hipaa.systems
Tool · 6 questions

Does HIPAA apply to me?

Answer a few questions to see whether you are a covered entity, a business associate, or outside HIPAA. Based on the definitions in 45 CFR 160.103.

Question 1 of up to 6

Is your organization a health plan?

For example a health insurer, HMO, Medicare or Medicaid program, or an employer group health plan.

Question 2 of up to 6

Do you convert health information between nonstandard and standard formats for other organizations?

This is what a health care clearinghouse does — for example, reformatting claims for providers.

Start over

Question 3 of up to 6

Do you provide health care?

For example diagnosing, treating, counseling or prescribing — as a practice, clinic, therapist, dentist or other provider.

Start over

Question 4 of up to 6

Do you — or a billing service for you — send health information electronically for standard transactions?

Standard transactions include insurance claims, eligibility checks, claim status and remittance.

Start over

Question 5 of up to 6

Do you create, receive, maintain or transmit protected health information (PHI) on behalf of a provider, health plan or clearinghouse?

For example as a SaaS or cloud vendor, IT provider, billing company, consultant, or a subcontractor of one of these.

Start over

Question 6 of up to 6

Do you offer a health app or service directly to consumers?

People sign up themselves, not through their doctor or health plan.

Start over

Result

Applies HIPAA applies — you are a covered entity (health plan)

Health plans are covered entities under 45 CFR 160.103 and must meet the Privacy, Security and Breach Notification Rules.

Start over

Result

Applies HIPAA applies — you are a covered entity (clearinghouse)

Health care clearinghouses are covered entities under 45 CFR 160.103.

Start over

Result

Applies HIPAA applies — you are a covered entity (health care provider)

A provider that conducts standard transactions electronically, directly or through a billing service, is a covered entity. You need the Privacy, Security and Breach Notification Rules, and a BAA with every vendor that handles your patients’ information.

Start over

Result

Depends You may not be a HIPAA covered entity

A provider that never conducts standard electronic transactions — directly or through anyone acting for it — may fall outside HIPAA’s definition of a covered entity. Confirm with counsel: one electronic claim changes the answer, and state privacy laws and professional ethics rules apply regardless.

Start over

Result

Depends Probably yes — most providers who take insurance are covered

If you accept insurance, your practice or billing service almost certainly sends claims electronically, which makes you a covered entity. Ask your billing service or EHR vendor to confirm.

Start over

Result

Applies HIPAA applies — you are likely a business associate

Organizations that handle PHI on behalf of a covered entity — and their subcontractors — are business associates. You must sign BAAs, meet the Security Rule, and report breaches to your customers, and you are directly liable to HHS for specified requirements. Exception: a mere conduit that only transmits data, with no storage beyond what transmission needs, is not a business associate.

Start over

Result

Likely not HIPAA probably does not apply — but other laws may

A consumer health app that is not acting on behalf of a covered entity is usually outside HIPAA. The FTC Health Breach Notification Rule and state health-privacy laws may still apply. If a provider or plan offers your app to its patients, the answer can change.

Start over

Result

Likely not HIPAA probably does not apply to you

Based on your answers you are neither a covered entity nor a business associate. If you start working with providers or plans and handling their patients’ information, run this check again.

Start over

Does HIPAA apply? At a glance

HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers that conduct standard transactions such as insurance claims electronically — and to business associates that create, receive, maintain or transmit protected health information on a covered entity's behalf, including their subcontractors. Consumer health apps not acting for a covered entity are usually outside HIPAA, though other laws may apply.

Covered entitiesHealth plans, clearinghouses, providers doing electronic standard transactions
Business associatesVendors handling PHI for a covered entity, and their subcontractors
Usually outside HIPAAConsumer apps, employers as employers, fully private-pay providers (confirm)
Defined in45 CFR 160.103

Frequently asked questions

Does HIPAA apply to me?

HIPAA applies if you are a covered entity — a health plan, a clearinghouse, or a provider that conducts standard transactions electronically — or a business associate that handles protected health information on behalf of one.

Does HIPAA apply to a cash-only practice?

Possibly not. A provider that never conducts standard electronic transactions, directly or through a billing service, may not be a covered entity. State laws still apply, so confirm with counsel.

Is this tool legal advice?

No. It gives a preliminary answer based on the definitions in 45 CFR 160.103. Edge cases need a lawyer.