Skip to main content
Category: Regulatory Framework

Organized Health Care Arrangement

Also known as: OHCA, Organized Health Care Arrangements, OHCAs
Simply put

An Organized Health Care Arrangement (OHCA) is an arrangement in which more than one covered entity works together in a shared or clinically integrated care setting, such as a hospital and the independent providers who practice there. Because these entities coordinate care for the same patients, HIPAA allows them to share protected health information and to use a single, joint privacy notice rather than each issuing its own. Being part of an OHCA does not remove any participant's own responsibilities under HIPAA.

Formal definition

Under the HIPAA Privacy Rule, an Organized Health Care Arrangement (OHCA) is a defined type of arrangement among covered entities that, per 45 CFR 160.103, generally includes a clinically integrated care setting in which individuals typically receive health care from more than one health care provider, as well as certain organized systems of health care in which more than one covered entity participates and holds itself out to the public as participating in a joint arrangement. Participation in an OHCA permits the participating covered entities to share protected health information for the joint activities of the arrangement and to satisfy notice obligations through a single, joint notice of privacy practices, subject to the applicable requirements. The OHCA construct is specific to the Privacy Rule and does not alter each participant's independent status as a covered entity or its individual compliance obligations; readers should confirm the full regulatory definition and its subparts against the current text of 45 CFR 160.103, and note that state law may impose additional requirements.

Why it matters

The Organized Health Care Arrangement (OHCA) construct addresses a practical reality of modern healthcare delivery: patients frequently receive care from multiple providers who share the same clinical setting but remain legally distinct covered entities. A hospital and the independent physicians who admit and treat patients there, for example, must coordinate care and share protected health information to treat those patients effectively. Without a mechanism like the OHCA, each participating covered entity under the HIPAA Privacy Rule would face duplicative and potentially confusing notice obligations, and the sharing of PHI for joint activities would be harder to administer.

The OHCA matters because it streamlines two things in particular: it permits participating covered entities to share protected health information for the joint activities of the arrangement, and it allows them to satisfy their notice of privacy practices obligations through a single, joint notice rather than each entity issuing its own. This reduces administrative burden and gives patients a clearer picture of how their information is used across the integrated care setting. Real-world arrangements exist, such as the framework described by Northwestern Medicine and the arrangement among provider entities affiliated with Allegheny Health Network and health plan entities affiliated with Highmark.

Critically, participation in an OHCA does not dissolve or reduce any participant's independent obligations. Each covered entity remains a covered entity in its own right, responsible for its own Privacy Rule and Security Rule compliance. The OHCA is a Privacy Rule construct that facilitates coordination; it is not a merger of legal responsibility, and it does not by itself resolve obligations that may arise under state law or other frameworks.

Who it's relevant to

Hospitals and Integrated Care Settings
Hospitals whose patients are treated by independent providers practicing on-site are among the most common OHCA participants. These organizations rely on the OHCA framework to share protected health information for joint care activities and to coordinate a single, joint notice of privacy practices, while still maintaining their own independent HIPAA compliance responsibilities.
Independent Providers Practicing Within a Shared Setting
Independent physicians and other providers who treat patients within a clinically integrated setting may qualify as OHCA participants. They should understand that joining an OHCA facilitates PHI sharing and joint notices but does not remove their individual obligations as covered entities under the Privacy Rule and other applicable HIPAA rules.
Privacy Officers and Compliance Staff
Privacy officers responsible for drafting notices of privacy practices and governing PHI disclosures need to determine whether their organization genuinely meets the OHCA definition at 45 CFR 160.103 before relying on joint notice provisions. They should verify the full regulatory language and account for any additional state-law requirements.
Legal Counsel Structuring Care Arrangements
Attorneys advising healthcare organizations on affiliations, integrated delivery networks, or combined provider-health plan arrangements must assess whether the arrangement qualifies as an OHCA and how the construct affects PHI sharing and notice obligations. Counsel should confirm subpart-specific conditions against the current regulatory text and flag where state law imposes obligations beyond HIPAA.

Inside OHCA

Clinically Integrated Care Setting
An Organized Health Care Arrangement (OHCA) generally arises where multiple covered entities participate in a clinically integrated setting in which individuals receive care from more than one provider, such as a hospital and the independent practitioners holding staff privileges there. The OHCA construct under the HIPAA Privacy Rule recognizes that these participants need to share PHI to jointly manage and operate the arrangement.
Joint Activities Among Covered Entities
An OHCA typically involves covered entities that hold themselves out to the public as participating in joint arrangements and that engage in shared activities such as utilization review, quality assessment and improvement, or payment activities involving the arrangement. These joint operations are the functional basis that distinguishes an OHCA from unrelated entities that merely exchange data.
Joint Notice of Privacy Practices
A recognized feature of an OHCA is the ability of the participating covered entities to produce and distribute a single, joint Notice of Privacy Practices covering the arrangement, rather than each entity issuing a separate notice. Practitioners should confirm the specific conditions for a joint notice against the current text of the Privacy Rule.
Privacy Rule Scope
The OHCA concept is a construct of the HIPAA Privacy Rule, which governs PHI in all forms including oral, paper, and electronic. It is distinct from the Security Rule, which addresses only electronic PHI. Participation in an OHCA does not by itself alter each entity's independent obligations under the Security Rule, the Breach Notification Rule, or the Enforcement Rule.
Permitted Information Sharing
Being part of an OHCA generally permits participating covered entities to share PHI with one another for the joint health care operations of the arrangement without each disclosure requiring a separate authorization or, in most cases, a business associate agreement between the covered participants themselves. The precise permitted uses and disclosures should be verified against current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about OHCA.

Does participating in an Organized Health Care Arrangement (OHCA) merge the participants into a single covered entity?
No. An OHCA is a defined arrangement under the HIPAA Privacy Rule that allows legally separate covered entities to share protected health information for the joint operations of the arrangement, but it does not merge them into a single legal entity. Each participant generally remains an independent covered entity responsible for its own HIPAA compliance. The OHCA framework facilitates certain permitted uses and disclosures and a joint notice of privacy practices; it does not eliminate each participant's individual obligations. Readers should confirm the specific requirements against the current Privacy Rule text.
Does an OHCA replace the need for business associate agreements between the participants?
Not in the way many assume. The OHCA construct addresses sharing of PHI among the participating covered entities for the joint activities of the arrangement, so participants may share PHI for those purposes without treating each other as business associates for that shared activity. However, this does not eliminate business associate obligations where a vendor or third party performs functions on behalf of the arrangement or a participant. Where a service provider handles PHI to perform a function or service for the OHCA or its participants, a business associate agreement is generally still required. Verify the applicable relationships against the current regulatory definitions.
How do participants in an OHCA typically handle the notice of privacy practices?
The Privacy Rule generally permits participants in an OHCA to use a single joint notice of privacy practices covering the arrangement, provided the notice meets the applicable content requirements and describes the participants or classes of participants to which it applies. This is an option that can reduce duplication, but participants should confirm that the joint notice satisfies all required elements under the current Privacy Rule and address how distribution and acknowledgment responsibilities are allocated among participants.
What kinds of uses and disclosures does OHCA status facilitate among participants?
OHCA status is generally intended to support sharing of PHI needed for the joint health care operations of the arrangement among the participating covered entities. This can include activities tied to the shared clinical or operational purposes of the arrangement. It does not create a blanket authorization to use or disclose PHI for any purpose, and other Privacy Rule limitations continue to apply. Participants should map which specific uses and disclosures fall within the joint operations of the arrangement and document that scope.
Should OHCA participants still enter into documentation defining the arrangement even though HIPAA does not require a single legal entity?
As a practical matter, yes. Because each participant remains individually responsible for HIPAA compliance, participants commonly document the scope of the arrangement, the shared activities, allocation of responsibilities for the joint notice, and the handling of PHI. While the Privacy Rule establishes the OHCA concept, clear internal documentation helps demonstrate the basis for shared uses and disclosures and clarifies each party's obligations. Confirm any specific documentation expectations against current guidance.
Does establishing an OHCA satisfy Security Rule obligations for the electronic PHI shared within the arrangement?
No. The OHCA concept arises under the Privacy Rule and addresses permitted uses and disclosures of PHI; it does not by itself satisfy Security Rule obligations. Each participating covered entity generally remains responsible for implementing the administrative, physical, and technical safeguards applicable to the electronic PHI it maintains or transmits. Participants should separately ensure their Security Rule compliance and coordinate on safeguards for any shared systems, verifying requirements against the current Security Rule.

Common misconceptions

An OHCA requires the participating covered entities to sign business associate agreements with each other to share PHI.
Covered entities that are participants in an OHCA are generally not one another's business associates for the joint activities of the arrangement, since they are acting as co-participants rather than one performing a service on behalf of the other. Business associate agreements attach to defined service relationships; separate BAAs may still be required for vendors and subcontractors that support the arrangement. Verify the specific relationships against current regulatory text.
Any two organizations that exchange patient data automatically form an OHCA.
An OHCA depends on defined conditions, typically including clinical integration and joint activities such as shared quality assessment, utilization review, or payment operations, together with the entities holding themselves out to the public as a joint arrangement. Mere data exchange between unrelated covered entities does not create an OHCA, and each entity retains its own compliance obligations.
Operating as an OHCA reduces or consolidates each entity's overall HIPAA compliance responsibilities.
The OHCA construct primarily facilitates joint privacy operations, such as a joint Notice of Privacy Practices and information sharing for the arrangement's operations. It does not merge the participants into a single covered entity, and each participant generally remains independently responsible for its own compliance under the Privacy, Security, Breach Notification, and Enforcement Rules, as enforced by HHS OCR.

Best practices

Document in writing whether an arrangement genuinely meets the OHCA conditions under the current Privacy Rule, including evidence of clinical integration and joint activities, rather than assuming OHCA status by default.
If issuing a joint Notice of Privacy Practices, confirm the current regulatory conditions for a joint notice and ensure each participating covered entity's role and information practices are accurately reflected.
Map which relationships within and around the arrangement are OHCA co-participant relationships versus business associate relationships, and put business associate agreements in place for vendors and subcontractors that perform services involving PHI.
Remember that OHCA participation does not diminish independent obligations under the Security Rule for ePHI or under the Breach Notification Rule, and maintain each entity's own administrative, physical, and technical safeguards accordingly.
Review any assumptions about permitted uses and disclosures for the arrangement's operations against the current text of the Privacy Rule, and treat OHCA status as a legal determination worth confirming with counsel.
Check whether state law or the HITECH Act imposes additional requirements beyond the federal HIPAA rules that may affect how the arrangement shares information or notifies individuals.