HIPAA does not apply to organizations or individuals that are not HIPAA Covered Entities or Business Associates, and it also does not apply to certain categories of records even when they contain health-related information.
HIPAA Applicability Standard
HIPAA applies to HIPAA Covered Entities and their Business Associates. HIPAA Covered Entities are health plans, healthcare clearinghouses, and healthcare providers that transmit health information in electronic form in connection with standard transactions. Business Associates are persons or organizations that create, receive, maintain, or transmit protected health information on behalf of a HIPAA Covered Entity, or on behalf of another Business Associate, for defined functions such as claims processing, billing, analytics, legal, accounting, consulting, data storage, and similar services.
Entities outside these definitions are not regulated by the HIPAA Privacy Rule, the HIPAA Security Rule, or the HIPAA Breach Notification Rule unless they assume a Business Associate role through their services for a HIPAA Covered Entity and sign a Business Associate Agreement.
Individuals Acting an a Personal Capacity
HIPAA does not apply to patients, family members, friends, or other individuals when they handle health information in a personal capacity. A person can share their own health information or another person’s health information they obtained outside a HIPAA Covered Entity relationship, and that activity is not regulated by HIPAA.
HIPAA also does not apply to a person who receives information from a patient and later discloses it, unless the person is acting as a workforce member, agent, or Business Associate of a HIPAA Covered Entity under an applicable relationship and scope of work.
Employers and Most Workplace Records
HIPAA does not apply to most employers when they hold employee health-related information in employment records. Employment records, including information used for leave administration, fitness-for-duty determinations, workers’ compensation administration, and workplace accommodations, are not protected health information when maintained by an employer in its role as an employer.
A health plan sponsored by an employer can be a HIPAA Covered Entity if it meets the definition of a health plan. HIPAA protections apply to protected health information held by the health plan and its Business Associates. HIPAA does not apply to the employer’s separate employment records, even when similar information appears in both places.
Schools and Education Records
HIPAA does not apply to education records covered by the Family Educational Rights and Privacy Act. Student health and counseling records maintained by a school in a manner that meets the definition of an education record are excluded from protected health information under HIPAA.
A school-based clinic that is operated as a HIPAA Covered Entity and performs covered electronic transactions can be subject to HIPAA for protected health information it maintains in that role. The scope depends on how the clinic is structured, how records are maintained, and whether records are treated as education records under applicable law.
Law Enforcement and Courts
HIPAA does not apply to law enforcement agencies, prosecutors, courts, or correctional institutions solely because they possess health information. These entities are not HIPAA Covered Entities by default, and they are not Business Associates unless they perform a Business Associate function for a HIPAA Covered Entity under an agreement and within the scope of that function.
HIPAA still regulates the HIPAA Covered Entity that discloses protected health information to law enforcement or a court. The HIPAA Privacy Rule conditions for disclosures, such as those for legal process or law enforcement purposes, remain applicable to the disclosing HIPAA Covered Entity.
Life Insurers, Disability Insurers, and Other Non Health Plans
HIPAA does not apply to many insurance products that are not “health plans” under the HIPAA definition. Life insurance, many disability insurance arrangements, workers’ compensation carriers, and many casualty insurers are not HIPAA Covered Entities solely by offering those products.
These organizations frequently receive medical information for underwriting, claims, and eligibility decisions. That information can be regulated by state insurance privacy laws, contractual confidentiality terms, and general consumer protection standards even when HIPAA does not apply.
Consumer Health Apps and Wearables Not Operating for a Covered Entity
HIPAA does not apply to many consumer-facing mobile apps, websites, wearables, and direct-to-consumer services that collect health-related information from users and do not operate on behalf of a HIPAA Covered Entity. Health information collected directly from a consumer by a non-covered entity is not protected health information under HIPAA solely because it relates to health.
HIPAA can apply when a vendor provides app, hosting, analytics, communications, or similar services to a HIPAA Covered Entity and handles protected health information as part of that service. The determining factor is the relationship and function performed for the HIPAA Covered Entity, not the label used by the vendor.
Data Brokers, Marketing Firms, And Media Organizations
HIPAA does not apply to data brokers, advertising networks, or media organizations that are not HIPAA Covered Entities or Business Associates. These organizations can handle health-related inferences, audience segments, and consumer data without becoming subject to HIPAA unless they are performing a covered function for a HIPAA Covered Entity that involves protected health information.
A HIPAA Covered Entity remains regulated when it uses or discloses protected health information for marketing-related activities. The HIPAA Privacy Rule imposes conditions on marketing communications and on disclosures that involve remuneration in connection with protected health information.
Organizations Handling De Identified Information
HIPAA does not apply to information that meets HIPAA de-identification standards and is not protected health information. An organization that receives properly de-identified information is not subject to HIPAA for that information because it is outside the definition of protected health information.
HIPAA applies to the HIPAA Covered Entity or Business Associate that performs the de-identification activity while it still holds identifiable protected health information and while de-identification is being created, used, or disclosed.
Government Benefit Programs Outside HIPAA Health Plan Definitions
HIPAA does not apply to all government programs that touch health information. Some government agencies operate programs that meet the definition of a health plan or provide healthcare and can be HIPAA Covered Entities for those functions. Other agencies hold health information for eligibility, benefits coordination, child welfare, public safety, or social services purposes without being HIPAA Covered Entities.
Scope depends on the function and the program. Agencies can also operate as hybrid entities with designated healthcare components that are regulated under HIPAA, while other components remain outside HIPAA.
Practical Compliance Implications
HIPAA compliance determinations depend on role and function rather than the sensitivity of the information. A recipient of protected health information is not automatically subject to HIPAA after receiving it, unless the recipient is a HIPAA Covered Entity, a Business Associate, or a workforce member operating within a regulated role.
When HIPAA does not apply, other legal and contractual regimes often govern privacy and security obligations. State medical confidentiality laws, state consumer privacy laws, federal consumer protection standards, and contractual requirements can impose restrictions on collection, use, disclosure, retention, and breach notification even when HIPAA does not apply.
