AMDA-IMIC

Who HIPAA Does Not Cover

Which organizations and data sources fall outside HIPAA's Privacy Rule — including employers, life insurance companies, workers' comp insurers, and consumer health apps — and what other laws may apply.

Who this is for

Anyone who wants to understand why their employer, a wellness app, a life insurer, or another organization is not bound by HIPAA's privacy protections, and what other legal frameworks might apply to their health data.

HIPAA is widely cited as the law protecting your medical privacy, but it covers only a specific category of organizations. A significant amount of health data — held by employers, life insurance companies, workers’ compensation programs, consumer apps, and other organizations — falls outside HIPAA’s reach entirely. Understanding where HIPAA ends and other frameworks begin helps you know when to rely on HIPAA and when to look elsewhere for protection or recourse.

The scope of HIPAA: covered entities only

HIPAA’s Privacy Rule applies to covered entities: healthcare providers, health plans, and healthcare clearinghouses. It also extends to business associates — vendors and service providers that handle protected health information on behalf of covered entities. Outside these categories, HIPAA does not apply, regardless of how sensitive the health information is or how it was obtained.

The three covered entity categories in practice:

  • Healthcare providers: Doctors, hospitals, clinics, pharmacies, nursing facilities, laboratories, and others who transmit health information electronically — which covers essentially all modern providers.
  • Health plans: Health insurance companies, HMOs, employer-sponsored health plans (with certain size exceptions for small, self-administered plans), Medicare, Medicaid, and similar programs.
  • Healthcare clearinghouses: Organizations that process health information on behalf of payers and providers, such as billing companies and claims processors operating as clearinghouses. (Many billing companies are business associates rather than clearinghouses; the distinction matters for the specific type of obligation.)

Employers: not covered by HIPAA as employers

Your employer is not a covered entity simply by virtue of being your employer, even if you receive health insurance through them. The employment relationship does not bring HIPAA into effect.

Your employer may receive health information about you through various legal channels:

  • A medical certification submitted to support an FMLA leave request
  • A fitness-for-duty examination ordered as a condition of return to work
  • A workers’ compensation claim
  • Voluntary disclosure by you

HIPAA does not restrict what your employer does with this information. Other federal and state laws impose some limits:

  • The Americans with Disabilities Act (ADA) requires that medical information obtained by employers be kept in separate, confidential files and limits the circumstances in which employers can use that information.
  • The Family and Medical Leave Act (FMLA) restricts the circumstances under which employers can require medical certification and imposes some confidentiality obligations.
  • The Genetic Information Nondiscrimination Act (GINA) prohibits employer use of genetic information in employment decisions.

However, these protections are narrower than HIPAA, apply only in specific employment contexts, and do not give you the same audit, access, and complaint rights that HIPAA provides against covered entities.

An important exception: If your employer operates a self-funded health plan, that health plan function is a covered entity under HIPAA. Your employer as the plan administrator must follow HIPAA for the plan functions — but there are required “firewall” provisions to prevent health plan information from flowing to employment decision-makers.

Life insurance companies

Life insurance companies are not covered entities under HIPAA. A life insurer is not a healthcare provider or health plan (in the HIPAA sense). When you apply for a life insurance policy, you typically authorize the insurer to obtain your medical records from providers — and that authorization is a voluntary HIPAA-compliant release by the providers. But what the life insurer does with your information is governed by state insurance regulations and the terms of that authorization, not by HIPAA.

State insurance laws vary considerably in what medical underwriting practices are allowed, what information insurers can use, and what disclosure and access rights policyholders have. If you have concerns about how a life insurer is using your health information, your state department of insurance is the relevant regulator.

Workers’ compensation insurers and programs

Workers’ compensation insurers and state workers’ compensation programs are generally not covered entities. When you file a workers’ compensation claim, your treating provider — as a covered entity — may disclose relevant health information to the workers’ compensation insurer or your employer without your authorization, to the extent required by state workers’ compensation law. HIPAA permits this specific disclosure.

The workers’ compensation insurer or employer who receives that information is not, however, bound by HIPAA in how they handle it subsequently. State workers’ compensation laws and regulations govern those handling practices.

Consumer health apps and digital health tools

This is an area of significant misunderstanding. The vast majority of consumer health applications — including fitness trackers, nutrition apps, period trackers, sleep monitors, mental wellness apps, and symptom checkers — are not covered entities and are not subject to HIPAA’s requirements.

App or serviceHIPAA coverage?Governing law
Consumer fitness tracker (e.g., standalone app)NoFTC Act (deceptive practices); state privacy laws
Period tracking app not connected to a health planNoFTC Act; state health data laws
Patient portal provided by your hospitalYes (provider is covered entity)HIPAA
App provided by your health insurerYes (health plan is covered entity)HIPAA
Telehealth provider appYes (telehealth provider is covered entity)HIPAA

If a consumer app says your data is “HIPAA-compliant,” this is often a marketing claim about their internal security practices, not a statement that HIPAA legally applies to them. It is accurate to say their internal practices follow HIPAA standards; it is misleading to imply that HIPAA gives you legal rights against them.

The Federal Trade Commission has authority under the FTC Act to take action against companies that make deceptive claims about their privacy practices, and has pursued enforcement in the health app space. Several states have enacted health data privacy laws that extend beyond HIPAA, with some specifically targeting consumer app data.

Documents and terms you’ll see

When understanding HIPAA’s boundaries, these terms appear in HHS guidance and privacy policy literature:

  • Covered entity — the category of organizations subject to HIPAA; entities outside this category are not legally bound by HIPAA regardless of whether they hold health data
  • HIPAA — the Health Insurance Portability and Accountability Act; its Privacy Rule is the primary instrument protecting PHI; its scope is narrower than commonly understood
  • FERPA — the Family Educational Rights and Privacy Act; governs student education records including health records that are part of the education record at federally funded schools; FERPA and HIPAA do not overlap — the same record is covered by one or the other, not both
  • Protected health information — only has this legal status under HIPAA when held by a covered entity or business associate; the same information held by a non-covered employer or app is health data, but not “PHI” in the legal sense

School nurses and student health records

Health records maintained as part of a student’s education record at a school receiving federal funding are governed by FERPA, not HIPAA. HHS and the Department of Education have issued joint guidance clarifying this: when records fall under FERPA, HIPAA expressly excludes them from its scope.

In practice, this means that a school nurse’s records are typically FERPA records — accessible to parents (for minors) and to the student (upon reaching majority) under FERPA’s framework, not HIPAA. Health clinics operating on a school campus that provide healthcare services and maintain separate records may be covered entities under HIPAA for those clinical records.

What other frameworks may protect you

For health data held outside HIPAA’s coverage, the following may provide some protection:

  • FTC Act: Unfair or deceptive data practices by consumer apps and other non-health entities fall under FTC jurisdiction.
  • State health data privacy laws: Several states — including California, Washington, and others — have enacted health data privacy laws that cover data held by entities not regulated by HIPAA.
  • ADA and GINA: Limit how employers and some other entities use medical and genetic information.
  • State insurance regulations: Govern what life and workers’ compensation insurers can do with health information.

The HIPAA and your medical records guide explains what HIPAA does cover, your right to access records from covered entities, and how to file a complaint if your privacy rights are violated.

Key terms

TermPlain meaningGlossary
Covered entity A healthcare provider, health plan, or healthcare clearinghouse subject to HIPAA's Privacy Rule →
HIPAA Federal law governing the privacy and security of protected health information held by covered entities and their business associates →
Protected health information Health information that identifies you or could reasonably identify you, held or transmitted by a covered entity or business associate →
FERPA The Family Educational Rights and Privacy Act, which governs student education records and applies to school health records maintained as part of the education record →

Common questions

Does my employer have to follow HIPAA when handling my health information?
Not directly. Employers are not covered entities under HIPAA unless they are also a healthcare provider or run a self-funded health plan. Your employer may learn health information through various channels — a medical leave request, a workers' compensation claim, a fitness-for-duty examination — and HIPAA generally does not restrict what your employer can do with that information. Other laws, such as the ADA and FMLA, impose some limits on how employers use health information, but HIPAA is not among them.
Is a health and wellness app covered by HIPAA?
Generally no. Most consumer health apps — fitness trackers, nutrition loggers, period trackers, mental wellness apps — are not covered entities and are not HIPAA-regulated, even if they collect detailed health information. Some limited exceptions exist if the app is offered by or acting as a business associate of a covered entity. The FTC has authority over deceptive privacy practices by consumer apps under the FTC Act.
Are life insurance companies covered by HIPAA?
Life insurance companies are not covered entities under HIPAA. They are not healthcare providers, health plans (in the HIPAA sense), or clearinghouses. Life insurers can request that you authorize disclosure of medical records and can use health information in underwriting decisions. State insurance regulations govern what information life insurers can collect and use.
Does HIPAA apply to workers' compensation?
Workers' compensation insurers and employers receiving workers' compensation claims are generally not covered entities. HIPAA does permit covered entities (your treating provider) to disclose relevant health information to workers' compensation programs without your authorization, to the extent required by law. But the workers' compensation insurer or employer receiving that information is not itself bound by HIPAA in how it handles it.
Does HIPAA apply to school nurses and school health records?
It depends on how the records are maintained. Health records that are part of a student's education record at a school receiving federal funding are generally governed by FERPA, not HIPAA. School nurses who treat students and maintain records as part of the education record are covered by FERPA's framework. Health records maintained separately by a school-based clinic acting as a healthcare provider may be subject to HIPAA.
What about law enforcement — can police access my medical records without my permission?
In most circumstances, HIPAA restricts covered entities from disclosing your health information to law enforcement without your authorization. There are narrow exceptions: imminent threat to safety, court orders, certain public health activities, and situations involving gunshot wounds or injuries in some states. Law enforcement generally cannot simply demand your records without legal process.
Does HIPAA apply to information I share on social media or in online communities?
No. When you share health information publicly — in a social media post, a patient forum, or a public comment — HIPAA does not apply to that information. It was not shared with a covered entity; it is now public. The original provider's records of the same information remain protected, but what you voluntarily share publicly is not under HIPAA's protection.
Are there any federal laws that protect health data held by non-HIPAA entities?
Several laws provide partial or overlapping protections. The FTC Act covers deceptive data privacy practices. The ADA restricts employer use of disability-related medical information. The FMLA limits disclosure of medical information in the leave context. The Genetic Information Nondiscrimination Act (GINA) restricts use of genetic information by employers and health insurers. Some states have enacted broader health data privacy laws that go beyond HIPAA. But there is no single comprehensive federal law covering all health data held by all entities.

Sources

  1. HHS OCR — Who must follow HIPAA
  2. FTC — Mobile health apps and privacy
  3. DOL — HIPAA and employer health plans
  4. HHS — FERPA and HIPAA interaction

Last reviewed: September 2026