Back to HIPAA

Who Does HIPAA Apply To? A Decision Guide for HealthTech and SaaS Founders

Who does HIPAA apply to illustration: health plans, clearinghouses, providers and business associates connected to a protected system

Short answer: HIPAA applies directly to three types of covered entities: health plans, health care clearinghouses and health care providers that conduct standard electronic transactions. It also applies to business associates, meaning vendors that create, receive, maintain or transmit protected health information on a covered entity's behalf, and to their subcontractors. Many consumer apps fall outside it.

Related guides:

Key takeaways

  • HIPAA is not triggered by "having health data." It is triggered by who you are (a covered entity) or who you work for (a covered entity or another business associate).
  • The definitions that decide this live in 45 CFR 160.103: covered entity, health plan, health care clearinghouse, health care provider, business associate and protected health information.
  • A SaaS vendor becomes a business associate when it handles PHI on behalf of a covered entity. Storing encrypted PHI without the key still counts.
  • Subcontractors of business associates are business associates too, so HIPAA obligations flow down the vendor chain.
  • Many direct-to-consumer health apps are outside HIPAA, but may be subject to the FTC Health Breach Notification Rule and state health privacy laws.

Which organizations are HIPAA covered entities?

There are exactly three kinds of covered entity, and each is defined in 45 CFR 160.103.

Covered entity type What it includes Founder-relevant notes
Health plan Individual and group plans that provide or pay for medical care: health insurers, HMOs, Medicare, Medicaid, employer-sponsored group health plans A group health plan with fewer than 50 participants that is administered solely by the employer that sponsors it is excluded
Health care clearinghouse Entities that process health information from a nonstandard format into a standard one, or the reverse Billing services and repricing companies can qualify if they perform this conversion
Health care provider Providers of medical or health services (physicians, clinics, hospitals, dentists, therapists, pharmacies, labs) that transmit health information electronically in connection with a HIPAA standard transaction A provider who never conducts standard transactions, directly or through a billing agent, is not a covered entity

The provider test is the one founders most often get wrong. "Standard transactions" are the electronic transactions adopted under 45 CFR Part 162, such as claims, eligibility inquiries, claim status, remittance advice, referral authorizations, and enrollment. A clinic that bills insurers electronically, even through a billing company acting on its behalf, is a covered entity. A cash-only practice that never submits electronic claims generally is not, although state law may still regulate its records.

When does HIPAA apply to a vendor or SaaS company?

HIPAA applies to a vendor when it creates, receives, maintains or transmits PHI on behalf of a covered entity, or performs certain services for one that involve PHI. That makes it a business associate under 45 CFR 160.103.

Typical business associate functions include claims processing, data analysis, utilization review, quality assurance, billing, practice management, and legal, accounting, consulting or data aggregation services. For HealthTech, that covers most B2B products sold to providers and payers:

  • An EHR, patient portal or telehealth platform used by a clinic.
  • A revenue cycle, scheduling or patient messaging tool.
  • An analytics or AI vendor that processes a hospital's patient data.
  • A cloud hosting provider storing ePHI, even when the data is encrypted and the provider does not hold the key.

Subcontractors. A subcontractor that handles PHI on behalf of a business associate is itself a business associate. If your platform runs on a cloud provider, sends PHI to a transcription vendor, or uses a support tool that stores patient messages, those vendors are your subcontractors. You need a written agreement with each, as covered in our guide to the business associate agreement.

Direct liability. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for complying with the Security Rule and for certain Privacy Rule and Breach Notification Rule obligations. A missing BAA does not remove that liability. Status follows the activity, not the paperwork.

The narrow conduit exception. Entities that only transport information and have transient access, such as a postal service or an internet service provider, are generally not business associates. HHS treats this exception narrowly. A service that stores PHI, even temporarily beyond transmission, usually does not qualify.

Who does HIPAA not apply to?

HIPAA does not apply to organizations that are neither covered entities nor acting on behalf of one, even when they handle sensitive health information.

Common examples:

  • Many consumer health apps. A fitness tracker, symptom diary or period tracker that a person downloads and uses on their own is generally not a business associate, because it is not acting on behalf of a covered entity. HHS guidance on the access right, health apps and APIs also indicates that an app the patient chooses to receive their records is not the provider's business associate. For a broader overview, see what HIPAA compliance means.
  • Employers acting as employers. Employment records held by an employer, such as sick notes or drug test results in an HR file, are excluded from the definition of PHI. The employer's group health plan is a covered entity, and the employer as plan sponsor faces restrictions on what plan PHI it can receive.
  • Life insurers and certain other insurers. Life insurance, disability income, workers' compensation, auto medical payment and similar coverage are generally outside the definition of a health plan.
  • Organizations holding only de-identified data. Data de-identified under 45 CFR 164.514 is not PHI.
  • Schools, for FERPA records. Education records covered by FERPA are excluded from PHI.

Not covered by HIPAA does not mean unregulated. See the section on rules that apply outside HIPAA.

What is a HIPAA hybrid entity?

A hybrid entity is a single legal entity that performs both covered and non-covered functions and chooses to designate its health care components (45 CFR 164.103 and 164.105).

A university with a student health clinic is a typical example. Most HIPAA requirements then apply only to the designated components, which must keep PHI from flowing freely to the rest of the business. This rarely affects startups, but it can matter if one legal entity runs both a clinical practice and a separate software line.

Does HIPAA apply to my company? A step-by-step test

Work through these steps in order for each product and each customer relationship. If step 1 shows no identifiable health information is involved, stop there. Otherwise: if you answer yes to step 2, 3 or 4, you are a covered entity, and you should still check steps 5 and 6, because a covered entity can also act as a business associate for others. If steps 2 to 6 are all no, go to step 7.

  1. Do you handle individually identifiable health information at all? If you only see de-identified or truly aggregate data, HIPAA likely does not apply to that data flow. Confirm de-identification meets 45 CFR 164.514.
  2. Are you a health plan? If you provide or pay for medical care as an insurer, HMO or group health plan, you are a covered entity.
  3. Are you a health care clearinghouse? If you convert health data between nonstandard and standard transaction formats, you are a covered entity.
  4. Are you a health care provider? If you furnish health care and you, or someone on your behalf, conducts standard electronic transactions, you are a covered entity. If you never conduct them, you are not a covered entity on this basis.
  5. Do you handle PHI on behalf of a covered entity? If a provider, plan or clearinghouse is your customer and your service involves their PHI, you are a business associate. You need a BAA and a Security Rule program.
  6. Do you handle PHI on behalf of a business associate? If your customer is itself a business associate and you touch the PHI it handles, you are a subcontractor business associate.
  7. None of the above? HIPAA likely does not apply to that data flow. Now check the FTC Health Breach Notification Rule, the FTC Act and state health privacy laws.

Repeat per relationship. A consumer product and a provider-facing product from one company can land in different places. Document the outcome and revisit it as customers and data sources change.

How does HIPAA apply in common HealthTech scenarios?

Use this table as a starting point, then confirm with counsel for your specific contracts and data flows.

Scenario Likely HIPAA status Why
Telehealth platform licensed to clinics that bill insurance Business associate Handles PHI on behalf of covered entity providers
Cash-pay telehealth practice that never submits electronic claims Possibly not a covered entity Provider status depends on standard transactions; state law likely applies
Consumer wellness app sold directly to individuals Generally not covered Not acting on behalf of a covered entity; FTC rules may apply
Same app offered by a health plan to its members under contract Business associate Now acting on behalf of a covered entity
Cloud provider hosting a SaaS vendor's ePHI Subcontractor business associate Maintains PHI on behalf of a business associate
Analytics vendor receiving only de-identified data Generally not covered for that data De-identified data is not PHI
Employer HR team holding employee sick notes Not covered for those records Employment records are excluded from PHI
Benefits broker or TPA administering a self-funded group health plan Business associate of the plan Performs plan functions involving PHI
Life insurer reviewing medical records for underwriting Not a covered entity Life insurance is not a health plan under HIPAA
Medical billing company converting claims into standard format Clearinghouse or business associate Depends on whether it performs format conversion

The "possibly" and "generally" rows are where founders get into trouble. Our HIPAA compliance for startups guide covers how to structure an early program.

What rules apply if HIPAA does not?

If HIPAA does not apply, your health data can still be regulated by the FTC and by state law.

  • FTC Health Breach Notification Rule (16 CFR Part 318). It covers vendors of personal health records and related entities that are not subject to HIPAA. The FTC amended the rule in 2024, effective July 29, 2024, to make clear that it can apply to many health apps and similar technologies, and that unauthorized disclosures, not only security breaches, can be notifiable events. If it applies, you may need to notify affected individuals, the FTC and, in some cases, the media.
  • FTC Act Section 5. Deceptive or unfair handling of health data, such as sharing it with advertisers contrary to your privacy promises, can lead to enforcement whether or not HIPAA applies.
  • State laws. Several states regulate health data more broadly than HIPAA. Examples include Washington's My Health My Data Act and California's Confidentiality of Medical Information Act, and some states define covered entities more broadly than federal law. Coverage, definitions and private rights of action vary by state, so review the states where your users live with counsel.
  • Contracts. Healthcare customers often require a BAA or security attestation even when HIPAA arguably does not apply.

For incident planning, compare these obligations with the HIPAA Breach Notification Rule, because timelines and recipients differ.

How SecureSlate helps

Once you know where HIPAA applies, SecureSlate helps you turn that scope into an operating program. You can document your HIPAA scope decision alongside the controls that follow from it, using a control library mapped to HIPAA and other frameworks. Policy management helps you keep HIPAA policies current and acknowledged, and vendor risk management helps you track the subcontractors that touch PHI and the status of their BAAs.

Start your free SecureSlate trial

FAQ

Does HIPAA apply to my company if we only store encrypted data?

Usually yes, if the data is PHI and you store it on behalf of a covered entity or business associate. HHS guidance on cloud computing says a provider that maintains encrypted ePHI is a business associate even without access to the encryption key.

Can we avoid HIPAA by not signing a BAA?

No. Business associate status depends on what you do with PHI, not on whether a contract exists. Operating without a required BAA is itself a compliance gap for both parties.

Are HIPAA covered entities only in the United States?

HIPAA is a US law and applies to covered entities and business associates as defined. A non-US vendor that handles PHI on behalf of a US covered entity can still be a business associate and will usually be asked to sign a BAA.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Oct 2, 2026 · HIPAA

HIPAA Compliant Texting: When You Can Text Patients and How to Do It Safely

Oct 2, 2026 · HIPAA

HIPAA Permitted Uses and Disclosures: When PHI Can Be Shared Without Authorization

Sep 29, 2026 · HIPAA

After SOC 2: The Compliance Roadmap for HealthTech Companies

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?