What Is a Healthcare Clearinghouse Under HIPAA?

A healthcare clearinghouse under HIPAA is a public or private entity that converts health information between nonstandard and standard electronic formats, sitting between providers and health plans as a translator. HIPAA treats clearinghouses as one of only three types of “covered entities,” which puts them under direct federal rules for handling protected health information (PHI).1HHS.gov. Covered Entities and Business Associates That status is not cosmetic. It means strict privacy, security, and breach-notification duties, with penalties that can reach into the millions for serious violations.

The Regulatory Definition

The definition lives in 45 CFR 160.103. A healthcare clearinghouse is any public or private entity that performs one of two functions: it takes health information in a nonstandard format and converts it into a standard transaction, or it receives a standard transaction and converts it into a nonstandard format for the receiving party.2eCFR. 45 CFR 160.103 – Definitions The regulation names billing services, repricing companies, community health information systems, and value-added networks as examples.

The label matters because it drops an entity into covered-entity status automatically. Only two other categories share that status: health plans and healthcare providers who transmit health information electronically.2eCFR. 45 CFR 160.103 – Definitions A provider becomes a covered entity only when it starts sending electronic transactions. A clearinghouse is covered the moment it does what clearinghouses do.

What a Clearinghouse Actually Does

The core job is translation. A provider generates a claim, an eligibility check, or another transaction in its own software. That data may not be in a format the receiving health plan can read. The clearinghouse ingests the data, scrubs it for errors, reformats it into the HIPAA-compliant standard, and sends it to the payer. The process runs in reverse too, taking a plan’s standardized response and converting it back into whatever format the provider’s system uses.

Federal regulations at 45 CFR Part 162 spell out which transaction types must follow adopted standards.3eCFR. 45 CFR Part 162 – Administrative Requirements Common ones a clearinghouse handles include claims submissions, eligibility inquiries and responses, claim status checks, remittance advice and electronic funds transfers, referral certifications and prior authorizations, and enrollment or disenrollment transactions.

Error-checking is where clearinghouses earn their fees. Before forwarding a transaction, the clearinghouse validates data elements against the required format, flags missing fields, and rejects submissions that would fail at the payer’s end. Catching those problems upstream saves providers the weeks-long cycle of denial and resubmission.

Covered Entity and Business Associate at the Same Time

Clearinghouses sit in an unusual spot. They are covered entities in their own right, but in practice they receive PHI mainly when performing translation services on behalf of a provider or health plan. HHS has acknowledged this: in most cases a clearinghouse handles PHI as a business associate of the entity that hired it, and only certain Privacy Rule provisions apply to those uses and disclosures.4HHS.gov. Summary of the HIPAA Privacy Rule

The dual nature confuses people. Under the statute a clearinghouse is always a covered entity, but the scope of its Privacy Rule obligations narrows when it acts as a business associate. The full Privacy Rule applies only when the clearinghouse creates or receives PHI in a capacity other than as a business associate of another covered entity.

HIPAA Compliance Requirements

Three HIPAA rules govern day-to-day clearinghouse operations, all in 45 CFR Part 164.5eCFR. 45 CFR Part 164 – Security and Privacy

The Privacy Rule

The Privacy Rule governs how a clearinghouse uses and discloses individually identifiable health information. A clearinghouse needs written policies that limit who inside the organization can access PHI, what they can do with it, and when it can leave the organization. As noted above, how much of the Privacy Rule applies depends on whether the clearinghouse is handling the information in its own right or as a business associate.

The Security Rule

The Security Rule applies to electronic PHI and requires three categories of safeguards. Administrative safeguards cover risk assessments, workforce training, and access-management policies. Physical safeguards address facility access and workstation security. Technical safeguards deal with access controls, audit logs, data integrity checks, and transmission security. Encryption is not strictly mandatory. It is an “addressable” specification, meaning a clearinghouse that chooses not to encrypt must document why an equivalent alternative provides adequate protection. Most clearinghouses encrypt data both at rest and in transit.

The Breach Notification Rule

When a clearinghouse discovers that unsecured PHI has been accessed, acquired, or disclosed without authorization, it must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery.6HHS.gov. Breach Notification Rule The notice must describe what happened, what information was involved, and what steps the individual should take to protect themselves.7eCFR. 45 CFR 164.404 – Notification to Individuals If a breach affects more than 500 residents of a single state or jurisdiction, the clearinghouse must also notify prominent media outlets serving that area.8eCFR. 45 CFR 164.406 – Notification to the Media All breaches must be reported to HHS, with those affecting 500 or more individuals reported at the same time as the individual notices.

Business Associate Agreements

Even though a clearinghouse is itself a covered entity, it still needs business associate agreements (BAAs) with outside vendors that handle PHI on its behalf. The regulation at 45 CFR 164.504 lists what these agreements must include: the permitted uses of PHI, a promise not to disclose beyond what the contract allows, a requirement to use appropriate safeguards, and an obligation to report unauthorized disclosures back to the clearinghouse.9eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements

Subcontractors add another layer. If a business associate delegates any PHI-related function to a subcontractor, that subcontractor must agree to the same restrictions and conditions. A subcontractor who meets the HIPAA definition is treated as a business associate whether or not a BAA was actually signed, so skipping the paperwork does not eliminate liability; it just adds a compliance violation on top of any breach.

On the other side of the relationship, a provider or health plan hiring a clearinghouse typically needs a BAA with the clearinghouse itself, since the clearinghouse will be receiving PHI to perform its translation work. If the hiring entity learns the clearinghouse is violating the agreement, it must take reasonable steps to fix the problem or end the arrangement.

Penalties for Non-Compliance

HIPAA violations carry both civil and criminal consequences, and clearinghouses are not exempt from either.

Civil Monetary Penalties

HHS enforces civil penalties through a four-tier structure based on the violator’s culpability. Base amounts were set in a 2019 enforcement discretion notice and are adjusted annually for inflation.10Federal Register. Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties As of early 2026, the inflation-adjusted ranges are:

  • Tier 1, no knowledge of the violation: $145 to $36,506 per violation, capped at $36,506 per year.
  • Tier 2, reasonable cause but not willful neglect: $1,461 to $73,011 per violation, capped at $146,053 per year.
  • Tier 3, willful neglect corrected within 30 days: $14,602 to $73,011 per violation, capped at $365,052 per year.
  • Tier 4, willful neglect not corrected within 30 days: $73,011 to $2,190,294 per violation, capped at $2,190,294 per year.

A single breach can involve thousands of individual records, and each record can count as a separate violation. Even at Tier 1 rates, the practical exposure from a major incident can be enormous.

Criminal Penalties

Individuals who knowingly obtain or disclose PHI in violation of HIPAA face prosecution under 42 U.S.C. 1320d-6. The penalties escalate with intent:

Criminal charges are relatively rare compared to civil enforcement, but they do happen, particularly when employees access records out of curiosity or for personal reasons. The Department of Justice handles those prosecutions, not HHS.