A few years ago, I got a call from the owner of a medical billing company in Georgia. She was panicked. The Office for Civil Rights had just opened an investigation into her firm after a laptop containing 2,700 patient records was stolen from an employee's car. Her first words to me: "I didn't think HIPAA applied to us — we're not a hospital."

She was wrong. And that misunderstanding cost her organization over $100,000 in penalties and corrective action costs.

If you've ever searched "who is covered by HIPPA" — and yes, the common misspelling is HIPPA, but the law is actually HIPAA (the Health Insurance Portability and Accountability Act) — you're asking the right question. The answer is broader than most people realize, and getting it wrong creates real legal exposure.

Who Is Covered by HIPAA? The Three Categories That Matter

HIPAA doesn't apply to every organization that touches health data. It applies to specific categories defined by the U.S. Department of Health and Human Services (HHS). If your organization falls into one of these buckets, you're on the hook for full compliance — no exceptions.

1. Healthcare Providers Who Transmit Electronically

This is the category most people think of first: doctors, hospitals, clinics, dentists, psychologists, chiropractors, and nursing homes. But there's a critical qualifier. A healthcare provider is only a covered entity under HIPAA if they transmit any health information electronically in connection with a HIPAA-covered transaction.

In practice, that covers virtually every provider in 2026. If you file electronic claims, verify insurance eligibility online, or send electronic referral authorizations, you're a covered entity. The solo practitioner who bills Medicare through a clearinghouse is covered. So is the massive hospital system.

2. Health Plans

Health insurance companies, HMOs, employer-sponsored group health plans, Medicare, Medicaid, and military healthcare programs like TRICARE — all covered entities. If you're a mid-sized employer sponsoring a group health plan, your plan itself is a covered entity and must comply with HIPAA's Privacy and Security Rules.

This catches a lot of HR departments off guard. The company isn't necessarily the covered entity, but the group health plan it sponsors is. And the employees administering that plan must handle PHI according to HIPAA standards.

3. Healthcare Clearinghouses

Clearinghouses are the middlemen. They process nonstandard health information into standard formats (or vice versa). Billing services, repricing companies, and community health management information systems often fall here. They receive PHI from one entity, translate it, and pass it along.

Most patients have never heard of clearinghouses. But they handle enormous volumes of protected health information every day.

Business Associates: The Fourth Wall of HIPAA

Here's where the billing company owner from Georgia got burned. Even if your organization isn't a covered entity, you may still be bound by HIPAA as a business associate.

A business associate is any person or organization that performs a function or activity on behalf of a covered entity that involves access to PHI. Think: IT vendors managing ePHI on cloud servers. Shredding companies handling paper records. Law firms reviewing patient files. Accountants auditing a medical practice.

Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for HIPAA violations. OCR doesn't care that you're "just the vendor." If you touch PHI, you carry the obligation.

The relationship must be formalized through a Business Associate Agreement (BAA). No BAA? That's already a violation — for both parties. OCR has made this crystal clear through enforcement.

The $4.3 Million Penalty That Proved OCR Means Business

In 2016, Advocate Health Care Network agreed to a $5.55 million settlement with HHS after multiple breaches affecting nearly 4 million individuals. Among the failures: ePHI on an unencrypted laptop, inadequate business associate oversight, and no comprehensive risk analysis.

Advocate was clearly a covered entity. But the case also exposed how covered entities fail to manage their business associate relationships — which is itself a HIPAA violation.

And in 2018, Fresenius Medical Care North America paid $3.5 million to settle five separate breach reports. OCR found that several Fresenius-owned covered entities had failed to conduct accurate risk analyses and implement proper policies. Five facilities, five breaches, one massive penalty.

Who Is Not Covered by HIPAA?

This is the question that deserves its own featured answer because the confusion cuts both ways.

These entities are generally NOT covered by HIPAA:

  • Employers (in their role as employers — your HR file with your doctor's note is not automatically HIPAA-protected)
  • Life insurance companies
  • Workers' compensation carriers
  • Most schools and school districts (they fall under FERPA instead)
  • Law enforcement agencies
  • Fitness apps and consumer wearable companies (unless they meet the definition of a covered entity or business associate)
  • Marketers and data brokers handling de-identified health data

I see this misunderstanding constantly. An employee calls HR furious about a "HIPAA violation" because their manager mentioned they were out sick. That's not a HIPAA issue. HIPAA governs covered entities and their business associates — not your boss.

What About Apps and Tech Companies?

This is the gray zone that keeps expanding. Consumer health apps — the ones you download to track your mood, cycle, or blood pressure — are generally not covered by HIPAA unless the app was provided by or contracted through a covered entity.

The FTC has stepped in with its Health Breach Notification Rule to cover some of these gaps, but the rules are different from HIPAA. If your organization develops health tech, you need to determine whether you qualify as a business associate or if you fall outside HIPAA's perimeter entirely. The HHS covered entity guidance page is a solid starting point for that analysis.

Your Staff Doesn't Know This — And That's the Real Risk

In my experience, the biggest compliance gaps don't come from leadership ignorance. They come from workforce members who don't understand the scope of HIPAA. Your front-desk staff, billing department, IT team, and contracted vendors all need to know whether HIPAA applies to their role — and what it demands of them specifically.

OCR's enforcement actions consistently cite "failure to train workforce members" as a contributing factor. It's not enough to have policies sitting in a binder. Your people need to understand what PHI is, what a covered entity is, what a business associate is, and what happens when those boundaries get crossed.

If you're running a clinical environment, our HIPAA training program for physicians and clinical staff is built around exactly these scenarios — real enforcement cases, real-world obligations, and the specific rules your team must follow.

Three Steps to Determine If Your Organization Is Covered

Step 1: Classify Your Entity

Are you a healthcare provider who transmits electronic health information? A health plan? A clearinghouse? If yes, you're a covered entity. Full stop.

Step 2: Evaluate Your Business Relationships

Do you handle, store, transmit, or have access to PHI on behalf of a covered entity? If yes, you're a business associate. You need a BAA, and you need a compliance program.

Step 3: Train and Document

Classification alone doesn't create compliance. You need workforce training, a risk analysis, written policies, breach notification procedures, and documentation that proves it all. Check out our full training catalog to find the right program for your organization's role and size.

The Penalty Spectrum Is Wider Than You Think

OCR uses a tiered penalty structure, and the range is enormous. Violations can result in penalties from $137 per violation (for unknowing violations) up to nearly $2.1 million per violation category per year. Criminal penalties — prosecuted by the Department of Justice — can include fines up to $250,000 and imprisonment up to 10 years for offenses committed with intent to sell or use PHI for personal gain.

And those are just the federal numbers. State attorneys general can bring additional actions under the HITECH Act. The financial exposure for an entity that didn't even realize it was covered can be devastating.

Stop Guessing. Get Classified.

If you're still wondering whether HIPAA applies to your organization, you're already behind. The law has been in effect since 1996. The enforcement infrastructure has never been more active. And "I didn't know I was covered" has never once worked as a defense with OCR.

Determine your status. Train your workforce. Document everything. That's not just advice — it's the minimum standard for operating in healthcare in 2026.