hipaa.systems
Guide

Who must comply with HIPAA?

Who HIPAA applies to — covered entities and business associates — with examples, common edge cases like health apps and private-pay practices, and who is outside HIPAA.

Who must comply with HIPAA? at a glance

HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers that conduct standard transactions such as insurance claims electronically — and to their business associates, meaning vendors and contractors that create, receive, maintain or transmit protected health information on a covered entity's behalf, including subcontractors. Organizations outside these groups, such as most consumer health apps, are generally not subject to HIPAA.

Covered entitiesHealth plans, clearinghouses, providers doing electronic standard transactions
Business associatesVendors and contractors handling PHI for a covered entity, plus their subcontractors
Usually not coveredConsumer apps used directly by individuals, employers as employers, life insurers, schools under FERPA
Defined in45 CFR 160.103
Quick checkDoes HIPAA apply to me? tool on this site

HIPAA applies to two groups. Start with the Does HIPAA apply to me? tool for a quick answer, or read on.

1. Covered entities

Details: Covered entity.

2. Business associates

Generally, a person or organization outside the covered entity’s workforce that creates, receives, maintains or transmits PHI on its behalf, or provides professional services involving PHI — and their subcontractors. Cloud, email and EHR vendors, billing companies, IT providers and SaaS products used with patient data are typical examples.

Details: Business associate.

Who is usually not covered

Organization Why not, usually
Consumer health and fitness apps Not acting on behalf of a covered entity
Employers, for employee records Employment records are excluded from PHI
Life and disability insurers Not health plans under HIPAA
Schools, for student health records Covered by FERPA instead
Providers who never conduct a HIPAA standard transaction electronically, directly or through another party Not covered entities — but confirm, and state law still applies

Being outside HIPAA does not mean anything goes: state privacy laws and the FTC’s rules on health data can still apply.

Next steps

Frequently asked questions

Does HIPAA apply to me as an individual?

HIPAA obligations fall on covered entities and business associates, not on individuals sharing their own health information. Employees of those organizations must follow their employer's HIPAA policies.

Does HIPAA apply to health apps?

Only if the app creates, receives, maintains or transmits PHI on behalf of a covered entity — for example, an app a clinic provides to its patients. A consumer app people download on their own is usually outside HIPAA.

Does HIPAA apply to companies outside the United States?

If a company acts as a business associate of a U.S. covered entity, it takes on HIPAA obligations through its BAA, wherever it is based.