Select the type of entity being audited. This determines which requirements apply.
Covered Entity
Health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically (45 CFR 160.103)
Business Associate
Entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity (45 CFR 160.103)
Non-HIPAA Entity
Health app, wearable, or wellness company not subject to HIPAA but subject to FTC Health Breach Notification Rule and state laws