What it means
HIPAA is broader than a privacy label, as it includes health-coverage and administrative provisions as well as rules developed for information privacy and security, so a business discussing compliance should identify which part applies to its activity. The Privacy Rule applies to covered entities and, through relevant obligations, business associates.
Covered entities include specified health plans, clearinghouses and healthcare providers carrying out covered electronic transactions, and merely collecting a fitness preference does not automatically make a business a covered entity. Protected health information is individually identifiable health information within the rule's scope, and the context and holder matter, so a medical detail in an employment record is not automatically governed in the same way as information in a covered healthcare record.
Business associates perform certain services or functions involving protected information for covered entities, and their contractual and regulatory responsibilities require attention. Calling a supplier a technology vendor does not remove obligations when its actual role brings it within scope.
The Privacy Rule permits specified uses and disclosures, including treatment, payment and healthcare operations under the relevant conditions, while other uses can require authorisation or a separate permitted basis, so managers should not assume that every sharing decision needs the same document. Authorisation is distinct from informal agreement: where required, it has specific elements and limits, and a signed form that lacks necessary information or covers a different purpose should not be treated as blanket permission to disclose anything.
Patients have rights under the rule, including rights relating to access and certain corrections or restrictions, and these rights operate through specific procedures and exceptions, so a privacy policy should describe the applicable process instead of promising an unlimited outcome. The minimum-necessary principle limits certain uses, disclosures and requests to what is needed for the purpose, with exceptions including particular treatment-related situations.
Applying it correctly requires knowing the activity rather than imposing one simple rule on every exchange. The Security Rule concerns electronic protected health information, and safeguards include administrative, physical and technical measures; encryption, access controls and training can matter, but one security product does not make the whole organisation compliant.
Other laws can also apply, as state privacy requirements, research rules and contractual duties may impose additional conditions. Compliance with one HIPAA provision does not establish that an action is permitted under every relevant framework.
The HHS summary explains scope, permitted uses and disclosures, and key patient rights, and it also notes that a summary does not address every detail, so organisations should connect the general rules to their actual operations and responsibilities. For a non-finance manager, identify the organisation's role, the information involved and the purpose of the activity, then follow the documented process for access, disclosure and incidents.
Avoid using HIPAA as either a universal excuse not to communicate or a vague assurance that all information is safe.
In practice
Real-world examples.
Example
A health plan handles identifiable claims information. It applies the relevant privacy rules and controls rather than treat the records as ordinary customer marketing data. Access is limited to staff who need the information for claims, payment or plan operations.
Example
A provider hires a supplier to process protected information. The parties assess the supplier's business-associate role and required safeguards before any records are shared. The written agreement then sets out permitted uses, security expectations and what happens if there is an incident.
Example
A manager asks to share patient details for a new purpose. The team checks the permitted basis or required authorisation instead of relying on an unrelated prior form. If the purpose is not covered, the request waits until the right basis is in place.
Formula
Calculation
There is no universal numerical HIPAA formula. A practical review identifies the entity's role, whether the information is protected, the proposed use or disclosure, the permitted basis and applicable safeguards. For an authorization-based use, the actual scope, recipients, purpose and validity must match the proposed activity.Case study
Seen in the real world.
Fictional case study: Beech Clinic assumed that a general privacy notice authorised a supplier to use patient records for an unrelated promotional project. The project team treated the notice as unlimited consent. The clinic's privacy lead reviewed the purpose, supplier role and proposed information. The team separated ordinary operations from the new marketing use and identified the additional requirements before disclosure. Beech changed the project plan and tightened access controls.
It learned that a broad claim of HIPAA compliance does not replace a purpose-specific review of information use. The clinic also added a short intake step for new projects asking who will hold the information, why it is needed, what the supplier's role is and which documents support the use. The privacy lead keeps the answers on file and revisits them when a project changes. This fictional case is illustrative and does not describe any real clinic.
Watch out
Common mistakes.
- Assuming HIPAA covers every health-related fact everywhere. Check the entity and information scope.
- Treating a privacy notice as blanket authorisation. Different purposes can require different legal bases.
- Equating one security measure with compliance. Roles, processes and safeguards all matter.
Questions
People also ask.
Does HIPAA forbid every disclosure?
No. The rules permit specified uses and disclosures under relevant conditions.
Is every app with health data a covered entity?
No. Scope depends on the organisational role and activity, not the data label alone.
Is privacy the same as security?
No. Privacy addresses permitted handling; security safeguards protect electronic information within scope.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
