A fitness app company thought HIPAA had nothing to do with them — until HHS came knocking. A county hospital assumed their janitorial contractor didn't need a business associate agreement. A solo-practice therapist believed she was too small for federal regulators to notice. Every one of them was wrong. Understanding exactly who HIPAA applies to isn't just a legal nicety. It's the difference between operating safely and writing a seven-figure check to the Office for Civil Rights.
I've spent years watching organizations stumble over this question. Not because it's impossibly complex, but because the answer has expanded significantly since HIPAA first became law in 1996. If you handle protected health information — or even touch the systems that store it — you need to read what follows.
Who HIPAA Applies To: The Two Core Categories
HIPAA's Privacy and Security Rules don't apply to everyone. They target two specific categories: covered entities and business associates. Miss this distinction, and you'll either over-invest in compliance you don't need or — far more dangerously — ignore obligations that absolutely apply to your organization.
Covered Entities: The Starting Point
A covered entity is any organization that transmits health information electronically in connection with a HIPAA-covered transaction. That definition covers three types of organizations:
- Health plans — health insurance companies, HMOs, employer-sponsored group health plans, Medicare, Medicaid, and military/veterans' health programs.
- Healthcare clearinghouses — entities that process nonstandard health information into standard formats (or vice versa). Think billing services and repricing companies.
- Healthcare providers — any provider who transmits health information electronically for transactions like claims, benefit eligibility inquiries, or referral authorizations. This includes hospitals, physicians, dentists, chiropractors, nursing homes, and pharmacies.
Here's the detail that catches people: a healthcare provider only becomes a covered entity when they conduct electronic transactions. A therapist who exclusively accepts cash and never submits electronic claims may not technically be a covered entity. But the moment they file a single electronic claim, HIPAA applies to them fully — not partially, not just for that one claim.
Business Associates: The Expanding Circle
The HITECH Act of 2009 changed everything for business associates. Before HITECH, HIPAA's enforcement teeth only reached covered entities directly. Now, HIPAA applies to any person or organization that performs functions or activities on behalf of a covered entity involving the use or disclosure of PHI.
Business associates include:
- IT companies that maintain or host systems containing ePHI
- Billing and coding companies
- Accountants who access PHI for auditing
- Attorneys who handle PHI in legal matters
- Cloud service providers storing ePHI
- Shredding and document destruction companies
- Answering services that take messages containing patient information
If your organization touches PHI in any capacity on behalf of a covered entity, you're a business associate. Full stop. You need a business associate agreement (BAA), and you need your own compliance program. The HHS guidance on business associates spells this out clearly.
The $4.3 Million Mistake: When Organizations Get It Wrong
In 2016, Advocate Health Care Network paid $5.55 million to settle multiple HIPAA violations, the largest settlement at the time. Among the findings: Advocate failed to obtain a BAA with a business associate and didn't conduct a proper risk analysis covering all entities within its network. OCR didn't care that the breaches happened at subsidiaries or through contractors. HIPAA applied across the entire chain.
I've seen this pattern repeat endlessly. A hospital hires a medical transcription service. They never sign a BAA. The transcription service has a breach. Suddenly both parties face enforcement action. The covered entity gets hit for failing to have a BAA in place, and the business associate gets hit for failing to safeguard PHI.
This is why I always tell clients: if someone outside your organization can see, access, transmit, or store PHI on your behalf, get a BAA signed before they start work. Not after. Not eventually. Before.
Does HIPAA Apply to Employers?
This is the question I hear most often, and the answer surprises people. HIPAA does not apply to employers simply because they hold employee health information. If a manager collects a doctor's note from an employee, that interaction alone doesn't trigger HIPAA obligations.
However — and this is critical — if your company sponsors a group health plan, that plan is a covered entity. The plan itself must comply with HIPAA. Employment records containing health information held by the employer in its role as employer are generally not subject to HIPAA, but the moment those records relate to the group health plan's functions, the rules apply.
The distinction matters in practice. I've consulted with HR departments that stored group health plan enrollment data on unencrypted shared drives alongside general HR files. That's a HIPAA problem, even though the employer-as-employer isn't directly regulated.
Subcontractors of Business Associates: The Layer Most People Forget
Here's where it gets interesting. Since the 2013 HIPAA Omnibus Rule, HIPAA applies to subcontractors of business associates too. If your IT vendor hires a sub-vendor to manage backups of your ePHI, that sub-vendor is also a business associate under HIPAA.
This creates a chain of accountability. Each link needs its own BAA with the link above it. Each link must comply with the Security Rule independently. OCR has been clear: you can't outsource your compliance obligations.
Our HIPAA Introduction Training 2026 walks through these relationships in detail, with practical examples of how covered entities, business associates, and subcontractors interact in real compliance scenarios.
Remote Workers and Mobile Devices: Where HIPAA's Reach Gets Personal
The explosion of remote work since 2020 created a compliance headache that still hasn't fully resolved. When your workforce accesses ePHI from home or from a personal phone, HIPAA's requirements follow the data — not the building.
Every laptop, tablet, and smartphone that touches patient data is subject to the Security Rule's administrative, physical, and technical safeguards. That means encryption, access controls, audit logging, and workforce training apply whether your staff sits in a hospital workstation or a kitchen table.
I've reviewed incident reports where a nurse accessed patient records on a home computer shared with family members. No password protection. No encryption. A child accidentally emailed a file containing PHI to a school teacher. That's a reportable breach.
If your organization has remote workers handling PHI, our Working from Home & PHI course addresses exactly these scenarios. And for the mobile device angle — lost phones, unsecured apps, texting patient information — our Mobile Devices & PHI training covers the safeguards OCR expects to see.
Who HIPAA Does NOT Apply To
Knowing the boundaries matters just as much as knowing the scope. HIPAA does not apply to:
- Life insurers
- Workers' compensation carriers (in most cases)
- Most schools and school districts (FERPA covers student records)
- Most law enforcement agencies
- Municipal agencies not providing healthcare
- Employers holding health data in employment records (as employers, not as health plan sponsors)
That said, state privacy laws often fill the gaps where HIPAA doesn't reach. Just because HIPAA doesn't apply to your organization doesn't mean you have no privacy obligations.
What Triggers an OCR Investigation?
OCR investigates when it receives a complaint or a breach notification. Per the HHS enforcement page, the agency has investigated over 300,000 cases since the Privacy Rule took effect. Settlements and civil money penalties have exceeded $142 million combined.
The question OCR asks first in many investigations is straightforward: Is this entity subject to HIPAA? If the answer is yes — because the entity is a covered entity, business associate, or subcontractor — the investigation proceeds. If the entity genuinely falls outside HIPAA's scope, OCR typically refers the matter to the FTC or a state attorney general.
This is exactly why getting the "who does HIPAA apply to" question right at the outset matters so much. You can't build a compliance program on a faulty foundation.
The Training Obligation That Comes With the Territory
If HIPAA applies to your organization, then workforce training isn't optional — it's required. Section 164.530(b) of the Privacy Rule and Section 164.308(a)(5) of the Security Rule both mandate it. Every member of your workforce must receive training on your HIPAA policies and procedures. Not just clinicians. Not just IT staff. Everyone.
OCR has specifically cited training failures in multiple enforcement actions. In 2019, the University of Rochester Medical Center paid $3 million partly because it failed to adequately train its workforce on managing ePHI on mobile devices. The lack of training contributed directly to the breach.
Your training must be specific to your organization's operations, not generic slide decks that no one reads. It must be documented. And it must happen at hire and periodically thereafter. The Security Rule requirements at 45 CFR Part 164 Subpart C make this unmistakably clear.
So Does HIPAA Apply to You?
Here's the simplest test I give my clients. Ask yourself three questions:
- Does your organization provide healthcare, process health transactions electronically, or offer a health plan?
- Does your organization handle PHI on behalf of an entity that does any of the above?
- Does your organization subcontract for a business associate that handles PHI?
If the answer to any of those is yes, HIPAA applies to you. Your obligations include implementing safeguards, training your workforce, conducting risk analyses, managing business associate agreements, and reporting breaches to HHS.
Don't wait for an OCR complaint to find out where you stand. Build your compliance program now, train your people properly, and document everything. That's not paranoia — it's the standard of care that federal law demands.