Short answer: An independent physician running their own practice is a covered entity under HIPAA, with full responsibility for the Security Rule's requirements. A nurse practitioner's status depends on their practice arrangement: an NP with an independent practice (where state law allows independent practice authority) is a covered entity in their own right, while an NP employed within someone else's practice is generally covered as part of that practice's compliance program, not as a separate entity themselves.
Independent physicians: straightforward coverage
A solo physician who owns and operates their own practice — billing insurance electronically, maintaining electronic records, using any digital scheduling or communication tools — is a covered entity, full stop. There's no reduced standard for a one-person practice. The physician is personally responsible for ensuring a risk assessment exists, policies are documented, any staff receive training, vendor agreements are in place, and the practice can produce evidence of all of this on request. Being independent means there's no larger organization's compliance department to lean on — the physician is that department.
Nurse practitioners: it depends on your practice arrangement
This is the genuinely nuanced part. Nurse practitioner scope of practice varies significantly by state — some states grant full independent practice authority, allowing an NP to run their own practice without physician oversight, while others require some form of collaborative agreement with a physician.
If you're an NP running your own independent practice (in a state that permits it), you're a covered entity in the same way an independent physician is — full responsibility for the compliance program falls on you.
If you're an NP working within a physician's practice, a clinic, or a larger healthcare organization, you're generally operating under that organization's status as the covered entity. Your individual actions still need to comply with that organization's HIPAA policies, but the compliance program itself — risk assessment, BAAs, overall documentation — is the organization's responsibility, not something you maintain separately and individually.
Why this distinction actually matters
It's easy for an NP moving between employment and independent practice to carry outdated assumptions from one context into the other. An NP who spent years in an employed role, where compliance was someone else's responsibility, and then opens an independent practice needs to recognize that the full weight of covered entity status now falls on them personally — there's no larger organization's compliance program to rely on anymore.
What independent status actually requires
For any independent provider — physician or nurse practitioner — the requirements are the same as any other covered entity: a current written risk assessment, documented policies matching your actual operations, training records for any staff, signed BAAs with vendors, and evidence you can produce on request.
Getting a clear answer for your situation
If you're an independent physician or nurse practitioner unsure exactly where your practice arrangement puts you, Truvidence's free risk assessment is built for exactly this kind of independent, solo, or small practice situation — not a large organization with its own compliance infrastructure.