Last updated: 2026-08-13 · Jurisdiction: United States (45 CFR Parts 160 and 164)
Do I need HIPAA?
HIPAA status is a classification, not a vibe. You are a covered entity, a business associate, or neither. The definitions live in 45 CFR 160.103. A provider is covered only if it conducts a HIPAA standard transaction electronically. A vendor's status derives from its clients, including the subcontractor chain. This page walks that test. It is not legal advice, and it is not a Business Associate Agreement.
The short version
Health plans and clearinghouses are covered as such. A health care provider is covered only when it (or a billing service acting for it) transmits health information electronically in a HIPAA standard transaction. Everyone else is reached only as a business associate, and only when they create, receive, maintain, or transmit protected health information for a covered entity or another business associate. Hosting counts. The conduit exception almost never does. Direct-to-consumer health data with no provider or plan in the chain is generally an FTC problem, not a HIPAA problem. Then keep ePHI out of tools that have not signed a BAA, including this one.
What “do I need HIPAA?” actually asks
The question is usually three questions stacked on top of each other. Collapsing them produces a policy pack for the wrong organization, or a BAA for a relationship that is not a business-associate function.
- Direct legal classification. Do the HIPAA Rules at 45 CFR Parts 160 and 164 apply to this organization, for this activity, as a covered entity or as a business associate? That is the question this guide answers.
- Contractual flow-down. A customer can require HIPAA-aligned controls, encryption, and a BAA even when your own classification is still open. That is a commercial requirement. It does not, by itself, make you a covered entity.
- Neighboring regimes. State medical-records laws, the FTC Act, the FTC Health Breach Notification Rule, and (for many digital-health startups) SOC 2 still apply when HIPAA does not. Opening only the Security Rule is the wrong first move if you are a consumer app with no covered entity in the chain.
This guide stays on question one. It paraphrases the structure of 45 CFR 160.103 and the related HHS guidance in original wording. It is not legal advice and not a binding determination.
The classification table most “HIPAA checklists” skip
HIPAA does not ask whether health information is sensitive. It asks which 45 CFR 160.103 description you match. Run the row that fits the activity you are assessing. An organization that wears two hats runs the table twice.
| What you are | The test | Result |
|---|---|---|
| Health plan | Provides or pays the cost of medical care (45 CFR 160.103) | Covered entity as such |
| Health care clearinghouse | Converts health information between standard and nonstandard formats for others | Covered entity as such |
| Health care provider | Furnishes, bills, or is paid for health care, and transmits health information electronically in a HIPAA standard transaction (45 CFR 160.102 / 160.103) | Covered entity only if the electronic-transaction trigger is met |
| Vendor to a covered entity or BA | Creates, receives, maintains, or transmits PHI on that client's behalf, including as a subcontractor | Business associate (direct Security Rule and Breach Notification Rule liability) |
| Mere transmission conduit | Transient access only, no maintenance of the data | Not a business associate, if the exception actually fits |
| Direct-to-consumer health product | Consumer gives the data with no provider or plan in the chain | Generally not HIPAA; look at 16 CFR Part 318 and the FTC Act |
Version and jurisdiction stamp: the rows paraphrase 45 CFR 160.102 and 160.103 as currently published on eCFR, plus the HHS cloud-computing guidance for the conduit row and 16 CFR Part 318 for the consumer-product row. State law is not assessed here. Checked 2026-08-13.
How to decide, step by step
- 1
Name the classification you are actually deciding
People ask “do I need HIPAA?” when they mean three different things: am I regulated, must I sign a business associate agreement, or should I run a health-data security program anyway. This page answers the first. Under 45 CFR 160.103 you are a covered entity, a business associate (including a subcontractor of one), or neither. There is no fourth bucket called “we work in health, so probably.” Signing a BAA, or refusing one, does not change the classification. The definition does.
- 2
If you are a health plan or a clearinghouse, you are covered as such
Two of the three covered-entity categories do not get an extra gate. A health plan is an organization that provides or pays the cost of medical care: a health insurer, an HMO, Medicare or Medicaid, and most employer-sponsored group health plans (45 CFR 160.103). A health care clearinghouse converts health information between standard and nonstandard formats for other organizations. If that is what you are, you are a covered entity. Stop guessing. One carve-out people mix in: employment records an employer holds in its role as employer are not protected health information. The group health plan is a separate legal person from the employer that sponsors it.
- 3
If you are a provider, apply the electronic-transaction trigger
This is the line most clinics get wrong. Furnishing, billing, or being paid for health care makes you a health care provider. It does not, by itself, make you a covered entity. The provider is covered only if it transmits health information in electronic form in connection with a transaction for which HHS has adopted a standard (45 CFR 160.102 and 160.103): claims, eligibility checks, prior authorizations, claim status, remittance, enrollment, premium payment, coordination of benefits. A billing service or clearinghouse that submits those transactions for you counts. A cash-only practice that never bills an insurer electronically may sit outside the definition. The carve-out is narrow and fragile. One electronic standard transaction changes the answer, and state medical-records law applies either way.
- 4
If you are a vendor, derive status from your clients
Vendor status is not a brand decision. It is a client decision. A business associate is a person or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity, or that provides services involving that information (45 CFR 160.103). Typical work: hosting, billing, analytics, transcription, EHR software, consultants whose work involves the data. Two mechanics matter more than the logo on the contract. First, the same product can be a business-associate function for a hospital and outside HIPAA for a consumer, because the information is protected health information only when a covered entity or another business associate is in the chain. Second, subcontractors that touch the data are business associates all the way down. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable under the Security Rule and the Breach Notification Rule, independently of the paper.
- 5
Do not hide in the conduit exception unless you are a conduit
“We never look at it” is not a classification. The conduit exception covers mere transmission services with only transient access (a telecommunications carrier, a courier) plus temporary storage incident to that transmission. A vendor that maintains the data is a business associate even when the data is encrypted and the vendor never holds the key. That is the HHS Office for Civil Rights position in the Guidance on HIPAA and Cloud Computing. Hosting is not a pipe. If you store it, you are in the definition.
- 6
If you sell health software to consumers, look at the FTC rule, not HIPAA
Direct-to-consumer health is the other common false positive. Data a person gives a wellness app, a wearable, or a personal health record with no provider or plan in the chain is generally not protected health information, so HIPAA does not attach. That is not a free pass. The FTC Health Breach Notification Rule (16 CFR Part 318) can require breach notification from vendors of personal health records, PHR related entities (including connected health apps in covered circumstances), and their third-party service providers. The FTC Act still covers the privacy promises on the marketing site. The same app becomes business-associate territory the moment it handles data on a provider's or plan's behalf. Two regimes, two answers, same product.
Run the same test as a free interactive check
The free HIPAA applicability checker asks the entity-type, electronic-transaction, vendor, and direct-to-consumer questions and returns a structured assessment (covered entity, business associate, review, or not covered) with reasons. Use this guide for the legal structure. Use the checker to run the interactive path. Both are starting points, not binding determinations. The checker runs in your browser and stores nothing.
Six mistakes that produce the wrong answer
Treating 'we work in health' as the test
HIPAA names three covered-entity categories and a business-associate function. A wellness brand, a medical-device maker that never sees identifiable patient data, and a cash-only practice that never bills electronically can all sit outside, for different reasons.
Skipping the provider electronic-transaction trigger
Seeing patients is not enough. The covered-entity definition for providers is conditional on a HIPAA standard transaction in electronic form, including one a billing service submits for you.
Letting the BAA decide the classification
A customer who sends a BAA is telling you how they classified the relationship. They can be wrong. Your status follows 45 CFR 160.103, not the document they attached to the deal.
Calling hosting a conduit
The conduit exception is a pipe, not a disk. HHS treats a cloud provider that maintains electronic protected health information as a business associate even when the data is encrypted and unread.
Applying HIPAA to a consumer app that has no covered entity in the chain
That data is usually not protected health information. The FTC Health Breach Notification Rule is the signpost. HIPAA starts the day the same app handles data for a provider or a plan.
Pasting PHI into a tool that has not signed a BAA
A documentation assistant is not a Business Associate because it drafts a Security Rule policy. ISMS Copilot does not sign a BAA. Keep ePHI in systems that do.
Where this page sits in the HIPAA cluster
| Surface | Job | Format |
|---|---|---|
| This guide | Explain the covered-entity / business-associate / neither test so a person (or an AI answer) can follow the definitions | Long-form how-to |
| HIPAA applicability checker | Run the same rules as an interactive questionnaire | Free tool |
| HIPAA framework page | Product-oriented overview of drafting HIPAA documentation with ISMS Copilot. No BAA. No PHI in chats. | Framework hub |
| US healthcare audience page | How digital-health and covered teams use the product for documentation, not for processing ePHI | Audience page |
| US region hub | SOC 2, HIPAA, NIST, CMMC, and CCPA as the US work, not as a hosting pitch | Region hub |
Frequently asked questions
Do I need HIPAA if I work in health but never bill insurance?
Maybe not as a covered entity. A health care provider is covered only if it transmits health information electronically in connection with a HIPAA standard transaction (45 CFR 160.102 and 160.103). A cash-only practice that never submits electronic claims or eligibility checks, directly or through a billing service, may sit outside that definition. The carve-out is fragile, state confidentiality law still applies, and a separate vendor relationship can still make you a business associate.
We host encrypted data and never look at it. Are we a business associate?
Usually yes, if the data is protected health information and you maintain it. HHS treats a cloud provider that creates, receives, or maintains electronic protected health information as a business associate even in the no-view, encrypted, no-key scenario. The conduit exception is for mere transmission with transient access, not for storage.
Can an organization be both a covered entity and a business associate?
Yes. HIPAA assesses each function. A hospital that also sells billing software to other clinics is a covered entity for its own care and a business associate for the software. Organizations whose activities are only partly covered can designate a hybrid entity (45 CFR 164.105) so the Rules apply to the health-care component. Run the test once per role.
Does HIPAA cover consumer health apps and wearables?
Usually not, when the consumer gives the data directly and no covered entity is in the chain. Look at the FTC Health Breach Notification Rule (16 CFR Part 318) and the FTC Act instead. The same product becomes a business-associate question the moment it handles data for a provider or a plan.
Will ISMS Copilot sign a Business Associate Agreement?
No. ISMS Copilot drafts policies, risk-analysis methods, and Security Rule documentation. It is not a HIPAA Business Associate and it does not sign a BAA. Do not paste protected health information into chats. Keep ePHI in systems that have a BAA chain. See /frameworks/hipaa and /for/us-healthcare.
How is this different from the free HIPAA applicability checker?
This page is the long-form decision method: the 45 CFR 160.103 definitions, the provider electronic-transaction trigger, the vendor/subcontractor chain, the conduit exception, and the FTC signpost. The free checker at /resources/hipaa-applicability-checker is the same rules as a six-question form. Use the guide to understand the test. Use the checker to run it.
Primary sources
- 45 CFR 160.103, definitions: covered entity, business associate, health care provider, health plan, health care clearinghouse, protected health information, transaction (eCFR, current). www.ecfr.gov (checked 2026-08-13).
- 45 CFR 160.102, applicability of the HIPAA Rules, including the electronic-transaction trigger that makes a health care provider a covered entity (eCFR, current). www.ecfr.gov (checked 2026-08-13).
- 45 CFR 164.502(e) and 164.504(e), business associate contracts and other arrangements (eCFR, current). www.ecfr.gov (checked 2026-08-13).
- HHS Office for Civil Rights, Covered Entities and Business Associates (who the HIPAA Rules reach, and when a written business associate agreement is required). www.hhs.gov (checked 2026-08-13).
- HHS Office for Civil Rights, Guidance on HIPAA and Cloud Computing (the no-view hosting position and the narrow conduit exception). www.hhs.gov (checked 2026-08-13).
- FTC Health Breach Notification Rule, 16 CFR Part 318 (breach notification for vendors of personal health records, PHR related entities, and their service providers, outside HIPAA). www.ftc.gov (checked 2026-08-13).
Written and maintained by the ISMS Copilot team. Last reviewed 2026-08-13.
This page paraphrases the structure of 45 CFR Parts 160 and 164 (public US regulatory text) and related HHS and FTC guidance in original wording. It is educational content, not legal advice and not a binding determination of your organization's status. ISMS Copilot drafts HIPAA documentation. It does not sign a Business Associate Agreement and it is not a place to store protected health information.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
