Skip to content
StudyDex
Health & Medicine

The HIPAA Privacy Rule Applies to Which of the Following?

Quick answer

The HIPAA Privacy Rule applies to covered entities — health plans, health care clearinghouses, and health care providers who transmit health information electronically — plus their business associates who handle protected health information on their behalf.

The answer

The HIPAA Privacy Rule applies to covered entities and their business associates. There are exactly three types of covered entities:

  1. Health plans — health insurers, HMOs, company health plans, and government programs like Medicare and Medicaid that pay for health care.
  2. Health care clearinghouses — organizations that process nonstandard health information into standard formats (or vice versa), such as billing services and repricing companies.
  3. Health care providers who transmit health information electronically in connection with a HIPAA transaction (for example, billing an insurer electronically). This includes doctors, clinics, hospitals, dentists, pharmacies, and psychologists — if they transmit any covered information electronically.

In addition, the Rule reaches business associates — vendors and contractors (billing companies, IT providers, cloud hosts, attorneys, transcription services) that create, receive, maintain, or transmit protected health information (PHI) on a covered entity's behalf. They are bound through a business associate agreement.

So if an exam option lists "health plans, health care clearinghouses, and providers who transmit health data electronically," that is the correct answer.

Who is NOT covered

This is where students trip up. HIPAA is not a general medical-privacy law that covers everyone who touches health information. It does not apply to:

  • Employers acting as employers — your boss holding your sick-note is not a covered entity (though a company's health plan is).
  • Life insurers, workers' compensation carriers, and most schools (student health records fall under FERPA, not HIPAA).
  • Fitness apps, wearables, and many health websites that you share data with directly and that are not acting for a covered entity.
  • Law enforcement and most marketing firms.
  • A provider who does no electronic transactions at all (rare today, but technically outside the transaction trigger).

Because HIPAA is scoped to the health-care payment-and-treatment ecosystem, an answer choice like "anyone who holds someone's health information" is wrong — the Rule is deliberately narrower than that.

The bigger picture

The Privacy Rule protects protected health information (PHI) — individually identifiable health information held or transmitted by a covered entity or business associate, in any form (electronic, paper, or oral). The whole architecture flows from a single question: is this organization a covered entity, a business associate, or neither? If neither, HIPAA simply does not reach it — even if it is handling sensitive health data. That is why two people can hold the exact same lab result, and one (your clinic) is bound by HIPAA while the other (a diet app you emailed it to) is not. Keeping the three covered-entity categories and the business-associate extension straight — and remembering the electronic-transaction trigger for providers — is the core of answering this question correctly.

Walk the decision
  1. 1

    Are you a health plan, clearinghouse, or health care provider?

    Health plans, clearinghouses, and providers are the three covered-entity categories. If none of these, go to the business-associate check.

  2. 2

    If a provider: do you transmit health info electronically for a HIPAA transaction?

  3. 3

    Not a covered entity? Do you handle PHI on a covered entity's behalf?

  4. 4

    Neither of the above?

Frequently asked

What are the three types of covered entities under HIPAA?

Health plans (insurers and programs like Medicare/Medicaid), health care clearinghouses (which convert data into standard formats), and health care providers who transmit health information electronically in connection with a HIPAA transaction such as electronic billing.

Who is not covered by the HIPAA Privacy Rule?

Employers acting as employers, life insurers, workers' compensation carriers, most schools (covered by FERPA instead), law enforcement, and consumer health apps or wearables you share data with directly. HIPAA only reaches covered entities and their business associates.

What is a business associate under HIPAA?

A business associate is a person or company that creates, receives, maintains, or transmits protected health information on behalf of a covered entity, such as billing firms, IT and cloud providers, or transcription services. They are bound by a business associate agreement.

What information does the HIPAA Privacy Rule protect?

It protects protected health information (PHI): individually identifiable health information held or transmitted by a covered entity or business associate in any form, whether electronic, paper, or spoken. This includes diagnoses, treatment, and payment information tied to an individual.

Does HIPAA apply to employers?

Not to employers acting as employers. An employer holding your sick note or medical documentation for HR purposes is not a covered entity. However, a company-sponsored group health plan is a covered entity and must follow HIPAA.

Start freeLog in