A solo chiropractor in New England assumed HIPAA didn't apply to her practice. She had fewer than ten employees, no electronic health records system, and filed most claims on paper. Then a patient complained to the Office for Civil Rights. Within months, she was facing a corrective action plan and scrambling to build a compliance program from scratch. Her mistake wasn't malice — it was a fundamental misunderstanding of who is covered under the HIPAA rules.

I see this confusion constantly. Dentists, therapists, billing companies, cloud storage vendors — many assume they fall outside HIPAA's reach. They're almost always wrong. Let me walk you through exactly who the law covers, why it matters, and what happens when organizations get this wrong.

Who Is Covered Under the HIPAA Rules? The Three Categories

HIPAA doesn't apply to every organization that touches health information. But it applies to far more than most people think. The law defines three categories of covered entities and adds a fourth critical group — business associates — that dramatically expands the reach.

1. Health Care Providers Who Transmit Electronically

If you furnish, bill, or are paid for health care and you transmit any information electronically in connection with a HIPAA-covered transaction, you're a covered entity. Period. Size doesn't matter. A solo psychiatrist who submits a single electronic claim is covered just like a 5,000-bed hospital system.

This catches people off guard. You don't need to use an EHR. You don't need a patient portal. If your office sends electronic claims, checks eligibility electronically, or transmits referral authorizations, you're in. The HHS guidance on this is explicit — see the HHS Covered Entities page for the full breakdown.

2. Health Plans

Health plans are the second category. This includes health insurance companies, HMOs, employer-sponsored group health plans, Medicare, Medicaid, and military and veterans' health programs. If you administer or pay for medical care, you're covered.

What surprises many employers: if you sponsor a group health plan, that plan is a covered entity. The employer itself may not be — but the plan is. And if your HR team handles enrollment, claims disputes, or PHI from the plan, you need firewalls, policies, and training to keep that data segregated.

3. Health Care Clearinghouses

Clearinghouses process or facilitate the processing of health information between providers and payers. They convert nonstandard data into standard formats (or vice versa). Companies like billing services that translate claims into HIPAA-standard electronic formats fall squarely here.

4. Business Associates — The Category Everyone Forgets

Here's where the net gets wide. Any person or organization that performs a function or activity on behalf of a covered entity — and that function involves access to protected health information (PHI) — is a business associate. The 2013 HIPAA Omnibus Rule made business associates directly liable under the HIPAA rules, not just contractually obligated.

Examples I encounter regularly: IT companies managing servers that store ePHI. Attorneys reviewing medical records for a hospital. Shredding companies that destroy paper records containing PHI. Accountants who access billing data with patient identifiers. Cloud hosting providers. Answering services. Consultants.

If you touch PHI on behalf of a covered entity, you're a business associate. You need a signed business associate agreement (BAA), your own compliance program, and workforce training. No exceptions.

The $4.3 Million Mistake: What Happens When You Ignore Coverage

In 2016, the University of Mississippi Medical Center paid $2.75 million to settle with OCR after a breach involving a stolen laptop with ePHI. Part of the problem? A failure to adequately manage access and implement policies across the workforce. OCR's investigation revealed systemic compliance gaps.

More recently, in 2023, OCR settled with Doctors' Management Services — a business associate — for $100,000 after a ransomware attack exposed the ePHI of 206,695 individuals. This case drove home a point I make to every client: business associates face the same enforcement scrutiny as covered entities. OCR's enforcement actions page is a sobering read. I recommend bookmarking it.

Penalties range from $141 per violation up to nearly $2.2 million per violation category per year under the updated penalty tiers. Willful neglect that goes uncorrected carries mandatory penalties. "I didn't know I was covered" has never been a successful defense.

Who Is NOT Covered — And Why That Matters Too

Not every entity that handles health data falls under HIPAA. Understanding the boundaries prevents both over-compliance and dangerous under-compliance.

Entities typically not covered include:

  • Life insurers
  • Workers' compensation carriers (in most cases)
  • Most schools and school districts (FERPA governs student health records)
  • Most law enforcement agencies
  • Most municipal agencies and employers (unless they sponsor a group health plan)
  • Consumer health apps that don't share data with covered entities

But here's the trap: a company might not be a covered entity and still become a business associate if it contracts with one. A tech startup building an app for a hospital system? Business associate. A staffing firm placing nurses at a clinic? Likely a business associate. Context determines coverage.

Subcontractors Are Covered Too — All the Way Down

The Omnibus Rule extended HIPAA obligations to subcontractors of business associates. If your IT vendor hires a cloud storage company to host your data — and that data includes ePHI — the cloud company is a business associate of your business associate. They need a BAA. They need their own compliance program.

I've audited organizations that had solid BAAs with their primary vendors but zero documentation for downstream subcontractors. That's a gap OCR will find. The chain of custody for PHI doesn't stop at the first handoff.

What Does Coverage Actually Require?

Once you're covered — whether as a covered entity or business associate — your obligations are substantial:

  • Privacy Rule compliance: Policies governing the use and disclosure of PHI
  • Security Rule compliance: Administrative, physical, and technical safeguards for ePHI
  • Breach Notification Rule: Notify affected individuals, HHS, and sometimes the media when unsecured PHI is breached
  • Workforce training: Every member of your workforce who handles PHI must receive HIPAA training — and it must be documented
  • Risk analysis: An accurate, thorough assessment of potential risks to ePHI — not a checkbox exercise, a real analysis

The training requirement is one of the most commonly failed elements I see during audits. Organizations that invest in structured, role-specific HIPAA training programs tend to perform dramatically better in OCR investigations than those running a once-a-year generic slide deck.

How to Determine If Your Organization Is Covered

Start with three questions:

  • Does your organization provide, pay for, or facilitate health care?
  • Do you transmit any health information electronically in connection with a covered transaction?
  • Do you handle PHI on behalf of an organization that answers "yes" to the first two questions?

If you answered yes to any of these, you're almost certainly covered. The HHS website offers a helpful decision tool, and the regulatory definitions are spelled out in 45 CFR Part 160, Subpart A.

When in doubt, act as if you're covered. The cost of unnecessary compliance is a fraction of the cost of a single OCR settlement.

Your Workforce Is the Front Line

Knowing you're covered is step one. Building a culture where every person in your organization understands their role in protecting PHI is the real work. That means onboarding training, annual refreshers, and documentation you can produce if OCR comes knocking.

I've watched organizations with strong training programs navigate OCR investigations in weeks. Organizations without them? Those investigations drag on for months or years, often ending in six- or seven-figure settlements.

If you haven't reviewed your training approach recently, explore the HIPAA training catalog at HIPAACertify for structured options designed for covered entities and business associates alike.

The Bottom Line on HIPAA Coverage

HIPAA's reach is broader than most organizations realize. Covered entities, business associates, and even subcontractors all carry direct obligations under the law. The penalties for getting this wrong aren't theoretical — OCR has collected hundreds of millions in enforcement actions since the Privacy Rule took effect.

Don't wait for a complaint or a breach to figure out where you stand. Map your data flows, identify every entity touching PHI, lock down your BAAs, and train your workforce. That's not just compliance advice — it's the most cost-effective risk management strategy you'll find in health care.