By Compyl Research · Last reviewed September 2026
HIPAA applies to three types of covered entity — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically for covered transactions — plus the business associates that handle protected health information on their behalf. It does not apply to health information in general, and for most employers it does not apply at all.
Key takeaways
- HIPAA regulates organizations, not information. The same medical fact can be protected in one company’s hands and completely unregulated in another’s. What matters is who holds it and why.
- Most employers are not covered by HIPAA. Health information an employer holds in its role as an employer — sick notes, fitness-for-duty results, workers’ compensation records — is expressly excluded from the definition of protected health information.
- But the health plan an employer sponsors usually is covered, and that distinction is where organizations get into trouble: the plan is a covered entity even when the employer is not.
- Business associates carry direct liability. Since the HITECH Act, vendors handling PHI are regulated in their own right, not merely through their contract.
- “Not covered by HIPAA” rarely means “unregulated.” State privacy law, the ADA, GINA and the FTC’s Health Breach Notification Rule frequently fill the gap.
The misconception that causes most of the confusion
People assume HIPAA protects health information. It does not — not as a general proposition. HIPAA protects protected health information held by a covered entity or its business associate. Strip either half of that and the law does not apply.
The consequences are counterintuitive and worth stating plainly:
- Your doctor’s record of your diagnosis is protected. The same diagnosis, typed by you into a consumer wellness app, generally is not covered by HIPAA.
- A hospital’s record of an employee’s treatment is protected. That same hospital’s HR file on that employee’s sick leave is not — the hospital is a covered entity, but it is wearing a different hat.
- A life insurer, most fitness trackers, many employers and most schools are outside HIPAA entirely, regardless of how sensitive the information they hold is.
This is why “that’s a HIPAA violation” is so often wrong in casual use, and why determining your own status matters before you build a compliance program around the wrong law.
Covered entity, business associate, or neither
| Category | Definition | Typical examples | HIPAA obligation |
|---|---|---|---|
| Covered entity | Health plans, healthcare clearinghouses, and providers who transmit health information electronically in connection with covered transactions | Hospitals, physician practices, dentists, pharmacies, health insurers, HMOs, most employer-sponsored group health plans | Full Privacy, Security and Breach Notification Rules |
| Business associate | A person or organization that creates, receives, maintains or transmits PHI to perform a function on a covered entity’s behalf | Billing companies, cloud hosting for clinical systems, EHR vendors, transcription services, shredding companies, some SaaS platforms | Security Rule in full, much of the Privacy Rule, plus a signed BAA. Directly liable to regulators |
| Neither | Holds health information but outside the covered relationship | Most employers acting as employers, life and disability insurers, consumer health apps, schools, gyms, workers’ compensation carriers | None under HIPAA — but other laws frequently apply |
One nuance that trips people up: a provider is only a covered entity if it conducts covered transactions electronically — electronic claims, eligibility checks, and similar. A cash-only practice that never bills insurance electronically can fall outside HIPAA, though this is rarer in practice than it sounds and should not be assumed without checking.
The three types of covered entity
Health plans
Health insurers, HMOs, employer-sponsored group health plans, government programs such as Medicare and Medicaid, and multi-employer plans. The plan itself is the covered entity — a distinction that matters enormously for employers and is covered below. Plans with fewer than 50 participants that are self-administered by the employer are generally excluded.
Healthcare providers
Any provider who furnishes, bills or is paid for healthcare and transmits health information electronically for a covered transaction. That covers hospitals, physician and dental practices, clinics, pharmacies, nursing homes, chiropractors, psychologists and telehealth providers. Size is irrelevant — a solo practitioner submitting electronic claims is as covered as a hospital system.
Healthcare clearinghouses
Organizations that translate health information between formats — converting non-standard data into standard transactions or the reverse. Billing services and value-added networks often fall here. It is the smallest of the three categories and the least commonly encountered.
Business associates and their subcontractors
A business associate is anyone handling PHI to perform a service for a covered entity. The relationship is defined by function, not by industry: a cloud provider hosting clinical records is a business associate; the same provider hosting a marketing site is not.
Two points organizations regularly miss:
- Liability is direct. Since the HITECH Act, business associates answer to regulators themselves rather than only to the covered entity through their contract. A business associate can be investigated and penalized in its own right.
- It flows downstream. A subcontractor that a business associate passes PHI to is itself a business associate, with its own agreement and its own liability. Chains of three or four are common in SaaS and each link needs an agreement.
The signed business associate agreement is the mechanism, but signing one does not by itself create or remove the status — the function does. Organizations sometimes sign a BAA “to be safe” and inadvertently accept obligations they had no need to take on.
Does HIPAA apply to employers?
Usually not — and this is the most misunderstood question in the whole area. An employer acting as an employer is not a covered entity, and health information it holds in that capacity is expressly excluded from the definition of protected health information. Employment records held by a covered entity in its role as employer are carved out of PHI by definition.
So sick notes, occupational health results, fitness-for-duty assessments, accommodation requests and workers’ compensation records held in an HR file are generally not PHI. They are frequently confidential under other law — but not under HIPAA.
The exception is what the employer sponsors:
| Scenario | HIPAA status | What it means in practice |
|---|---|---|
| HR holds a doctor’s note for sick leave | Not PHI | Employment record. Confidential under ADA and state law, not HIPAA |
| Employer requests a fitness-for-duty exam | Not PHI in the employer’s hands | The provider’s own record is PHI; the copy in the HR file is not |
| Workers’ compensation records | Largely outside HIPAA | Disclosure to comply with workers’ comp law is permitted |
| Employer sponsors a self-insured group health plan | The plan is a covered entity | Plan data must be firewalled from employment decisions; plan administration needs safeguards |
| Employer sponsors a fully insured plan and receives only summary data | Limited obligations | Reduced requirements where the employer receives only summary health information and enrolment data |
| Employer operates an on-site clinic that bills electronically | Likely a covered entity | The clinic is a provider; its records are PHI and must be separated from HR |
| Wellness program run through the group health plan | Plan data is PHI | The same program run outside the plan usually is not — structure determines status |
The practical failure mode is the firewall. An employer that sponsors a self-insured plan has legitimate access to plan data for administration and no right to use it in employment decisions. Where the same person handles both roles without separation, the organization has a problem that is both a HIPAA issue and an employment-law issue at once.
Who HIPAA does not apply to
- Most employers, in their employer capacity, as above.
- Life, disability and most auto insurers — they hold extensive health information and are not covered entities.
- Consumer health and fitness apps that are not operating on behalf of a covered entity, including most wearables and direct-to-consumer testing.
- Schools and universities, whose student health records are generally governed by FERPA rather than HIPAA.
- Workers’ compensation carriers and most state workers’ comp administration.
- Law enforcement agencies receiving health information under legal process.
- Individuals discussing their own health, or someone else’s — HIPAA binds organizations, not private conversation.
What applies when HIPAA does not
Falling outside HIPAA is not the same as being unregulated, and organizations that stop investigating at “we’re not a covered entity” frequently miss the law that actually binds them:
- The FTC’s Health Breach Notification Rule reaches consumer health apps and connected devices outside HIPAA, with breach notification obligations of its own.
- State privacy laws, several of which now treat health data as a sensitive category requiring consent, and some of which regulate consumer health data specifically.
- The ADA requires employee medical information to be kept confidential and stored separately from personnel files.
- GINA restricts the collection and use of genetic and family medical history information by employers.
- FERPA for student records.
- Contractual obligations — customers increasingly impose HIPAA-equivalent terms on vendors who are not legally covered.
How to determine your status
- Do you furnish, bill for or get paid for healthcare, and transmit health information electronically for covered transactions? If yes, you are a covered provider.
- Do you provide or administer health coverage? If yes, the plan is a covered entity — including a self-insured plan you sponsor.
- Do you translate health data between standard and non-standard formats for others? If yes, you are a clearinghouse.
- Do you handle PHI to perform a function for someone in categories 1 to 3? If yes, you are a business associate regardless of your industry — and so is any subcontractor you pass it to.
- If none apply, identify what does. Work through state privacy law, the FTC rule, ADA, GINA and your customer contracts before concluding you have no obligations.
- Re-check when the business changes. Adding a telehealth line, an on-site clinic, a self-insured plan or a healthcare customer can move you across the boundary without anyone noticing.
What being covered actually obliges you to do
If you land inside HIPAA, the obligations divide across three rules:
- The Privacy Rule — permitted uses and disclosures, minimum necessary access, a notice of privacy practices, and individual rights of access, amendment and accounting.
- The Security Rule — administrative, physical and technical safeguards for electronic PHI, built on a documented risk analysis. This is the rule currently being updated, and the proposed revisions would make several previously addressable specifications mandatory.
- The Breach Notification Rule — notification to individuals, HHS and in larger breaches the media, within defined timeframes.
Business associates carry the Security Rule in full plus much of the Privacy Rule, and both parties need the agreement in place before PHI moves.
Where Compyl fits
Most organizations that carry HIPAA obligations carry others alongside them — SOC 2 for enterprise customers, ISO 27001 for international ones, PCI DSS if they take payment. The underlying controls overlap heavily: access management, encryption, logging, vendor oversight and incident response satisfy all of them with different evidence labels. Compyl maps one control library across 70+ frameworks so a control is written once and proves itself against the HIPAA Security Rule, SOC 2 and ISO 27001 simultaneously, with business associate agreements and vendor status tracked in one register rather than a spreadsheet.
See how one access control satisfies HIPAA, SOC 2 and ISO 27001 at the same time in a 20-minute walkthrough — request a demo, or read the complete guide to HIPAA compliance for the requirement detail.
Frequently asked questions
Who does HIPAA apply to?
Three types of covered entity – health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically for covered transactions – plus the business associates that handle protected health information on their behalf, and any subcontractors those business associates use.
Does HIPAA apply to employers?
Generally no. An employer acting as an employer is not a covered entity, and health information held in employment records is expressly excluded from the definition of protected health information. However, a group health plan the employer sponsors is usually a covered entity, so plan data must be kept separate from employment decisions.
What is a covered entity under HIPAA?
A health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with covered transactions such as claims or eligibility checks. Size is irrelevant – a solo practitioner billing electronically is covered.
What is the difference between a covered entity and a business associate?
A covered entity is regulated because of what it is – a plan, clearinghouse or electronically-billing provider. A business associate is regulated because of what it does: handling PHI to perform a function on a covered entity’s behalf. Business associates carry direct liability to regulators, not merely contractual liability.
Is a doctor’s note in an HR file protected by HIPAA?
No. Employment records held by an employer, including a covered entity acting as an employer, are excluded from protected health information. The note is likely confidential under the ADA and state law and must generally be stored separately from the personnel file, but that obligation does not come from HIPAA.
Are health apps and fitness trackers covered by HIPAA?
Usually not, unless they operate on behalf of a covered entity. Consumer health apps typically fall under the FTC’s Health Breach Notification Rule and state consumer health privacy laws instead, which carry their own breach notification and consent requirements.
Does HIPAA apply to a self-insured employer health plan?
Yes. A self-insured group health plan is a covered entity in its own right. The sponsoring employer must firewall plan information from employment decision-making, restrict which staff can access it, and apply appropriate safeguards to plan administration functions.
What happens if HIPAA does not apply to my organization?
Check what does. State privacy laws increasingly treat health data as sensitive, the FTC Health Breach Notification Rule covers consumer health apps, the ADA and GINA govern employee medical and genetic information, FERPA covers student records, and customer contracts frequently impose HIPAA-equivalent terms.
Sources: HIPAA Privacy, Security and Breach Notification Rules; the definitions at 45 CFR 160.103, including the exclusion of employment records from protected health information; HITECH Act provisions on business associate liability. This is general information, not legal advice — confirm your status with counsel.
Related: Compyl’s HIPAA compliance software maps the Security and Privacy Rule safeguards to live evidence, so your program stays audit-ready year-round.