HIPAA does not apply to private individuals acting in a personal capacity, but it does apply to individuals when they are part of a HIPAA Covered Entity workforce, act as an agent of a HIPAA Covered Entity or Business Associate, or operate as a Business Associate that creates, receives, maintains, or transmits protected health information on behalf of a HIPAA Covered Entity.
Private individuals who share their own health information are not regulated by HIPAA for that activity. Private individuals who learn health information outside a role connected to a HIPAA Covered Entity or Business Associate are also not regulated by HIPAA for later sharing, even when the disclosure is inappropriate, although other laws and remedies may apply depending on jurisdiction and circumstances.
HIPAA applies to individuals who access or disclose protected health information through their duties for a HIPAA Covered Entity or Business Associate, including employees, volunteers, trainees, and contractors under direct control. HIPAA also applies to sole proprietors and independent contractors when they perform Business Associate functions that involve protected health information, such as billing services, transcription, information technology support, consulting, analytics, legal services, or cloud storage, when those services are performed on behalf of a HIPAA Covered Entity.
When a private individual is acting within a regulated role, compliance obligations are implemented through the policies, procedures, training, access controls, and sanction standards of the HIPAA Covered Entity or Business Associate. Improper access, impermissible disclosures, and failure to follow required safeguards can create organizational liability and, in certain knowing misconduct cases, potential individual criminal exposure.
