Skip to main content
Category: Regulatory Framework

Hybrid Entity

Simply put

A hybrid entity is a single organization that does some things covered by HIPAA and other things that are not. Instead of applying HIPAA rules across the entire organization, it can formally designate only the parts that perform health care functions as its 'health care component,' so most HIPAA obligations apply mainly to those designated parts. This designation is generally optional and is chosen by the organization itself.

Formal definition

Under the HIPAA Privacy Rule, a hybrid entity is a single legal entity that qualifies as a covered entity but performs both covered functions and non-covered functions. Such an entity may elect hybrid status and must designate one or more health care components consisting of the portions of its operations that perform covered functions (and certain functions that would make a unit a business associate of a covered component). When properly designated, most HIPAA requirements generally apply to the designated health care component(s) rather than to the entity as a whole, though the covered entity retains overall responsibility for compliance, including ensuring the health care component does not improperly disclose PHI to other parts of the organization. Note that 'hybrid entity' has an unrelated meaning in tax law (entities treated differently across jurisdictions), which is out of scope here. Specific designation requirements, the definition of covered and non-covered functions, and any related obligations should be verified against the current text of the Privacy Rule, and readers should note that the Security Rule and state law may impose additional considerations.

Why it matters

Hybrid entity designation matters most for large, diverse organizations, such as universities, government agencies, or corporations, where only a portion of the operation performs health care functions. Without a hybrid designation, the entire legal entity could be treated as a covered entity, potentially sweeping units that have nothing to do with health care under HIPAA's obligations. By formally designating a health care component, an organization can generally focus most HIPAA Privacy Rule requirements on the parts that actually perform covered functions, which can simplify compliance and reduce unnecessary burden on unrelated business units.

At the same time, the designation is not a way to escape responsibility. The covered entity as a whole retains overall accountability for compliance, including the obligation to ensure that the health care component does not improperly share protected health information (PHI) with other, non-covered parts of the same organization. This internal firewall requirement is a central reason the designation must be done carefully: treating separate parts of one legal entity as insiders or outsiders for PHI purposes requires clear, documented boundaries. A poorly drawn or undocumented designation can leave an organization exposed to the argument that HIPAA applies to the entire entity.

Because hybrid status is generally optional and self-elected, the decision itself carries compliance consequences. Organizations that qualify but choose not to designate a health care component may find HIPAA obligations applying more broadly than intended. Readers should verify specific designation requirements against the current text of the Privacy Rule, and should note that the Security Rule and applicable state laws may impose additional considerations beyond the Privacy Rule's hybrid entity provisions.

Who it's relevant to

Universities and academic institutions
Colleges and universities frequently perform some HIPAA-covered functions, such as operating a student health clinic or academic medical center, alongside many activities that are not covered. Hybrid entity designation allows such institutions to focus most Privacy Rule obligations on the designated health care component rather than the entire university.
Government agencies and large employers
A single legal entity that conducts both covered and non-covered functions, such as a government agency or a large employer operating an on-site clinic, may elect hybrid status to apply HIPAA obligations mainly to the parts performing health care functions while maintaining the required internal boundaries around PHI.
Privacy officers and compliance staff
Those responsible for HIPAA compliance must carefully draw and document the health care component, ensure PHI is not improperly disclosed to non-covered parts of the organization, and recognize that the entity retains overall responsibility for compliance despite the designation. They should verify designation requirements against the current Privacy Rule text.
Legal counsel advising diversified organizations
Attorneys should note that 'hybrid entity' under HIPAA is unrelated to its meaning in tax law, where it refers to entities treated differently across jurisdictions. Counsel advising on HIPAA hybrid status should also consider that the Security Rule and state law may impose additional requirements beyond the Privacy Rule's hybrid provisions.

Inside Hybrid Entity

Hybrid Entity Designation
A hybrid entity is a single legal entity whose business activities include both covered and non-covered functions, and that formally designates one or more health care components to which HIPAA obligations apply. The designation is a documented decision made by the entity itself under the Privacy Rule.
Health Care Component
The part or parts of the organization that perform covered functions (or activities that would make a unit a business associate if it were separate). Once designated, the health care component is generally the portion of the entity that must comply with the applicable HIPAA requirements, including relevant Privacy and Security Rule obligations for PHI and ePHI it handles.
Non-Covered Functions
Business activities of the same legal entity that do not involve covered functions. These fall outside the designated health care component, though the entity must still take care to control how PHI moves between components.
Internal Firewalls and Safeguards
Because the covered and non-covered parts share one legal entity, the entity must generally implement safeguards to prevent the health care component from disclosing PHI to the non-covered parts of the organization in a manner that would violate the Privacy Rule, treating such internal flows with appropriate controls.
Documentation of Designation
The entity should maintain written documentation identifying which components are designated as health care components. This documentation supports demonstrating compliance and clarifies where HIPAA obligations attach within the organization.

Common questions

Answers to the questions practitioners most commonly ask about Hybrid Entity.

Does becoming a hybrid entity mean parts of my organization are exempt from HIPAA?
No. Designating hybrid entity status does not exempt any part of the organization from HIPAA. It defines which components, the health care components, are subject to the applicable HIPAA rules, while the rest of the organization is generally not treated as part of the covered entity for those purposes. However, the covered entity as a whole remains responsible for ensuring the designation is properly made and maintained, and the non-health care components are still restricted in how they may use or disclose protected health information received from a health care component. The designation limits scope; it does not create a HIPAA-free zone.
If any part of my organization handles PHI, does the whole organization automatically fall under HIPAA?
Not necessarily. The hybrid entity provisions exist precisely so that a single legal entity performing both covered and non-covered functions can, by designating its health care components, limit the reach of the applicable rules to those designated components. Absent that designation, the entire legal entity is generally treated as the covered entity. So the outcome depends on whether a valid hybrid entity designation has been made and whether the components have been correctly identified. Readers should verify the current regulatory text, as the precise definitions and requirements are set by HHS regulations.
How do we determine which of our components must be designated as health care components?
Generally, a component that performs covered functions, the functions that make the organization a covered entity, must be included, as must components that perform activities that would make them a business associate of a health care component if they were separate legal entities. Organizations typically map their business functions, identify where covered functions and PHI-handling support activities occur, and document the analysis. Because the specific criteria are defined in the HIPAA regulations and can be nuanced, the analysis should be reviewed against the current regulatory text and, in most cases, with qualified counsel.
What documentation should we maintain to support our hybrid entity designation?
Organizations generally maintain a written designation identifying the health care components, along with the underlying analysis showing how those components were determined. Because HIPAA requires covered entities to retain certain documentation for a specified period, the designation and supporting records should be kept and updated as the organization changes. Verify current retention requirements and any documentation specifics against the applicable regulatory text, and note that state law may impose additional recordkeeping obligations.
How should information flow between health care components and non-health care components be controlled?
A hybrid entity must generally erect appropriate safeguards so that PHI is not improperly disclosed from a health care component to a non-health care component. In practice this typically involves treating disclosures across that internal boundary similarly to disclosures to a separate entity, applying access controls, and limiting use of PHI by non-health care components. For electronic PHI, the Security Rule's administrative, physical, and technical safeguards apply to the health care components; note that addressable specifications are not optional and must be evaluated. Confirm specifics against current regulatory guidance.
When should we revisit or update our hybrid entity designation?
Organizations typically review the designation when business functions change, such as adding, removing, or restructuring components, launching new services that handle PHI, or altering how components support covered functions. Periodic review is generally advisable even without changes, to confirm the designation still reflects operations. Because an outdated designation can misstate the scope of HIPAA obligations, many organizations tie the review to broader compliance assessments. Any updates should be documented and evaluated against the current regulatory text.

Common misconceptions

Designating as a hybrid entity means only the health care component has any HIPAA responsibility and the rest of the organization can ignore PHI entirely.
The overall legal entity remains responsible for making the designation correctly and for ensuring that the non-designated parts do not receive or use PHI in ways that violate the Privacy Rule. The entity must generally maintain safeguards controlling PHI flow between components, so obligations do not disappear for the broader organization.
Any organization can freely choose to be a hybrid entity to reduce its compliance scope.
Hybrid entity status is a Privacy Rule concept available to a single legal entity that performs both covered and non-covered functions. It is not a general opt-out mechanism, and the designation must accurately reflect which components perform covered functions rather than being used simply to shrink obligations.
Being a hybrid entity changes which HIPAA rules apply to protected health information.
The scope of each rule is unchanged. The Privacy Rule still covers PHI in all forms and the Security Rule still covers only ePHI within the designated health care component. Hybrid designation affects which parts of the organization the obligations attach to, not the substance of those obligations. Readers should verify specifics against the current regulatory text.

Best practices

Formally document the hybrid entity designation, clearly identifying each component treated as a health care component and the covered functions it performs.
Implement and document internal safeguards, sometimes described as firewalls, to prevent impermissible PHI disclosures from the health care component to non-covered parts of the same legal entity.
Periodically review the designation to confirm it still accurately reflects the organization's covered and non-covered functions as business activities change.
Ensure the designated health care component applies the applicable Privacy and Security Rule requirements to the PHI and ePHI it handles, distinguishing which safeguards attach to electronic information.
Train staff in non-covered components on the limits regarding access to and use of PHI so that internal boundaries are respected in practice.
Confirm the specific requirements and definitions of hybrid entity status against the current HIPAA regulatory text and any applicable state law, which may impose additional obligations beyond HIPAA.