Do Managed Care Organizations (MCOs) have to comply with HIPAA, too?
(3/2002) If the MCO meets the requirements for a covered entity, yes, the MCO must comply. According to the definition found in the Federal Register, Volume 65, No. 160, page 50318, the state Medicaid plan contracts with an MCO to provide services to Medicaid members. The MCO in turn contracts with health care providers to render these services. The MCO is then considered a health plan. All providers, health plans, and clearinghouses that transmit or store electronic data must comply.