A therapist in private practice once told me she didn't think HIPAA applied to her because she wasn't a hospital. A dental billing company assumed the same thing — until OCR came knocking with a six-figure penalty. The question "HIPAA Privacy Rule applies to which of the following?" shows up on certification exams, compliance quizzes, and Google searches thousands of times a month. But it's not just a test question. Getting it wrong in the real world costs money, reputation, and patient trust.
If you're searching this phrase, you likely need a clear, specific answer — either for an exam or because your organization is trying to figure out its obligations. I'm going to give you both: the textbook answer and the practical reality I've seen play out across hundreds of compliance engagements.
The HIPAA Privacy Rule Applies to Which of the Following Entities?
The HIPAA Privacy Rule applies to three categories of organizations. Not individuals acting alone. Not every business that touches health data. Three specific types:
- Health Plans — Health insurance companies, HMOs, employer-sponsored group health plans, Medicare, Medicaid, and military/veterans' health programs.
- Health Care Clearinghouses — Entities that process nonstandard health information into standard formats (or vice versa). Think billing services that convert claims data.
- Health Care Providers — Any provider who transmits health information electronically in connection with a HIPAA-covered transaction. This includes hospitals, physicians, dentists, psychologists, chiropractors, nursing homes, and pharmacies.
These three groups are collectively called covered entities. If your organization falls into one of these categories, the HIPAA Privacy Rule is not optional. It is federal law, enforced by the Office for Civil Rights (OCR) at HHS.
There's also a critical fourth player: business associates. These are companies or individuals who perform services for a covered entity and access protected health information (PHI) in the process. Cloud storage vendors, billing companies, IT contractors, shredding services — all potentially business associates. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable under HIPAA as well.
You can find the full regulatory text defining covered entities and business associates at HHS.gov's covered entities page.
The Trick Question That Trips Everyone Up
Here's the nuance most people miss: not every health care provider is a covered entity. A provider becomes a covered entity only when they transmit health information electronically in connection with a transaction that HHS has adopted a standard for — like claims, eligibility inquiries, or referral authorizations.
A personal trainer who gives nutrition advice? Not covered. A rural physician who exclusively uses paper records and never bills electronically? Technically, possibly not covered — though in 2026, finding a provider who never touches electronic transactions is nearly impossible.
The moment a provider submits an electronic claim to a health plan, they cross the line into covered entity status. And once you're in, you're all in. You can't apply the Privacy Rule to just your electronic records and ignore your paper charts. It covers all PHI in every format — electronic, paper, and oral.
What the Privacy Rule Actually Protects
The Privacy Rule governs how covered entities and business associates use and disclose protected health information (PHI). PHI is any individually identifiable health information that relates to a person's past, present, or future health condition, treatment, or payment for care.
The 18 Identifiers You Need to Know
PHI includes 18 specific identifiers that can link health data to an individual. Names, dates of birth, Social Security numbers, medical record numbers, email addresses, biometric identifiers — the full list is defined in the HHS de-identification guidance. Strip all 18, and the data is no longer considered PHI under the Privacy Rule.
ePHI Gets Its Own Rule
When PHI exists in electronic form — stored on servers, transmitted via email, sitting in an EHR — it becomes ePHI, and the HIPAA Security Rule kicks in with additional technical, administrative, and physical safeguard requirements. The Privacy Rule and Security Rule work in tandem, but they're not interchangeable.
Who Does the HIPAA Privacy Rule NOT Apply To?
This is just as important as knowing who it covers. The Privacy Rule does not apply to:
- Employers acting in their capacity as employers (even though they may sponsor a group health plan, the employer function itself isn't covered)
- Life insurers
- Workers' compensation carriers
- Most schools and school districts (they're typically governed by FERPA instead)
- Law enforcement agencies
- Municipal offices
I've seen small employers assume they're covered entities because they offer health benefits. They're not — though their group health plan might be. The distinction matters enormously when you're deciding where to invest compliance resources.
Real Enforcement: What Happens When Covered Entities Get It Wrong
OCR doesn't just write guidance documents. They enforce. And the penalties are real.
In 2018, Anthem Inc. paid $16 million to settle HIPAA violations following a breach that affected nearly 79 million people. It remains the largest HIPAA settlement in history. The failures included insufficient technical safeguards and a lack of enterprise-wide risk analysis — both Privacy Rule and Security Rule obligations that apply to covered entities.
In 2023, Yakima Valley Memorial Hospital paid $240,000 after OCR found that 23 security guards had snooped through patient medical records without authorization. The Privacy Rule's "minimum necessary" standard requires covered entities to limit access to PHI to only those workforce members who need it for their job functions.
These aren't hypothetical scenarios. They're public enforcement actions listed on OCR's enforcement page.
Why This Question Matters Beyond the Exam
If you're studying for a compliance certification or onboarding quiz, knowing that the HIPAA Privacy Rule applies to covered entities and their business associates will get you the right answer. But in practice, the question has deeper implications.
Your Workforce Needs to Know the Answer Too
Every member of your workforce — from front desk staff to clinicians to IT administrators — needs to understand that they operate within a covered entity and that the Privacy Rule governs their daily behavior. I've watched breaches happen because a nurse assumed HIPAA only applied to billing. Or because a receptionist didn't realize that a verbal disclosure of a patient's diagnosis in a waiting room constitutes a Privacy Rule violation.
Our course on Verbal Disclosures: Watch What You Say was built specifically to address the oral PHI risks most training programs ignore. It's one of the most underestimated areas of Privacy Rule compliance.
For clinical teams, role-specific training changes everything. Our HIPAA Training for Nurses program addresses the exact scenarios nurses face during shift changes, patient handoffs, and family conversations — situations where the Privacy Rule's requirements collide with clinical workflow every single day.
Mental Health Providers Face Extra Scrutiny
If you're a behavioral health or mental health provider, the Privacy Rule applies to you with additional layers. Psychotherapy notes get heightened protection under 45 CFR § 164.508(a)(2). Substance use disorder records carry extra federal protections under 42 CFR Part 2. The stakes are higher, and the rules are stricter.
Our HIPAA Training for Mental and Behavioral Health course breaks down these overlapping requirements in plain language. If your practice handles psychotherapy notes or substance use records, generic HIPAA training won't cut it.
A Quick-Reference Checklist: Does the Privacy Rule Apply to You?
Ask yourself these questions:
- Does your organization provide, pay for, or process health care or health care transactions?
- Do you transmit any health information electronically in connection with a HIPAA-standard transaction?
- Do you handle PHI on behalf of a covered entity under a business associate agreement?
If you answered yes to any of these, the HIPAA Privacy Rule applies to your organization. Full stop.
The Bottom Line for Your Organization in 2026
The regulatory environment isn't getting simpler. OCR has signaled ongoing enforcement priorities around risk analysis, breach notification timelines, and right-of-access failures. If your organization qualifies as a covered entity or business associate, your Privacy Rule obligations are non-negotiable.
Don't guess about whether HIPAA applies to you. Know. And make sure your entire workforce knows too — because OCR doesn't accept ignorance as a defense. Explore our full HIPAA training catalog to find the course that matches your organization's specific risks and roles.