HIPAA & compliance

Who Must Follow HIPAA? Covered Entities & Business Associates

HIPAA applies to covered entities, their business associates, and any vendor that touches PHI. Here's who is bound, who is exempt, and what non-compliance costs in 2026.

HIPAA applies to three groups: covered entities, their business associates, and anyone those vendors subcontract to handle protected health information (PHI). If your organization creates, receives, stores, or transmits health information for a healthcare provider or plan, you are almost certainly bound by HIPAA, and since 2009 you can be penalized directly for failing to comply.

Here is exactly who is covered, who is exempt, and what non-compliance costs.

What is a covered entity under HIPAA?

Covered entities are the three groups at the center of the healthcare system:

  • Healthcare providers who transmit health information electronically: physicians, hospitals, clinics, psychologists, dentists, chiropractors, physical therapists, nursing homes, and pharmacies.
  • Health plans: insurance companies, HMOs, employer group health plans, Medicare, Medicaid, and CHIP.
  • Healthcare clearinghouses that process health data between formats.

If you bill electronically or send claims, you are almost certainly a covered entity.

Who are business associates under HIPAA?

A business associate is any third party that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Common examples include:

  • Medical billing companies
  • EHR vendors
  • Patient intake platforms
  • Cloud storage and IT support
  • Transcription services
  • Legal and accounting firms that handle PHI

The HITECH Act of 2009 made business associates directly liable for compliance, not just contractually responsible to the covered entity. That is why any vendor touching PHI must sign a Business Associate Agreement (BAA) and meet the same safeguards.

Who is exempt from HIPAA?

HIPAA does not follow health information everywhere. Organizations generally exempt include:

  • Employers holding employee health records outside a group health plan
  • Life insurers and workers' compensation carriers
  • Most schools and school districts
  • Most law enforcement agencies
  • Many state agencies
  • Consumer health apps not connected to a provider or plan

The key test is the relationship: the same data can be protected in a clinic and unprotected in a fitness app, because only one sits inside a covered-entity relationship.

Does HIPAA apply to online patient intake forms?

Yes. Whenever an online form collects PHI for a covered entity, the form, its hosting, and its storage all fall under HIPAA. That is why you cannot safely collect intake on a generic form builder: you need encryption in transit and at rest, access controls, audit logging, and a signed BAA. Purpose-built platforms bake these in, capturing consents with HIPAA-compliant e-signatures and storing every submission securely.

What are the penalties for non-compliance?

Penalties scale with culpability. As of January 2026, tiers run from about $145 per violation (Tier 1, unknowing) up to $2,190,294 per violation (Tier 4, willful neglect not corrected), and enforcement is active, with regulators resolving cases and levying penalties each year. The first-year cost of the 2025 Security Rule updates alone is estimated at $9 billion across the industry. Against those numbers, the cost of a compliant platform is rounding error.

The bottom line

If you provide care, pay for it, process it, or handle PHI for someone who does, HIPAA applies to you, and a BAA plus real safeguards are non-negotiable. Choosing vendors that are built for compliance is the simplest way to stay on the right side of it. See how Zentake handles HIPAA-compliant intake and e-signatures, or read our guide to choosing patient intake software.

Frequently asked questions

Who has to follow HIPAA?

Covered entities (healthcare providers, health plans, and clearinghouses) and their business associates (any vendor that creates, receives, maintains, or transmits protected health information on their behalf). Since the HITECH Act of 2009, business associates are directly liable, not just contractually bound.

Is a patient intake platform a business associate?

Yes. A platform that collects, stores, or transmits protected health information on behalf of a practice is a business associate and must sign a Business Associate Agreement and meet HIPAA safeguards.

Who is exempt from HIPAA?

Organizations that hold health information outside the covered-entity relationship, such as employers holding employee records, life insurers, workers' compensation carriers, most schools, most law enforcement, and consumer health apps not tied to a provider or plan.

Does HIPAA apply to online intake forms?

Yes, whenever the form collects protected health information for a covered entity. The form, its hosting, and its storage all fall under HIPAA, which is why a signed BAA and encryption are required rather than a generic form tool.

Start your free trial← Back to the journal