Remedora
Start building
Remedora
Start building
ARTICLE

Who Does HIPAA Apply To? Covered Entities, Business Associates, and Everyone Else

HIPAA applies to covered entities and business associates, and to almost nobody else. Where the line sits, who is exempt, and when a D2C health brand crosses it.

RRemedoraRemedora Editorial
August 8, 2026 8 min read
ARTICLE

Who Does HIPAA Apply To? Covered Entities, Business Associates, and Everyone Else

HIPAA applies to covered entities and business associates, and to almost nobody else. Where the line sits, who is exempt, and when a D2C health brand crosses it.

RRemedoraRemedora Editorial
August 8, 2026 8 min read

HIPAA might be the most confidently misquoted law in America. It gets invoked at pharmacy counters, at school board meetings, and in comment sections, usually against someone it does not bind.

The actual scope is narrow. HIPAA applies to two groups: covered entities and business associates. If you are neither, the law does not regulate you, no matter how much health information passes through your hands. That one fact settles most internet HIPAA arguments. It also sets a trap for D2C health founders, because the moment a wellness brand adds a licensed provider, it crosses from one side of the line to the other, and most of the marketing stack crosses with it.

Here is where the line actually sits.

The short answer: covered entities and business associates

HIPAA’s Privacy and Security Rules bind exactly two kinds of organizations:

  • Covered entities: health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically for billing and related transactions.
  • Business associates: companies that create, receive, maintain, or transmit protected health information (PHI) while doing work for a covered entity. Think billing firms, cloud hosts, telehealth platforms, and e-prescribing vendors.

That is the whole list. Your employer, your fitness app, and the influencer discussing her diagnosis on TikTok all sit outside it. So do you when you talk about your own health, which you may do as loudly as you like.

Covered entities: the three categories

The definitions live at 45 CFR 160.103, and HHS maintains a plain-English covered entities page that walks through each one.

Health plans: insurance companies, HMOs, Medicare, Medicaid, and employer-sponsored group health plans. Note the split here: the group health plan is covered, while the employer that sponsors it is not, at least in its role as employer.

Healthcare clearinghouses: intermediaries that convert nonstandard health data into standard billing formats. Unless you run one, you will mostly encounter them as a line item in someone else’s data flow.

Healthcare providers: doctors, clinics, pharmacies, labs, dentists, therapists. With a wrinkle that surprises people: a provider is covered only if it transmits health information electronically in connection with transactions HHS has adopted standards for, which mostly means billing insurance. A cash-only therapist who never submits an electronic claim can sit outside HIPAA entirely.

In telehealth, that wrinkle is close to academic. The medical groups behind D2C health brands e-prescribe, verify eligibility, and move claims-shaped data constantly. Treat any real clinical operation as covered.

Business associates: the vendors doing PHI work

A business associate is any person or company that handles PHI to perform a service for a covered entity. HHS’s business associate guidance lists the classic examples: claims processing, billing, data analysis, cloud storage, transcription, even a law firm reviewing patient files.

Two things founders tend to learn late:

  • The BAA obligation flows downhill: a covered entity must sign a business associate agreement with every vendor that touches PHI, and those vendors must sign BAAs with their own subcontractors. The chain does not stop at the first hop.
  • Business associates carry direct liability: since the 2013 Omnibus Rule, HHS’s Office for Civil Rights can fine a business associate directly for Security Rule failures and improper disclosures. “We were just the vendor” stopped working as a defense over a decade ago.

Who HIPAA does not apply to

This is where most of the folklore lives. HHS’s own consumer guidance lists organizations that have no HIPAA obligations at all, and the list is longer than most people expect.

Employers

Your boss can ask for a doctor’s note. Employment records held by an employer are excluded from the definition of PHI even when they contain health information, so requesting or holding that note does not violate HIPAA. Other laws, like the ADA and FMLA, govern what an employer does with medical information. HIPAA is simply the wrong statute to cite.

Most health apps and wearables

A fitness tracker, a period tracker, a sleep app: none of these are covered by HIPAA unless they are offered on behalf of a provider or health plan. Consequences still exist, just under different law. The FTC’s Health Breach Notification Rule covers many consumer health apps, which is how GoodRx ended up paying a $1.5 million penalty in February 2023 for sharing user health data with advertising platforms. That was the FTC’s first enforcement action under the rule, and GoodRx was never a HIPAA covered entity.

People discussing health, including yours

Influencers, journalists, podcasters, your neighbor: HIPAA restricts what covered entities and their business associates disclose, and nobody else. A stranger repeating your diagnosis may be a jerk, and in some cases a defamation defendant, but they are not a HIPAA violator. The same logic runs in your favor: nothing in HIPAA stops you from sharing your own records anywhere you want.

A short list of other exempt parties

Per that same HHS guidance: life insurers, workers’ compensation carriers, most schools and school districts (FERPA governs student records), many state agencies, and most law enforcement agencies.

When a D2C health brand crosses into covered territory

Now the part that matters for operators.

A wellness brand selling supplements with a symptom quiz sits outside HIPAA. The FTC and state consumer-protection laws still police your claims and your data practices, but nobody needs a BAA.

Add a licensed provider who evaluates patients and prescribes, and the ground shifts underneath the whole company:

  • The medical group becomes a covered entity: it diagnoses, prescribes, and transmits health information electronically, which checks every box in the definition.
  • Your brand typically becomes a business associate: if your company handles intake responses, patient support tickets, or order data tied to prescriptions on the medical group’s behalf, you need a BAA and you carry direct liability for the PHI you hold.
  • So does every vendor in the data path: the email platform holding intake answers, the help desk reading patient messages, the analytics tool watching the funnel. Mainstream e-commerce marketing tools generally will not take on that role; Klaviyo and Mailchimp both state they are not HIPAA compliant. And OCR’s December 2022 bulletin on tracking technologies warned that ad pixels on scheduling and intake pages can transmit PHI to ad platforms.

Vendor sprawl is what makes this expensive. Five tools touching PHI means five BAAs, five security reviews, and five vendors who can each put the medical group’s compliance at risk. This is the main argument for consolidation: Remedora runs the storefront, funnels, intake, licensed providers in all 50 states and Puerto Rico, e-prescribing, pharmacy fulfillment, payments, and support under a single BAA, from $200 per month. One agreement to review instead of a stack of them. If you are weighing that route, start with what a HIPAA-compliant telehealth platform actually has to cover.

A practical checklist for deciding whether HIPAA applies to you

Run your business through these five questions:

  1. Check for electronic billing: do you, or does a provider inside your operation, bill health plans electronically? If yes, there is a covered entity in the picture.
  2. Check for clinical activity: does a licensed provider diagnose, treat, or prescribe anywhere in your funnel? If yes, same answer, even when the provider belongs to a partner medical group rather than your own company.
  3. Check your own data handling: do you store or transmit identifiable patient information for that provider? Intake answers, visit status, prescription details, support conversations all count. If yes, you are likely a business associate: sign a BAA and meet the Security Rule.
  4. Check your vendors: does any subcontractor touch the same data? Their BAAs are your problem too.
  5. Confirm the wellness case: purely consumer wellness, no providers, no insurance billing? HIPAA does not apply, though the FTC’s breach rule and state privacy laws still do.

If you land in covered territory, the follow-up work is an inventory: every system that touches PHI, every agreement covering it, every gap between the two. HIPAA compliance software exists to track exactly that paperwork, and a consolidated platform shrinks the inventory before you start.

FAQ

Who must comply with HIPAA?

Covered entities (health plans, healthcare clearinghouses, and providers that bill electronically) and their business associates, meaning any vendor that handles PHI on a covered entity’s behalf. Nobody else has HIPAA obligations, though other privacy laws may still apply.

Does HIPAA apply to employers?

No, not in their role as employers. Employment records fall outside the definition of PHI even when they contain health information. An employer-sponsored group health plan is covered; the employer itself is not.

Does HIPAA apply to health apps and fitness trackers?

Usually not. A consumer app is only covered when it operates on behalf of a provider or health plan. Many otherwise-uncovered apps answer to the FTC’s Health Breach Notification Rule instead, the rule behind the GoodRx penalty in 2023.

Does HIPAA apply to everyone who sees my medical information?

No. It binds the clinic, the insurer, and their vendors. A coworker, a reporter, or a family member who repeats what they know about your health is outside HIPAA’s reach, and you are always free to share your own information.

For the wider view of how HIPAA shapes a telehealth operating model, read HIPAA Explained. If you are already evaluating vendors, the HIPAA telehealth platform checklist covers the BAA, audit-log, and subprocessor questions to ask before you sign.

Ready to build yours?Storefront, doctors, pharmacy, and payments are already wired together. Start building today
R RemedoraRemedora EditorialRemedora is the all-in-one telehealth platform for e-commerce health brands: storefront, intake, licensed providers, pharmacy, and payments in one system.

Keep reading

All articles →
Remedora pill mascot

Launch your telehealth brand
this week.

Storefront, doctors, pharmacy, payments, and compliance, included and ready. The only thing missing is your brand.

LegitScript Certified
HIPAA COMPLIANT · BAA
© 2026 Remedora Inc.