Who does HIPAA apply to?
short answer
HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers that transmit health information electronically — and to business associates who handle protected health information on their behalf. It does not apply to most consumer health apps, wearables, life insurers, or employers acting as employers. Those organizations are frequently still regulated, but by state privacy laws, the FTC Act, or the FTC's Health Breach Notification Rule rather than by HIPAA.
Covered entities
Three categories, and only three:
- Health plans — insurers, HMOs, employer group health plans, government programs such as Medicare and Medicaid
- Health care clearinghouses — organizations that convert health data between formats
- Health care providers who transmit health information electronically in connection with a covered transaction
That last qualifier matters. A provider who never bills electronically may fall outside HIPAA entirely, which surprises people.
Business associates
A business associate handles PHI on a covered entity’s behalf — billing services, cloud hosting, analytics, transcription, and so on. The relationship must be governed by a business associate agreement, and the business associate has direct HIPAA obligations of its own.
A BAA is a contract, not a certification. A vendor offering to sign one is telling you it will accept the obligations, not that it has been audited.
Who is commonly assumed to be covered and is not
- Consumer health and fitness apps — usually not covered entities
- Wearables and their platforms — usually not
- Life and disability insurers — generally not covered entities
- Employers, when acting as employers rather than as a group health plan
- Most marketers of health-adjacent products
This is why “HIPAA compliant” appears on so many products that HIPAA does not reach. In many cases the claim is meaningless because the obligation never applied.
Being outside HIPAA is not being unregulated
Organizations that fall outside HIPAA still commonly face:
- The FTC Health Breach Notification Rule, which reaches many health apps and has been enforced against them
- Section 5 of the FTC Act, for unfair or deceptive practices — the FTC’s main privacy enforcement tool
- State privacy laws, most of which treat health data as sensitive and require heightened treatment or opt-in consent
- State health-specific laws, notably Washington’s My Health My Data Act, which is broad and carries a private right of action
The practical position: if you handle anything health-adjacent, decide your standard on the sensitivity of the data rather than on whether a specific statute technically reaches you. The boundary is a poor place to build a strategy, because you will be arguing about it precisely when you can least afford to.
If you are a covered entity or business associate
The obligations that generate most enforcement:
- Minimum necessary — use and disclose the least PHI needed for the purpose
- Access controls and audit logging — who saw what, and when
- Breach notification — individuals, HHS, and in larger breaches the media, within defined timeframes
- Patient right of access — a frequent enforcement subject, and closely related to DSAR handling
- BAAs in place with every vendor touching PHI
General information, not legal advice. HIPAA is fact-specific; consult counsel for your situation.
people also ask this as
- Does HIPAA apply to my app?
- What is a covered entity?
- What is a business associate agreement?
- Is my employer covered by HIPAA?
keep reading
Last updated August 2026. This is general information, not legal advice — privacy law changes often and turns on specifics. For your own situation, talk to counsel.