Does HIPAA apply to me?
Answer a few questions to see whether you are a covered entity, a business associate, or outside HIPAA. Based on the definitions in 45 CFR 160.103.
Question 1 of up to 6
Is your organization a health plan?
For example a health insurer, HMO, Medicare or Medicaid program, or an employer group health plan.
Question 2 of up to 6
Do you convert health information between nonstandard and standard formats for other organizations?
This is what a health care clearinghouse does — for example, reformatting claims for providers.
Question 3 of up to 6
Do you provide health care?
For example diagnosing, treating, counseling or prescribing — as a practice, clinic, therapist, dentist or other provider.
Question 4 of up to 6
Do you — or a billing service for you — send health information electronically for standard transactions?
Standard transactions include insurance claims, eligibility checks, claim status and remittance.
Question 5 of up to 6
Do you create, receive, maintain or transmit protected health information (PHI) on behalf of a provider, health plan or clearinghouse?
For example as a SaaS or cloud vendor, IT provider, billing company, consultant, or a subcontractor of one of these.
Question 6 of up to 6
Do you offer a health app or service directly to consumers?
People sign up themselves, not through their doctor or health plan.
Result
Applies HIPAA applies — you are a covered entity (health plan)
Health plans are covered entities under 45 CFR 160.103 and must meet the Privacy, Security and Breach Notification Rules.
Result
Applies HIPAA applies — you are a covered entity (clearinghouse)
Health care clearinghouses are covered entities under 45 CFR 160.103.
Result
Applies HIPAA applies — you are a covered entity (health care provider)
A provider that conducts standard transactions electronically, directly or through a billing service, is a covered entity. You need the Privacy, Security and Breach Notification Rules, and a BAA with every vendor that handles your patients’ information.
Result
Depends You may not be a HIPAA covered entity
A provider that never conducts standard electronic transactions — directly or through anyone acting for it — may fall outside HIPAA’s definition of a covered entity. Confirm with counsel: one electronic claim changes the answer, and state privacy laws and professional ethics rules apply regardless.
Result
Depends Probably yes — most providers who take insurance are covered
If you accept insurance, your practice or billing service almost certainly sends claims electronically, which makes you a covered entity. Ask your billing service or EHR vendor to confirm.
Result
Applies HIPAA applies — you are likely a business associate
Organizations that handle PHI on behalf of a covered entity — and their subcontractors — are business associates. You must sign BAAs, meet the Security Rule, and report breaches to your customers, and you are directly liable to HHS for specified requirements. Exception: a mere conduit that only transmits data, with no storage beyond what transmission needs, is not a business associate.
Result
Likely not HIPAA probably does not apply — but other laws may
A consumer health app that is not acting on behalf of a covered entity is usually outside HIPAA. The FTC Health Breach Notification Rule and state health-privacy laws may still apply. If a provider or plan offers your app to its patients, the answer can change.
Result
Likely not HIPAA probably does not apply to you
Based on your answers you are neither a covered entity nor a business associate. If you start working with providers or plans and handling their patients’ information, run this check again.
Does HIPAA apply? At a glance
HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers that conduct standard transactions such as insurance claims electronically — and to business associates that create, receive, maintain or transmit protected health information on a covered entity's behalf, including their subcontractors. Consumer health apps not acting for a covered entity are usually outside HIPAA, though other laws may apply.
| Covered entities | Health plans, clearinghouses, providers doing electronic standard transactions |
|---|---|
| Business associates | Vendors handling PHI for a covered entity, and their subcontractors |
| Usually outside HIPAA | Consumer apps, employers as employers, fully private-pay providers (confirm) |
| Defined in | 45 CFR 160.103 |
Frequently asked questions
Does HIPAA apply to me?
HIPAA applies if you are a covered entity — a health plan, a clearinghouse, or a provider that conducts standard transactions electronically — or a business associate that handles protected health information on behalf of one.
Does HIPAA apply to a cash-only practice?
Possibly not. A provider that never conducts standard electronic transactions, directly or through a billing service, may not be a covered entity. State laws still apply, so confirm with counsel.
Is this tool legal advice?
No. It gives a preliminary answer based on the definitions in 45 CFR 160.103. Edge cases need a lawyer.