A home health aide in Georgia texts a photo of a patient's wound to a family member — using her personal phone, over an unsecured network. Nobody reports it. Nobody thinks twice. Six months later, HHS comes knocking. The agency's owner says the same thing I hear in almost every case: "I didn't think HIPAA applied to us."
That phrase has cost organizations millions of dollars. So let's settle this once and for all. Who does HIPAA apply to? The answer is broader than most people realize, and getting it wrong isn't just risky — it's expensive.
Who Does HIPAA Apply To? The Short Answer
HIPAA applies to two main categories: covered entities and business associates. If your organization touches protected health information (PHI) in any capacity that fits these categories, you're on the hook. Period.
Covered entities include health plans, health care clearinghouses, and health care providers who transmit any health information electronically. Business associates are individuals or organizations that perform services for covered entities and access PHI in the process.
But here's where it gets complicated — and where I've watched organizations stumble for over a decade.
Covered Entities: It's Not Just Hospitals
When people ask who does HIPAA apply to, they usually picture a hospital or a doctor's office. That's only the beginning. The Department of Health and Human Services defines three types of covered entities:
- Health care providers — any provider who electronically transmits health information in connection with certain transactions. This includes physicians, dentists, chiropractors, nursing homes, pharmacies, and yes, home health agencies.
- Health plans — health insurance companies, HMOs, employer-sponsored health plans, Medicare, Medicaid, and military health programs like TRICARE.
- Health care clearinghouses — entities that process nonstandard health information into standard formats. Most people have never heard of them, but they're absolutely covered.
Notice what's missing from that list? A size threshold. There's no "we're too small" exemption. A solo practitioner billing electronically is just as covered as a 5,000-bed hospital system.
The Home Health Trap
Home health care agencies are covered entities that frequently underestimate their HIPAA obligations. Their workforce operates in patients' homes, uses mobile devices, and often manages ePHI on the go. In my experience, these agencies face a unique combination of risks that many aren't prepared for.
I've walked into home health agencies where staff had zero formal HIPAA workforce training. No policies on mobile device use. No encryption on tablets carried from home to home. If that sounds familiar, your agency needs HIPAA training built specifically for home health care agencies — because generic training misses the risks your staff faces every day.
Business Associates: The Category Everyone Forgets
Before 2013, business associates lived in a gray area. The HITECH Act and the Omnibus Rule changed that permanently. Now, business associates are directly liable for HIPAA violations — and OCR enforces against them aggressively.
A business associate is any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Examples include:
- IT companies managing servers that store ePHI
- Billing and coding companies
- Cloud storage providers
- Shredding companies handling paper records with PHI
- Attorneys who access PHI during legal work
- Consultants performing utilization reviews
Here's the part that catches people off guard: subcontractors of business associates are also considered business associates under the Omnibus Rule. If your IT vendor hires a subcontractor who touches your ePHI, that subcontractor must also comply with HIPAA and sign a business associate agreement (BAA).
The $4.3 Million Penalty That Proved the Point
In 2018, OCR settled with Fresenius Medical Care North America for $3.5 million after five separate breach incidents. The root causes? Failures in risk analysis and risk management across multiple covered entity components. Every organization in that chain thought someone else was handling compliance.
That's exactly the mindset I encounter when working with organizations that use multiple business associates. Everyone assumes the other party has it covered. Nobody does.
Who HIPAA Does Not Apply To
This question matters just as much. HIPAA does not apply to:
- Employers in their role as employers (though employer-sponsored health plans are covered)
- Life insurers
- Workers' compensation carriers
- Most schools and school districts (they fall under FERPA instead)
- Law enforcement agencies
- Municipal offices
A gym that collects your heart rate data? Not covered. A fitness app on your phone? Probably not covered either — though the FTC has started stepping in on consumer health data under separate authority.
But be careful here. Just because your organization isn't a covered entity doesn't mean you're off the hook. If you provide services to a covered entity and access PHI, you're a business associate. The question isn't always "what are we?" — it's "who are we working with, and what data do we touch?"
Your Workforce Is Covered Too — Every Single Person
HIPAA's Privacy Rule defines "workforce" broadly. It includes employees, volunteers, trainees, and any person under the direct control of a covered entity or business associate — whether or not they're paid. That summer intern? Covered. The volunteer at the front desk? Covered.
This is why workforce training isn't optional. Under 45 CFR Part 164, Subpart C, covered entities must train all workforce members on HIPAA policies and procedures. OCR has made it clear that "we didn't train them" is not a defense — it's an admission.
If your organization hasn't provided role-specific HIPAA training recently, explore our full catalog of HIPAA training courses to find the right fit for every member of your team.
What Happens When You Get It Wrong
OCR's enforcement arm doesn't distinguish between ignorance and negligence. Penalties for HIPAA violations fall into four tiers, ranging from $137 to over $2 million per violation category per year (adjusted for inflation). Criminal penalties under HIPAA can result in fines up to $250,000 and imprisonment up to 10 years.
In 2023, OCR settled with Banner Health for $1.25 million after a 2016 breach affecting nearly 3 million individuals. The investigation revealed failures in access controls and risk analysis — basics that every covered entity should have in place.
And it's not just large systems at risk. OCR's Right of Access Initiative has targeted small practices, including a dental practice and a solo provider clinic, with penalties ranging from $30,000 to $240,000 for failing to give patients timely access to their own records.
Breach Notification: The Clock Starts Immediately
If you experience a breach of unsecured PHI, the breach notification rule requires you to notify affected individuals within 60 days. Breaches affecting 500 or more individuals must also be reported to HHS and prominent media outlets. Smaller breaches must be logged and reported annually.
I've seen organizations delay notification because they "weren't sure HIPAA applied" to their situation. That delay turned a manageable incident into a six-figure penalty.
How to Know If HIPAA Applies to Your Organization
Ask yourself three questions:
- Do we provide, pay for, or facilitate health care? If yes, you're likely a covered entity.
- Do we handle PHI on behalf of a covered entity? If yes, you're a business associate.
- Do we have a signed BAA in place for every relationship involving PHI? If not, you have a compliance gap right now.
If you answered yes to any of those, HIPAA applies to you. Full stop.
Stop Guessing. Start Training.
The single biggest compliance failure I see isn't a technical gap — it's an awareness gap. Organizations that don't know who HIPAA applies to can't possibly comply with it. And OCR has zero patience for that excuse in 2026.
Your staff needs to understand not just that HIPAA exists, but how it governs their specific daily actions. Home health aides need different training than billing specialists. Front desk volunteers need different guidance than IT administrators.
Start with HIPAA training designed for home health care agencies if that's your world. Or browse our complete training catalog to match courses to every role in your organization.
Because the worst time to learn that HIPAA applies to you is when OCR is already at the door.