Who Does HIPAA Apply To? Covered Entities Explained
Who must comply with HIPAA — and who doesn
Who Does HIPAA Apply To? Covered Entities & BAs
Who must comply with HIPAA — and who doesn't. Covered entities, business associates, and edge cases for sober living, cash-pay, and SUD programs.
Quick Facts
- Category
- Federal Compliance
- Published
- Jun 12, 2026
- Reading Time
- 9 min
Need compliance help?
HIPAA applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with standard transactions — plus their business associates, the vendors that handle protected health information on their behalf. It does not apply to everyone: employers, most schools, life insurers, and consumer wellness apps generally fall outside it.
That is the answer. The rest of this page explains each category, who falls outside HIPAA entirely, and the behavioral health edge cases — sober living homes, cash-pay practices, recovery coaches — where generic guides go silent. (General information, not legal advice: applicability determinations are fact-specific, and the edge cases below deserve a conversation with counsel.)
The Three Types of Covered Entities
HHS defines covered entities at 45 CFR 160.102 and 160.103 ↗; the plain-English version of its Covered Entities and Business Associates guidance ↗:
- Healthcare providers — but only if they conduct electronic standard transactions. Doctors, clinics, psychologists, treatment centers, pharmacies, and labs are covered if they transmit health information electronically in connection with a transaction HHS has adopted a standard for — electronic claims, eligibility checks, prior authorization requests, and similar. This conditional is the most misunderstood part of HIPAA: it is the electronic billing activity, not the clinical service, that triggers coverage. And it triggers it once, organization-wide — a provider does not get to be “covered for insurance clients and not covered for cash clients.” BH example: a residential SUD treatment center that bills insurance electronically is a covered entity; the moment its biller submits the first 837 claim, coverage attaches to the whole organization’s PHI.
- Health plans. Insurers, HMOs, Medicaid and Medicare, and employer group health plans. BH example: the managed care organization that administers a state’s behavioral health Medicaid benefit.
- Healthcare clearinghouses. Entities that translate health information between standard and nonstandard formats — the intermediaries sitting between providers and payers. BH example: the claims clearinghouse a treatment center’s billing system routes claims through.
Business Associates: The Second Group
A business associate is a person or company that creates, receives, maintains, or transmits PHI on behalf of a covered entity: billing companies, EHR and software vendors, IT and cloud hosting providers, answering services, shredding companies, attorneys and accountants who receive PHI, and analytics vendors.
Three things operators should know:
operates as a business associate to its treatment-provider customers and signs BAAs accordingly.
- A business associate agreement (BAA) is mandatory before PHI flows to the vendor. The contract obligates the vendor to safeguard the data and report breaches.
- Business associates carry direct liability. Since the 2013 Omnibus Rule, business associates are directly subject to the Security Rule, parts of the Privacy Rule, and OCR enforcement — not just contract liability to their covered-entity customer.
- The chain keeps going. A business associate’s subcontractors that touch PHI become business associates themselves and need their own BAAs — the billing startup that outsources data entry, the EHR vendor’s hosting provider. If you run a BH-adjacent services business, assume that signing your first BAA with a treatment center pulls you (and your subcontractors) into the HIPAA enforcement perimeter.
So Does HIPAA Apply to Everyone? (No — Here’s Who It Doesn’t Cover)
No. HIPAA is not a general medical-privacy law; it regulates specific entity types. Commonly assumed-covered parties that generally are not:
The practical error runs both directions: operators assume HIPAA covers everything (it doesn’t), and adjacent businesses assume “we’re not covered” ends the privacy analysis (it doesn’t — state law, contracts, and Part 2 keep going).
- Employers acting as employers. Sick notes, drug-test results in an HR file, FMLA paperwork — employment records are excluded from PHI even when they contain health information. (The employer’s group health plan is a different story — it is a covered entity.)
- Most schools. Student health records at schools that receive federal education funding are typically governed by FERPA, not HIPAA, per joint HHS/ED guidance ↗.
- Life insurers, workers’ compensation carriers, and disability insurers. Excluded from the health-plan definition.
- Direct-to-consumer fitness apps and wearables. A mood tracker or step counter you download yourself is not a covered entity — though the FTC’s Health Breach Notification Rule may apply to it.
- Friends, family, and gossip. Private individuals are not regulated by HIPAA at all.
”HIPAA Applies to Groups Of…” — The Training-Quiz Answer
If your compliance training quiz asks “HIPAA applies to groups of ___,” the answer it wants is: covered entities and their business associates — specifically the three covered-entity types (healthcare providers conducting electronic standard transactions, health plans, and healthcare clearinghouses) plus the business associates that handle PHI for them.
Behavioral Health Edge Cases (The Part Generic Guides Skip)
These are the applicability questions BH operators actually ask, each hedged the way the analysis deserves. None of these is a definitive legal determination — coverage turns on the specific facts, and HHS’s guidance (including the CMS covered entity decision tool ↗ ) is the starting reference.
Sober living homes and recovery residences. A residence that provides housing, structure, and peer support — but no clinical services billed to insurance — is generally not a covered entity: no healthcare provision plus no electronic standard transactions means no coverage trigger. But the analysis rarely ends there. A residence that is also an IOP, employs clinicians, or bills Medicaid for any service can be covered. A residence handling resident records on behalf of a treatment provider may be that provider’s business associate, BAA and all. And state confidentiality and landlord-tenant privacy laws apply regardless. Operate to a privacy standard even when HIPAA doesn’t compel one — referral partners increasingly require it contractually.
Cash-pay-only therapy practices. A therapist who takes no insurance and never transmits a standard transaction electronically — no e-claims, no electronic eligibility checks, not even one courtesy claim — is generally not a covered entity. Three cautions: a single electronic claim (including via a billing service on your behalf) flips the switch; superbills handed to clients who self-file generally don’t, but the line is fact-specific; and state licensing boards’ confidentiality rules bind you regardless. Most cash-pay practices adopt HIPAA-grade safeguards anyway: it is the de facto professional standard, and clients ask.
Recovery coaches and peer-support organizations. Standalone coaching with no clinical services and no insurance billing generally sits outside HIPAA. But peer organizations embedded in covered providers’ workflows — receiving referral records, documenting in a provider’s EHR — typically function as business associates or workforce members, which brings obligations with it.
Interventionists and referral marketers. Usually not covered entities — but routinely handling deeply sensitive information with no federal privacy rule attached, which is precisely why treatment centers should bind them with contracts, and why referral-fee arrangements raise separate legal issues (EKRA and state patient-brokering laws) beyond privacy.
Billing startups and BH software vendors. Companies built to serve treatment providers — billing services, EHR and CRM platforms, analytics tools, answering services — are almost always business associates rather than covered entities (unless they also function as clearinghouses, which converts them into covered entities in their own right). The practical consequence: Security Rule safeguards, breach reporting obligations, and direct OCR exposure attach from the first customer, and sophisticated treatment-center buyers will ask for the BAA and a security questionnaire before the contract is signed.
SUD programs: the Part 2 overlay. Even when a program’s HIPAA status is ambiguous, 42 CFR Part 2 can apply independently if the program is federally assisted — a test that reaches further than operators expect (it includes, for example, holding DEA registration to dispense controlled substances or tax-exempt status). Run the Part 2 analysis separately; do not assume “not a covered entity” means “no federal confidentiality rule.”
Covered or Not, Here’s What You Should Do
Whichever bucket you land in, the infrastructure answer looks similar: keep client records in a system with access controls and audit trails instead of inboxes and spreadsheets. A HIPAA-compliant behavioral health EHR is built for exactly that.
- If you’re a covered entity: you need the full program — risk analysis, policies, training, BAAs, breach response. Start with our HIPAA guide for treatment centers and staff training requirements, and know what violations cost — see our guide to HIPAA violations, examples, and penalties.
- If you’re a business associate: sign and honor BAAs, implement Security Rule safeguards, and report incidents upstream on the contract’s timeline. OCR can enforce against you directly.
- If you’re neither: state confidentiality laws, professional ethics rules, FTC consumer-protection authority, and your contracts still bite — and in SUD work, Part 2 may apply on its own. “Not covered” is the beginning of the privacy analysis, not the end.
Sources
Questions about running a compliant operation at any coverage level? Request a demo to see how handles privacy infrastructure for behavioral health organizations.
- HHS OCR: Covered Entities and Business Associates ↗
- 45 CFR 160.102–160.103 ↗ — applicability and definitions
- CMS: Are You a Covered Entity? ↗ — decision tool
- HHS/ED Joint Guidance on FERPA and HIPAA ↗
- eCFR 42 CFR Part 2 ↗ — SUD confidentiality overlay
This guide is provided for informational purposes only and does not constitute legal, regulatory, or professional advice. Regulations change frequently — always verify current requirements with the relevant state agency or accrediting body. is not a law firm or consulting firm.
See a HIPAA-Compliant EHR
helps behavioral health organizations navigate compliance with confidence.
Common questions
Official sources
- 45 CFR 160.102 and 160.103ecfr.gov
- Covered Entities and Business Associates guidancehhs.gov
- joint HHS/ED guidancehhs.gov
- CMS covered entity decision toolcms.gov
- eCFR 42 CFR Part 2ecfr.gov