Who must comply with HIPAA?
Who HIPAA applies to — covered entities and business associates — with examples, common edge cases like health apps and private-pay practices, and who is outside HIPAA.
Who must comply with HIPAA? at a glance
HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers that conduct standard transactions such as insurance claims electronically — and to their business associates, meaning vendors and contractors that create, receive, maintain or transmit protected health information on a covered entity's behalf, including subcontractors. Organizations outside these groups, such as most consumer health apps, are generally not subject to HIPAA.
| Covered entities | Health plans, clearinghouses, providers doing electronic standard transactions |
|---|---|
| Business associates | Vendors and contractors handling PHI for a covered entity, plus their subcontractors |
| Usually not covered | Consumer apps used directly by individuals, employers as employers, life insurers, schools under FERPA |
| Defined in | 45 CFR 160.103 |
| Quick check | Does HIPAA apply to me? tool on this site |
HIPAA applies to two groups. Start with the Does HIPAA apply to me? tool for a quick answer, or read on.
1. Covered entities
- Health plans — insurers, HMOs, government programs, employer group health plans.
- Health care clearinghouses — organizations that convert health information between nonstandard and standard formats.
- Health care providers that transmit health information electronically in a standard transaction — claims, eligibility checks, remittance — themselves or through a billing service.
Details: Covered entity.
2. Business associates
Generally, a person or organization outside the covered entity’s workforce that creates, receives, maintains or transmits PHI on its behalf, or provides professional services involving PHI — and their subcontractors. Cloud, email and EHR vendors, billing companies, IT providers and SaaS products used with patient data are typical examples.
Details: Business associate.
Who is usually not covered
| Organization | Why not, usually |
|---|---|
| Consumer health and fitness apps | Not acting on behalf of a covered entity |
| Employers, for employee records | Employment records are excluded from PHI |
| Life and disability insurers | Not health plans under HIPAA |
| Schools, for student health records | Covered by FERPA instead |
| Providers who never conduct a HIPAA standard transaction electronically, directly or through another party | Not covered entities — but confirm, and state law still applies |
Being outside HIPAA does not mean anything goes: state privacy laws and the FTC’s rules on health data can still apply.
Next steps
- HIPAA for therapists in private practice →Scenario
- Covered entity →Requirement
- Business associate →Requirement
- PHI and ePHI →Requirement
Frequently asked questions
Does HIPAA apply to me as an individual?
HIPAA obligations fall on covered entities and business associates, not on individuals sharing their own health information. Employees of those organizations must follow their employer's HIPAA policies.
Does HIPAA apply to health apps?
Only if the app creates, receives, maintains or transmits PHI on behalf of a covered entity — for example, an app a clinic provides to its patients. A consumer app people download on their own is usually outside HIPAA.
Does HIPAA apply to companies outside the United States?
If a company acts as a business associate of a U.S. covered entity, it takes on HIPAA obligations through its BAA, wherever it is based.