A Question That Costs Organizations Millions Every Year
I got a call last year from a medical billing company owner who was convinced HIPAA didn't apply to her business. "We're not a doctor's office," she said. "We just process claims." Two months later, she was staring at an OCR investigation letter after a laptop containing 12,000 patient records was stolen from an employee's car.
The question "the HIPAA Privacy Rule applies to which of the following" shows up on every certification exam and compliance quiz in healthcare. But it's not just a test question. It's the single most consequential compliance determination your organization will ever make. Get it wrong, and you're operating without safeguards you're legally required to have — while OCR sharpens its enforcement tools.
Here's the direct answer, and then I'll break down every category so you never have to guess again.
The Definitive Answer: Who the HIPAA Privacy Rule Covers
The HIPAA Privacy Rule applies to covered entities and business associates. That's it. Two categories. But inside those two categories lives an enormous range of organizations that many people don't expect.
Covered Entities: The Three Types
HHS defines three types of covered entities under the Privacy Rule:
- Health plans — health insurance companies, HMOs, employer-sponsored group health plans, Medicare, Medicaid, and military and veterans' health programs.
- Health care clearinghouses — entities that process nonstandard health information into standard formats. Billing services and repricing companies often fall here.
- Health care providers — any provider who transmits health information electronically in connection with a HIPAA-covered transaction. This includes hospitals, physicians, dentists, chiropractors, nursing homes, pharmacies, and yes, even solo practitioners.
The critical nuance on that third category: a health care provider only becomes a covered entity if they conduct certain electronic transactions, like submitting claims electronically. A therapist who only accepts cash and never files electronic claims might technically fall outside HIPAA — but the moment they submit a single electronic claim, they're in. You can review HHS's own guidance on covered entity categories at HHS.gov's covered entities page.
Business Associates: The Category Everyone Forgets
The 2013 HITECH Omnibus Rule changed everything for business associates. Before that, business associates had indirect obligations through their contracts with covered entities. Now, they're directly liable under the Privacy Rule and the Security Rule.
A business associate is any person or organization that performs a function or activity on behalf of a covered entity that involves access to protected health information (PHI). Think:
- IT companies that host or maintain systems containing ePHI
- Accounting firms that access PHI during audits
- Attorneys who receive PHI for legal representation
- Shredding companies that destroy paper records containing PHI
- Cloud storage providers that store ePHI
That billing company owner I mentioned? She was a textbook business associate. She needed a Business Associate Agreement with every covered entity she served, plus her own HIPAA compliance program. She had neither.
Who the HIPAA Privacy Rule Does NOT Apply To
This is where I see the most confusion. The Privacy Rule does not apply to:
- Employers acting in their role as employers (not as health plan sponsors)
- Life insurers
- Workers' compensation carriers
- Most schools and school districts (student health records are typically covered by FERPA, not HIPAA)
- Law enforcement agencies
- Most state agencies outside of Medicaid
- Consumer health apps that aren't provided by or on behalf of a covered entity
Here's the trap, though. An entity might not be a covered entity under HIPAA but could still be a business associate if it handles PHI for one. A fitness app company that contracts with a hospital to provide patient wellness tracking? That's a business associate relationship, and HIPAA applies.
The $4.3 Million Mistake: When Entities Don't Know the Rule Applies
In 2016, Advocate Health Care Network paid $5.55 million to settle HIPAA violations after multiple breaches affecting approximately 4 million individuals. Among the issues: business associate relationships without proper agreements and inadequate safeguards for ePHI. You can review the details of this enforcement action on the HHS enforcement page for Advocate Health Care.
I've personally consulted with organizations that discovered mid-breach that they were business associates with no compliance infrastructure. No risk assessment. No workforce training. No breach notification procedures. The scramble that follows is ugly, expensive, and entirely preventable.
Subcontractors Are Business Associates Too
One layer that still catches organizations off guard: if your business associate hires a subcontractor who accesses PHI, that subcontractor is also a business associate. They need their own Business Associate Agreement. They need their own compliance program. The chain doesn't break just because you added a link.
What the Privacy Rule Actually Requires of These Entities
Once the HIPAA Privacy Rule applies to your organization, you're on the hook for a specific set of obligations:
- Minimum Necessary Standard — only access, use, or disclose the minimum PHI needed for the task at hand.
- Patient Rights — provide individuals access to their records, honor amendment requests, and provide an accounting of disclosures.
- Notice of Privacy Practices — covered entities must give patients a clear notice explaining how their PHI may be used and disclosed.
- Workforce Training — every member of your workforce must be trained on your HIPAA policies and procedures. Not just clinicians. Everyone.
- Administrative Safeguards — designate a Privacy Officer, conduct risk assessments, and implement policies for PHI handling.
- Breach Notification — notify affected individuals, HHS, and in some cases the media when a breach of unsecured PHI occurs.
That workforce training requirement is where I see the biggest gap between what organizations think they're doing and what they're actually doing. Handing someone a policy binder on their first day doesn't qualify. Training needs to be role-specific and documented. Nurses face different PHI exposure scenarios than front-desk staff, which is why role-based programs like HIPAA training designed specifically for nurses and clinical workflows exist.
Verbal Disclosures: The Risk Hiding in Plain Sight
When people hear "HIPAA Privacy Rule," they think about electronic records and data breaches. But some of the most common violations I've investigated involved spoken words. A nurse discussing a patient's diagnosis in a hospital elevator. A receptionist confirming a patient's appointment within earshot of the waiting room. A therapist leaving a voicemail with too much clinical detail.
The Privacy Rule governs all forms of PHI — electronic, paper, and oral. Verbal disclosures are particularly dangerous because they leave no audit trail and are nearly impossible to remediate once they happen. I always recommend that covered entities invest in targeted training on this topic, like the Verbal Disclosures: Watch What You Say course, which walks staff through real scenarios they'll actually encounter.
Mental Health Records Get Extra Protection
The Privacy Rule applies broadly to all PHI, but psychotherapy notes occupy a special category. These notes — the personal observations a mental health provider records during a counseling session — require separate patient authorization before disclosure in most circumstances. They're excluded from the standard "treatment, payment, and health care operations" permissions.
If your organization provides mental or behavioral health services, this distinction matters enormously. A general HIPAA training program won't cover the nuances of 42 CFR Part 2 or psychotherapy note protections in enough depth. That's why specialized programs like HIPAA training for mental and behavioral health professionals exist — they address the specific regulatory layers your clinicians navigate daily.
How to Determine If the Privacy Rule Applies to You
Run through this checklist:
- Do you provide health care and submit any transactions electronically? → You're likely a covered entity.
- Do you operate a health plan of any size? → Covered entity.
- Do you process health information from nonstandard to standard formats? → Health care clearinghouse. Covered entity.
- Do you handle, access, store, transmit, or dispose of PHI on behalf of a covered entity? → Business associate.
- Are you a subcontractor of a business associate with PHI access? → Also a business associate.
If you answered yes to any of those, the HIPAA Privacy Rule applies to you. Full stop. The HHS Privacy Rule overview page is the authoritative starting point for understanding your obligations.
Stop Guessing. Start Building Your Compliance Program.
I've watched too many organizations treat HIPAA applicability as a gray area when it's actually black and white. The Privacy Rule applies to covered entities and business associates. If your organization touches PHI in any capacity connected to a covered entity, you have obligations under federal law.
The penalty for noncompliance isn't theoretical. OCR has collected over $142 million in HIPAA enforcement actions since the Privacy Rule took effect. Your best protection starts with understanding that the rule applies to you — and then training your entire workforce accordingly. Browse the full HIPAA training catalog to find role-specific courses built for how your teams actually work.