
Officers at organizations that meet the regulatory definition of a clearinghouse should recognize that their entity is a covered entity subject directly to the HIPAA Privacy, Security, and Breach Notification Rules. They should also assess when the clearinghouse is acting as a business associate of another covered entity, since that role carries certain limitations on the use and disclosure of PHI. Both roles should be mapped against the current text of 45 CFR.
Healthcare providers and their billing teams
Providers that route claims through a clearinghouse should understand the intermediary's role in translating data between nonstandard and standard formats, and should confirm whether the clearinghouse is functioning as a business associate on their behalf. Where a business associate relationship exists, obligations attach through the appropriate defined relationship and agreement, which teams should verify.
Health plans and payers
Payers that receive claims and other transactions from clearinghouses rely on these entities to deliver data in standard formats. Payers should understand the clearinghouse's covered-entity status and the circumstances in which it may act as a business associate when handling PHI on another entity's behalf.
Auditors and legal counsel
Auditors and counsel evaluating an organization's HIPAA posture should carefully determine whether the entity meets the regulatory definition of a clearinghouse, since this drives whether HIPAA obligations apply directly rather than through contract. They should note that the term's HIPAA regulatory meaning may differ from broader industry usage describing any medical billing intermediary, and should confirm applicable requirements against the current regulation.

Inside Health Care Clearinghouse

Statutory Definition
A health care clearinghouse is one of the three types of covered entities under HIPAA, alongside health plans and health care providers who transmit health information in connection with covered transactions. It is a public or private entity that processes health information.
Format Translation Function
The defining activity of a clearinghouse is processing or facilitating the processing of health information received from another entity from a nonstandard format or nonstandard content into a standard data element or standard transaction, or vice versa (from standard back into nonstandard format for a receiving entity).
Typical Entities
Entities generally treated as clearinghouses include billing services, repricing companies, community health management information systems, value-added networks, and switches, but only to the extent they perform clearinghouse functions rather than other roles.
Covered Entity Obligations
As a covered entity, a clearinghouse is directly subject to the HIPAA Privacy Rule (covering PHI in all forms), the Security Rule (covering ePHI through administrative, physical, and technical safeguards), the Breach Notification Rule, and the Enforcement Rule administered by HHS OCR.
Business Associate Relationship Nuance
A clearinghouse frequently acts as a business associate when it performs clearinghouse functions on behalf of another covered entity. In that context, its obligations and permitted uses and disclosures are typically shaped by the applicable business associate agreement, and special Privacy Rule provisions may apply to information it processes in that role.

Common questions

Answers to the questions practitioners most commonly ask about Health Care Clearinghouse.

Is a health care clearinghouse the same as a business associate under HIPAA?
Not inherently. A health care clearinghouse is one of the three types of covered entities defined under HIPAA, alongside health plans and health care providers who transmit health information in covered electronic transactions. However, a clearinghouse can also function as a business associate when it performs clearinghouse services on behalf of another covered entity. In that scenario, its obligations for the information it handles in that role are shaped by the business associate relationship and the applicable business associate agreement, rather than by its status as a standalone covered entity. Because a clearinghouse frequently operates as a business associate to health plans and providers, it is important to identify the specific role and relationship at issue before determining which obligations apply. Readers should verify how these roles interact against the current regulatory text.
Does a health care clearinghouse simply store or route data without changing it?
This is a common misunderstanding. The regulatory concept of a clearinghouse generally centers on processing or facilitating the processing of health information from a nonstandard format or nonstandard data content into a standard format or standard data content, or the reverse. In other words, the defining function typically involves translation or reformatting between standard and nonstandard forms, not mere passive storage or transmission. Entities that only store or route data without performing this format or content conversion may not meet the regulatory definition of a clearinghouse, though they could still fall under other HIPAA roles depending on their activities. The precise scope should be confirmed against the current definition in the regulation.
When a clearinghouse acts as a business associate, which HIPAA rules govern its use of PHI?
When a clearinghouse operates as a business associate on behalf of another covered entity, its permitted uses and disclosures of protected health information are generally governed by the terms of the business associate agreement and by the applicable provisions of the Privacy Rule that extend to business associates, in addition to the Security Rule obligations that apply to electronic protected health information. The Privacy Rule includes specific provisions addressing how a clearinghouse handles PHI it receives or creates in its business associate capacity. Because the interplay between covered entity and business associate roles can be intricate, entities should map each function to the correct obligations and confirm the details against the current regulatory text.
What Security Rule obligations apply to a clearinghouse handling electronic protected health information?
As an entity that handles electronic protected health information, a clearinghouse is generally expected to implement the administrative, physical, and technical safeguards required under the Security Rule, along with the associated required and addressable implementation specifications. Addressable does not mean optional; it generally means an entity must assess whether a specification is reasonable and appropriate in its environment and, if not, document the rationale and implement an equivalent alternative where reasonable and appropriate. A clearinghouse that is part of a larger organization may also be subject to specific provisions concerning the separation and protection of ePHI within that larger structure. The exact requirements should be confirmed against the current Security Rule text.
How should an organization determine whether one of its functions qualifies as a clearinghouse?
An organization should generally analyze whether the function in question involves processing or facilitating the processing of health information into a standard format or standard data content from a nonstandard form, or the reverse, in connection with covered transactions. This analysis focuses on the actual activities performed rather than on how a service is marketed or labeled. Because an entity can hold more than one HIPAA role at once, it is often helpful to inventory each data-handling activity and assess it separately. Where the determination is unclear, organizations typically consult the current regulatory definitions and may seek legal review to confirm the classification.
Does obtaining HITRUST certification establish that a clearinghouse is HIPAA compliant?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. A clearinghouse may use the HITRUST CSF to help structure and demonstrate its security and privacy controls, but HIPAA compliance is assessed against the requirements of the applicable HIPAA rules as enforced by HHS OCR. Organizations should treat any framework certification as supporting evidence rather than a substitute for meeting the underlying regulatory obligations, and should also consider that the HITECH Act, state law, or other frameworks may impose additional requirements. Specific control mappings should be verified against the current HITRUST CSF version.

Common misconceptions

A health care clearinghouse is a vendor regulated only through a business associate agreement, not a covered entity itself.
A clearinghouse is expressly one of the three categories of covered entity under HIPAA and is directly subject to HIPAA rules. It may also act as a business associate when performing functions on behalf of another covered entity, but that role does not remove its own covered-entity status.
Any organization that touches or transmits health data qualifies as a clearinghouse.
The term has a specific regulatory meaning tied to translating health information between nonstandard and standard formats or content. An entity is generally treated as a clearinghouse only to the extent it performs that translation function; merely handling or transmitting data does not by itself make an organization a clearinghouse.
Because a clearinghouse mainly handles electronic transactions, only the Security Rule applies to it.
The Security Rule governs only ePHI, but as a covered entity a clearinghouse is also subject to the Privacy Rule, which covers PHI in all forms, as well as the Breach Notification and Enforcement Rules. Its compliance obligations are not limited to electronic safeguards.

Best practices

Confirm whether your organization meets the regulatory definition of a clearinghouse based on the format-translation function you actually perform, rather than assuming your status from general data handling, and verify the current definition against the applicable regulatory text.
Map which activities you perform as a covered entity versus as a business associate on behalf of another covered entity, since the applicable business associate agreement typically shapes permitted uses and disclosures in the latter role.
Maintain compliance across all applicable HIPAA rules, not just the Security Rule, ensuring Privacy Rule protections cover PHI in all forms and that Breach Notification procedures are in place.
Implement Security Rule safeguards across administrative, physical, and technical categories for ePHI, treating addressable implementation specifications as requiring documented evaluation rather than as optional.
Ensure business associate agreements are in place and current with each covered entity for whom you perform clearinghouse functions, and clarify the special Privacy Rule provisions that may apply to information processed in that capacity.
Check whether state law, the HITECH Act, or other frameworks impose additional obligations beyond HIPAA, and confirm penalty tiers, deadlines, and citations against current HHS OCR guidance rather than relying on fixed figures.