2.5 Covered Entity Structures: Hybrid Entities, ACEs, OHCAs and Health Information Exchanges
Key Takeaways
- A hybrid entity must designate its health care components under 45 CFR 164.105(a)(2)(iii)(D) and document the designation under 164.105(c); without that written record the Privacy Rule applies to the entire legal entity.
- An affiliated covered entity requires common ownership (a 5 percent or greater interest) or common control (power to significantly influence or direct); an organized health care arrangement requires neither and leaves each participant separately liable.
- OHCA participants may share PHI for the arrangement's joint health care operations and publish a joint Notice of Privacy Practices without executing business associate agreements with one another.
- A health information exchange that creates, receives, maintains, or transmits PHI on behalf of participants is a business associate and must sign a BAA, regardless of its nonprofit or state-designated status.
- Data governance policy — stewardship, classification, secondary-use approval, and de-identification authority — is the mechanism that keeps analytics and AI projects from becoming unauthorized disclosures.
Covered Entity Structures: Hybrid Entities, ACEs, OHCAs and Health Information Exchanges
Detailed Content Outline task 1.B asks the privacy officer to develop, review, or update governance policies (e.g., Board, data governance, HIEs, ACE/OHCA/Hybrid). It is one of the least intuitive tasks on the outline and one of the most consequential, because the structural designation an organization adopts decides a prior question: where does the Privacy Rule apply at all, and between which internal units does PHI move freely?
Get the structure wrong and every downstream control is aimed at the wrong perimeter. A health system that never documented its hybrid designation is regulated in its entirety — including the foundation, the parking authority, and the employee wellness program. A system that assumes an informal "clinical affiliation" lets two corporations swap PHI has been making impermissible disclosures for years.
1. Start With the Legal Entity, Not the Org Chart
The Privacy Rule attaches to a legal entity that meets the definition of a health plan, health care clearinghouse, or health care provider who transmits health information electronically in connection with a covered transaction (45 CFR § 160.103). Everything else — service lines, campuses, departments, cost centers — is internal architecture that HIPAA does not see unless you use one of three designations to make it visible.
| Designation | Regulatory Cite | Ownership Requirement | Effect on Legal Identity | Liability |
|---|---|---|---|---|
| Hybrid Entity | § 164.103, § 164.105(a) | Single legal entity performing both covered and non-covered functions | Shrinks the regulated perimeter to the designated health care components | The entity remains liable for its components; unregulated units must be firewalled |
| Affiliated Covered Entity (ACE) | § 164.105(b) | Common ownership (5% or more) or common control required | Legally separate covered entities are treated as one covered entity | Shared — a violation by one affiliate is a violation by the designated single covered entity |
| Organized Health Care Arrangement (OHCA) | § 164.501 definition | No ownership relationship required | Participants remain separate covered entities that share a clinical arrangement | Each participant remains independently liable for its own compliance |
2. Hybrid Entities: Drawing the Internal Firewall
A hybrid entity is a single legal entity whose business activities include both covered and non-covered functions. A public university that operates an academic medical center, a school of public health, an athletics department, and a research enterprise is the canonical example. So is a municipality that runs an ambulance service, a police department, and a water utility.
The mechanics matter more than the concept:
- Designation must be in writing. Section 164.103 defines a hybrid entity as one that designates health care components in accordance with § 164.105(a)(2)(iii)(D), and § 164.105(c) requires a written or electronic record of that designation, retained for six years from creation or from the date it was last in effect, whichever is later. There is no such thing as an implied hybrid designation. If nothing is written down, the entity is not a hybrid entity and the entire corporation is a covered entity.
- Components include support units that would be business associates. A health care component must include any unit that performs functions which, if performed by an outsider, would make that outsider a business associate — the internal IT department that hosts the EHR, the internal legal office that handles malpractice defense, the internal billing office.
- PHI may not flow to non-designated units except as the Privacy Rule would permit disclosure to an outside third party. The university development office cannot pull grateful-patient lists from the medical center chart system merely because it shares a tax ID; that is a disclosure requiring either the § 164.514(f) fundraising pathway or an authorization.
- Workforce members who straddle components must be trained and access-controlled at the component boundary.
[!CAUTION] The Silent Hybrid Failure. The most common finding is an organization that believes it is a hybrid entity because a consultant said so in 2011, but cannot produce the written designation, the component list, or evidence that the list has been reviewed since. When OCR asks for the designation document during an investigation and none exists, the enforcement scope expands instantly from one clinic to the entire corporate entity.
3. Affiliated Covered Entities: One Identity, Shared Exposure
Section 164.105(b)(2)(i)(A) permits legally separate covered entities to designate themselves a single affiliated covered entity if all of the covered entities designated are under common ownership or control. Both terms are defined at § 164.103: common ownership exists where an entity or entities hold an ownership or equity interest of 5 percent or more in another entity, and common control exists where an entity has the power, directly or indirectly, significantly to influence or direct the actions or policies of another entity. Neither test requires majority board control, which is a common misstatement.
What an ACE designation buys:
- One covered entity for compliance purposes — a single Notice of Privacy Practices, one set of policies, one privacy official if the organization wants it.
- PHI moves within the ACE without disclosure analysis, because there is only one covered entity; internal use replaces external disclosure.
- Enormous administrative simplification for a 30-hospital system with 30 tax IDs.
What it costs:
- The designation must be documented under § 164.105(b)(2)(i)(B) and retained per § 164.105(c) for six years from creation or from the date it was last in effect, whichever is later.
- Shared consequence. Because the affiliates are one covered entity, a sanctionable failure at the smallest affiliate is a failure of the whole ACE. Systems that designate an ACE and then let one legacy hospital run on an unpatched, unaudited legacy record system have pooled that risk across the enterprise.
- ACE status does not merge the entities for any other legal purpose — antitrust, corporate practice of medicine, Stark, and licensure analyses are untouched.
4. Organized Health Care Arrangements: Clinical Integration Without Merger
An OHCA is defined at § 164.501. The two forms a privacy officer meets most often are:
- A clinically integrated care setting in which individuals typically receive care from more than one provider — the classic hospital plus its independent medical staff. The community cardiologist with privileges is not the hospital's workforce member and is not its business associate, yet both hold PHI for the same patient encounter.
- A group health plan and the health insurance issuer or HMO with respect to that plan, and arrangements among multiple plans maintained by the same or affiliated sponsors.
The privileges an OHCA confers are narrow and precise:
- Participants may share PHI for the joint health care operations of the arrangement — joint quality assessment, joint utilization review, joint credentialing, shared clinical protocols.
- Participants may issue a joint Notice of Privacy Practices covering the arrangement, provided the notice identifies the participants and the service delivery sites to which it applies.
- Participants do not need business associate agreements with one another for those joint activities, because neither is acting on the other's behalf.
The privileges an OHCA does not confer:
- It does not make the participants one covered entity. Each answers to OCR separately.
- It does not authorize sharing for a participant's own independent operations unrelated to the arrangement — a medical group cannot mine hospital data to market its own ambulatory surgery center under OHCA authority.
- It does not eliminate the need for a BAA where one participant genuinely performs a service for another, such as the hospital running the medical group's billing.
5. Health Information Exchanges and Participation Governance
A health information exchange (HIE) — sometimes a state-designated entity, sometimes a regional nonprofit, sometimes a vendor network — moves PHI among unaffiliated participants. Its status is straightforward and frequently mis-stated in practice:
An HIE that creates, receives, maintains, or transmits PHI on behalf of participating covered entities is a business associate and must execute a BAA. Nonprofit status, state designation, or a governance seat for participants does not change that analysis.
The governance policy set that a privacy officer must maintain for HIE participation:
| Policy Element | What It Must Settle |
|---|---|
| Participation agreement | Permitted purposes, downstream redisclosure limits, audit rights, breach notification timing, termination and data return |
| Patient consent model | Whether the state or the HIE uses opt-in or opt-out, who captures the choice, how it is honored across participants, and how it is revoked |
| Sensitive data segmentation | How 42 CFR Part 2, behavioral health, HIV, and minor-consent records are flagged, withheld, or consent-gated before they enter the exchange |
| Break-the-glass | Who may override access restrictions in an emergency, what justification is captured, and how every override is reviewed afterward |
| Query audit | Retrieval of participant query logs, because an HIE query by your workforce member is an access event your monitoring program owns |
Data Governance as the Connective Tissue
Underneath all four structures sits the organization's data governance policy — the piece of task 1.B that has no CFR citation and is therefore easiest to skip. At minimum it must assign:
- Data stewardship by domain (clinical, financial, research, HR), naming an accountable owner for each.
- Data classification tiers that drive handling rules, so "restricted" data cannot be exported to a spreadsheet on a shared drive.
- Secondary-use approval, a standing committee decision path for analytics, quality registries, machine learning, and vendor pilots, with the privacy officer holding a documented veto.
- De-identification authority — who may authorize a Safe Harbor scrub or commission an expert determination, and where those determinations are filed.
[!TIP] Board-level governance policy. Task 1.B also names the Board. The deliverable is a short, board-approved privacy charter that states the board's oversight duty, names the committee that receives privacy reporting, sets the reporting cadence, and defines the threshold at which an incident is escalated to the board between meetings. Two pages of board-adopted charter do more for a program's authority than fifty pages of departmental procedure.
A public university operates an academic medical center, a school of nursing, an intercollegiate athletics program, and a fundraising foundation under one legal entity. General counsel says the university 'has always been a hybrid entity,' but no one can locate any written designation of health care components. What is the correct compliance conclusion?
A community hospital and the 200 independent physicians who hold privileges there participate in a joint quality improvement and credentialing program. The physicians are not hospital employees and no entity owns another. Which arrangement fits, and what does it permit?
A regional nonprofit health information exchange, designated by the state and governed by a board on which participating hospitals hold seats, aggregates and routes patient records among 40 unaffiliated providers. How should the privacy officer classify it?