Does HIPAA actually apply to you?
Most businesses guess — and guess wrong in both directions. Some spend on rules that don't apply to them. Others are "business associates" who are directly liable and don't know it.
HIPAA applies to you directly — as a covered entity.
As a healthcare provider, health plan, or clearinghouse, you're squarely under HIPAA. That means the full stack: a designated Privacy & Security Officer, a documented Security Risk Analysis, administrative/physical/technical safeguards, signed Business Associate Agreements with every vendor that touches your data, a breach-notification process, and years of retained documentation.
The area OCR cites most often isn't fancy — it's a missing or thin risk analysis. And proposed 2026 updates would make annual risk assessments, encryption, and MFA mandatory rather than "addressable." The bar is rising.
The real question isn't "does it apply" — it's "can you prove you're meeting it if OCR or a breach ever asks." That's a governance and documentation question, which is exactly what I do.
You're likely a "business associate" — and directly liable.
This is the one most businesses miss. If you handle, store, transmit, or even just have health information pass through your systems on behalf of a healthcare client, HIPAA treats you as a business associate — and since the HITECH Act, business associates are directly liable to regulators, not just contractually to your client.
Practically, that means you likely need: a signed Business Associate Agreement with each client (and with any subcontractor you pass data to), safeguards for that data, a breach-notification process (60-day rule), and documentation to prove it. Proposed 2026 rules would even require you to give clients annual written verification that you're compliant — which is fast becoming a condition of winning the contract at all.
Being a business associate without the paperwork and safeguards is one of the most common — and most penalized — HIPAA gaps. Worth a straight conversation about where you actually stand.
HIPAA probably doesn't apply to you — and that's worth knowing.
Based on your answers, you're neither a covered entity nor a business associate, so the federal HIPAA rules likely don't apply to you. That means you shouldn't be spending time or money chasing HIPAA compliance you don't owe — a surprising number of businesses do exactly that.
Two honest caveats worth a moment: first, if you ever start handling health data for a healthcare client, you'd become a business associate the day it begins. Second, some states (Texas is the notable one) define "covered" far more broadly than federal law — so state rules can reach you even when HIPAA doesn't. And separately from HIPAA, you almost certainly still have general data privacy and security obligations worth governing.
This is a quick educational self-check based on the HIPAA definitions of "covered entity" and "business associate" (45 CFR 160.103) — not legal advice or a compliance determination. Your actual status can depend on specific facts and state law. For a formal determination, consult qualified counsel. HHS provides an official covered-entity decision tool at hhs.gov.