Hybrid Entity
A hybrid entity is a single organization that does some things covered by HIPAA and other things that are not. Instead of applying HIPAA rules across the entire organization, it can formally designate only the parts that perform health care functions as its 'health care component,' so most HIPAA obligations apply mainly to those designated parts. This designation is generally optional and is chosen by the organization itself.
Under the HIPAA Privacy Rule, a hybrid entity is a single legal entity that qualifies as a covered entity but performs both covered functions and non-covered functions. Such an entity may elect hybrid status and must designate one or more health care components consisting of the portions of its operations that perform covered functions (and certain functions that would make a unit a business associate of a covered component). When properly designated, most HIPAA requirements generally apply to the designated health care component(s) rather than to the entity as a whole, though the covered entity retains overall responsibility for compliance, including ensuring the health care component does not improperly disclose PHI to other parts of the organization. Note that 'hybrid entity' has an unrelated meaning in tax law (entities treated differently across jurisdictions), which is out of scope here. Specific designation requirements, the definition of covered and non-covered functions, and any related obligations should be verified against the current text of the Privacy Rule, and readers should note that the Security Rule and state law may impose additional considerations.
Why it matters
Hybrid entity designation matters most for large, diverse organizations, such as universities, government agencies, or corporations, where only a portion of the operation performs health care functions. Without a hybrid designation, the entire legal entity could be treated as a covered entity, potentially sweeping units that have nothing to do with health care under HIPAA's obligations. By formally designating a health care component, an organization can generally focus most HIPAA Privacy Rule requirements on the parts that actually perform covered functions, which can simplify compliance and reduce unnecessary burden on unrelated business units.
At the same time, the designation is not a way to escape responsibility. The covered entity as a whole retains overall accountability for compliance, including the obligation to ensure that the health care component does not improperly share protected health information (PHI) with other, non-covered parts of the same organization. This internal firewall requirement is a central reason the designation must be done carefully: treating separate parts of one legal entity as insiders or outsiders for PHI purposes requires clear, documented boundaries. A poorly drawn or undocumented designation can leave an organization exposed to the argument that HIPAA applies to the entire entity.
Because hybrid status is generally optional and self-elected, the decision itself carries compliance consequences. Organizations that qualify but choose not to designate a health care component may find HIPAA obligations applying more broadly than intended. Readers should verify specific designation requirements against the current text of the Privacy Rule, and should note that the Security Rule and applicable state laws may impose additional considerations beyond the Privacy Rule's hybrid entity provisions.
Who it's relevant to
Inside Hybrid Entity
Common questions
Answers to the questions practitioners most commonly ask about Hybrid Entity.