Who HIPAA Actually Covers
A wearable knows a person’s resting heart rate, sleep pattern and menstrual cycle. Their dentist knows about one tooth. Federal health privacy law reaches the dentist and not the wearable, and the reason is structural rather than accidental.
HIPAA regulates by who holds the information, not by how sensitive it is.
The three covered entities
The Department of Health and Human Services states the categories plainly in its guidance on cloud computing. A covered entity is a health plan, a health care clearinghouse, or a health care provider conducting certain billing and payment related transactions electronically.
Read the third one twice. A provider does not become covered by treating patients. It becomes covered by transmitting health information electronically in connection with a transaction for which the department has adopted standards. A cash-only practice billing nobody electronically can sit outside HIPAA, holding the same records as the clinic next door.
Business associates and their subcontractors
The second tier catches the vendors. A business associate is an entity or person outside the covered entity’s workforce. It performs functions or activities on behalf of a covered entity, or provides certain services to one. Either way the work involves creating, receiving, maintaining or transmitting protected health information.
The department adds a point candidates forget. A business associate also includes any subcontractor handling protected health information on behalf of another business associate. Liability runs down the chain rather than stopping at the first vendor.
Where HIPAA stops
So the boundary is drawn around a payment and treatment system, and everything consumer-facing falls outside it. A symptom tracker, a fertility app, a sleep monitor and a genetic test can each hold detailed health information. None of them needs any relationship to a covered entity.
That gap is well known to the regulator that fills it.
The Health Breach Notification Rule
The Federal Trade Commission runs a separate regime for exactly this population. Its guidance on consumer health information explains the reach. The Health Breach Notification Rule applies to businesses not covered by HIPAA: vendors of personal health records, related entities, and third party service providers.
The Commission finalised amendments in April 2024 clarifying that the rule reaches health apps and similar technologies. That obligation is notification. Individuals, the Commission, and in some cases the media, following a breach of unsecured personally identifiable health data. Third party service providers to those vendors must notify the vendors in turn.
Two different regulators, two different triggers, one category of information. That is the shape of United States privacy law in miniature.
HIPAA in the CIPP/US exam
The Body of Knowledge is the IAPP’s published outline of what each certification exam tests. Healthcare sits inside the domain on limits to private-sector collection and use, alongside the financial and education sectors.
The recurring question asks whether an organisation is covered. It usually turns on the electronic transaction rather than on the health data. Watch for a scenario describing an app, a wellness programme or an employer holding health records. None of those is a covered entity by that fact alone. Watch also for the option treating a subcontractor as out of scope. Our piece on the BIPA private right of action reaches health-adjacent data through a state statute. The piece on VPPA consumers applies the same coverage logic in a different sector.
Sectoral questions reward a decision tree rather than recall, and building one takes an afternoon. The CIPP/US Exam Question Masterclass at €195 teaches the reading habit that makes the tree usable under time pressure.
