The Health Insurance Portability and Accountability Act, passed in 1996, created a set of national rules about who can see your health information and what they can do with it. But HIPAA doesn't protect all health information or all organizations that touch it. Understanding the actual boundaries matters because many people assume they're protected when they're not—and then get surprised when information they thought was private turns out to be accessible.
Understanding Zipcash Bill Payments and How They Work →
HIPAA's privacy and security rules apply to "covered entities." These are organizations that handle protected health information as part of their business. The main categories are: health plans (insurance companies, HMOs, employer health plans), healthcare providers (doctors, dentists, hospitals, clinics, therapists), and healthcare clearinghouses (organizations that process health information for other entities). If your doctor's office, your insurance company, or your hospital system collects and stores your health information, HIPAA rules apply to them.
But here's where it gets narrow: HIPAA only covers those three types of organizations. It does not cover your employer just because they sponsor your health plan. It doesn't cover life insurance companies, disability insurers, or long-term care insurers. It doesn't cover your gym, your pharmacist (unless they're part of a HIPAA-covered pharmacy), your school, or your workplace in general. If you use a mental health app that isn't connected to a covered provider, that app company isn't bound by HIPAA. Many people hand over sensitive health information to these non-covered entities thinking they have the same protections they'd have at a doctor's office—but they don't.
The information HIPAA protects is called "protected health information" or PHI. This includes obvious things like your diagnosis, test results, medications, and medical history. But it also includes things people don't always think about: your name or address if it's connected to health information, appointment dates, billing information from a healthcare provider, and even information that could identify you indirectly (like "the 54-year-old diabetic accountant in Springfield"). HIPAA protects this information whether it's on paper, in an electronic system, or transmitted over the phone.
One crucial boundary: HIPAA does not create a "right to privacy" in the way many people understand it. It doesn't say healthcare providers can't use or share your information. It says they must use and share it according to specific rules. There's a real difference.
Practical takeaway: Before sharing health information with any organization, ask directly: "Are you a HIPAA-covered entity?" If they say no, know that they operate under different (usually weaker) privacy rules. Many states and specific laws offer additional protections, but HIPAA won't be your safety net.
One of the biggest misconceptions about HIPAA is that covered entities need your permission to use or share your health information at all. That's not how it works. HIPAA allows healthcare providers and health plans to use and disclose your protected health information without your written consent for a number of defined purposes—and they do this regularly without asking you first.
Get Your Free Guide to Scheduling LabCorp Lab Tests Online →
The primary permitted use is "treatment." Your doctor can use your information to diagnose you, create a treatment plan, refer you to a specialist, and coordinate care with other providers. When you see a doctor and they order lab work, discuss your case with a nurse, or send records to a specialist, that's all treatment-related use that doesn't require a separate permission form. This makes practical sense—healthcare providers need access to information to actually treat you—but it means your information flows between providers and departments regularly.
The second major category is "payment." Your health insurance company can access your medical records to determine whether to pay a claim, how much to pay, and whether a service is covered under your plan. Your provider can use your information to bill your insurance. Your employer can access summary health information to manage their health plan. These operations mean your diagnosis and treatment details aren't just sitting in your provider's files—they're also with your insurance company, billing departments, and sometimes your employer's benefits administrators.
Healthcare operations is the third category. This is broad and includes things like quality improvement, fraud detection, training, and accreditation. A hospital can use your information to audit whether providers are following protocols. They can use it to investigate complaints. They can use it for business planning. They can share it with contractors (like IT companies or lawyers) who help run the organization. This category gives covered entities a lot of latitude.
Beyond these three main categories, HIPAA allows disclosure without consent for several other reasons: when required by law (like reporting communicable diseases or abuse), for public health activities, for law enforcement (under specific conditions), for coroners, for organ donation, and for research (usually with protections in place). Your provider can also share information with family members involved in your care, though they should give you a chance to object first.
Many people don't realize that once your information is shared for one of these permitted reasons, the receiving organization might not be bound by HIPAA. If your information goes to your employer, to a researcher, or to a law enforcement agency, HIPAA doesn't necessarily follow it there. That's why the initial disclosure matters.
Practical takeaway: Your healthcare information is being used and shared regularly without a separate permission from you. This isn't a violation—it's built into how HIPAA works. If you want to restrict these standard uses and disclosures, you need to know your options (see section 5) and actively communicate them.
HIPAA does require covered entities to get your written authorization before using or sharing your health information for certain purposes. These situations are narrower than many people think, but they're important to understand because they're where you actually have control over what happens with your information.
Get Your Free Guide to Manicure and Pedicure Costs →
Most uses for marketing require your authorization. If your health plan wants to use your information to market services to you, they need permission. However—and this is a huge exception—the "treatment, payment, and healthcare operations" uses we discussed earlier aren't considered marketing. Your doctor doesn't need permission to send you an appointment reminder or a notice about a new treatment option they offer. Your insurance company doesn't need permission to tell you about a covered preventive service. But if a pharmaceutical company wants to send you information about a new drug for your condition, and your health plan is handling that marketing, authorization is required.
Using or sharing your information for research almost always requires authorization. Researchers can't just access your medical records or use your information in studies without your consent. There's an exception for de-identified information (information that has been stripped of identifying details according to specific rules), but if there's any way to connect the research data back to you, authorization is required. This is one area where HIPAA gives individuals meaningful control.
Sharing information for reasons outside treatment, payment, and operations generally requires authorization. If a healthcare provider wants to share your records with a life insurance company, a lawyer, a school, or anyone outside the standard care and billing loop, they should ask for permission first. The exception: if the law requires it, they can share without asking.
Your authorization for one purpose doesn't cover other purposes. If you sign a form allowing your records to be shared with a disability insurance company, that doesn't mean the provider can also share them with a pharmaceutical company or a potential employer. Each authorization should be specific about who gets the information and what they'll do with it.
Many covered entities use broad authorization forms that ask you to consent to all possible uses and disclosures. These are legal under HIPAA, but you can usually negotiate. You can ask to authorize only specific uses. You can revoke an authorization at any time (though revocation doesn't undo disclosures that already happened). The authorization form should tell you how to revoke it.
Practical takeaway: When a healthcare provider or health plan asks you to sign a form authorizing use of your information, read it carefully. Understand specifically who will see your information and what they'll use it for. Know that you can limit the authorization or refuse it, and ask what happens if you do.
HIPAA has several built-in exceptions and exclusions that create real gaps in protection. Understanding these matters because they're where your health information can be shared with fewer restrictions than many people realize.
Learn How to Grow Ginger From Root →
The psychotherapy notes exception is one of the most significant. If your therapist or psychiatrist writes
This guide is for general information only and is not medical, financial, legal, or other professional advice. For decisions specific to your situation, consult a qualified professional. See our Editorial Policy.