Who does HIPAA apply to?

short answer

HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers that transmit health information electronically — and to business associates who handle protected health information on their behalf. It does not apply to most consumer health apps, wearables, life insurers, or employers acting as employers. Those organizations are frequently still regulated, but by state privacy laws, the FTC Act, or the FTC's Health Breach Notification Rule rather than by HIPAA.

Covered entities

Three categories, and only three:

  1. Health plans — insurers, HMOs, employer group health plans, government programs such as Medicare and Medicaid
  2. Health care clearinghouses — organizations that convert health data between formats
  3. Health care providers who transmit health information electronically in connection with a covered transaction

That last qualifier matters. A provider who never bills electronically may fall outside HIPAA entirely, which surprises people.

Business associates

A business associate handles PHI on a covered entity’s behalf — billing services, cloud hosting, analytics, transcription, and so on. The relationship must be governed by a business associate agreement, and the business associate has direct HIPAA obligations of its own.

A BAA is a contract, not a certification. A vendor offering to sign one is telling you it will accept the obligations, not that it has been audited.

Who is commonly assumed to be covered and is not

This is why “HIPAA compliant” appears on so many products that HIPAA does not reach. In many cases the claim is meaningless because the obligation never applied.

Being outside HIPAA is not being unregulated

Organizations that fall outside HIPAA still commonly face:

The practical position: if you handle anything health-adjacent, decide your standard on the sensitivity of the data rather than on whether a specific statute technically reaches you. The boundary is a poor place to build a strategy, because you will be arguing about it precisely when you can least afford to.

If you are a covered entity or business associate

The obligations that generate most enforcement:


General information, not legal advice. HIPAA is fact-specific; consult counsel for your situation.

people also ask this as

keep reading

Last updated August 2026. This is general information, not legal advice — privacy law changes often and turns on specifics. For your own situation, talk to counsel.