{"id":1960,"date":"2018-10-25T19:15:41","date_gmt":"2018-10-26T02:15:41","guid":{"rendered":"https:\/\/blog.sprucehealth.com\/?p=1960"},"modified":"2026-09-16T02:02:18","modified_gmt":"2026-09-16T09:02:18","slug":"think-hipaa-doesnt-apply-to-you-think-again","status":"publish","type":"post","link":"https:\/\/sprucehealth.com\/blog\/think-hipaa-doesnt-apply-to-you-think-again\/","title":{"rendered":"Does HIPAA Apply to Your Practice? Probably, Yes (2026)"},"content":{"rendered":"<p>Plenty of practices read the scope of HIPAA, notice they do not conduct the covered electronic transactions, and conclude the law does not reach them. That conclusion is technically defensible but practically dangerous. Courts across the United States use HIPAA to establish the standard of care for medical privacy in ordinary state tort cases, which means a practice can lose a lawsuit over HIPAA even when HIPAA does not directly apply to it. On top of that, many states have their own privacy laws that are stricter than HIPAA and that apply to every provider, with no scope exemption at all.<\/p>\n<p>A little knowledge can be a dangerous thing, and this is definitely true when it comes to HIPAA. At Spruce, we sometimes hear from healthcare providers who think that they are exempt from HIPAA, but this is almost never fully accurate and it can be a costly regulatory mistake to make.<\/p>\n<p>If you&#8217;re involved with healthcare in the United States and you believe that HIPAA doesn&#8217;t apply to you, you might want to reconsider that position. Read on to learn why and to make sure that you&#8217;re protected.<\/p>\n<h2>The Pitfall: Thinking That HIPAA Only Applies on the Federal Level<\/h2>\n<p>HIPAA is a federal law, and its resultant regulations are therefore developed and enforced by the federal Department of Health and Human Services (HHS) and its Office for Civil Rights (OCR). This situation means that HIPAA has potential implications for everybody in the country, but <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html\">as per HHS<\/a>, the scope of the law is generally limited to &#8220;health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically.&#8221;<\/p>\n<p>We&#8217;ve spent time on this blog discussing the ins and outs of this <a href=\"https:\/\/sprucehealth.com\/blog\/hipaa-compliance-apply-to-me\/\">scope limitation<\/a>, including the specifics of which &#8220;electronic transactions&#8221; put you under the purview of HIPAA, and the government even provides <a href=\"https:\/\/www.cms.gov\/Regulations-and-Guidance\/Administrative-Simplification\/HIPAA-ACA\/AreYouaCoveredEntity.html\">a clickable flowchart<\/a> to help you determine if the law might apply to you.<\/p>\n<p>If you read all of this guidance, you could easily get the idea that HIPAA doesn&#8217;t hold any sway over many types of medical practices, such as those that don&#8217;t accept health insurance or those that use paper charts.<\/p>\n<p>This, however, would be a huge mistake.<\/p>\n<h2>The Catch: HIPAA Can Be Used to Establish the Standard of Care in Non-HIPAA Lawsuits<\/h2>\n<p>This gets a little technical, but bear with me.<\/p>\n<p>As we discussed, HIPAA is federal law and doesn&#8217;t apply directly to all medical practices. There are, however, many common state laws that patients and other parties can use to bring lawsuits against medical practices. Many of these fall under <a href=\"https:\/\/en.wikipedia.org\/wiki\/Tort\">tort law<\/a>, which is the branch of law that addresses civil wrongs that have caused damages, and it includes colloquially familiar entities like &#8220;negligence,&#8221; &#8220;invasion of privacy,&#8221; and &#8220;intentional infliction of emotional distress,&#8221; among many others.<\/p>\n<div class=\"inset-box inset-box-right\">HIPAA has been used to determine the legal duties of healthcare providers, even in cases that are not within the strict scope of the law.<\/div>\n<p>While formal actions under HIPAA itself can only be pursued by state attorneys general or the Secretary of HHS, private individuals, such as patients, are free to file tort claims (primarily in state courts) without any direct governmental involvement. Let&#8217;s look at a &#8220;negligence&#8221; tort claim as an example.<\/p>\n<p>If a patient brings a negligence claim against a medical practice, there are typically four elements that they must establish in order to be successful (this can vary by state, but it is a common framework):<\/p>\n<ul>\n<li><strong>Duty<\/strong>: They must show that the medical practice owed them a duty of care<\/li>\n<li><strong>Breach<\/strong>: They must show that this duty was not fulfilled<\/li>\n<li><strong>Damages<\/strong>: They must demonstrate damages from the breach of duty<\/li>\n<li><strong>Causation<\/strong>: The damages must have been reasonably foreseeable<\/li>\n<\/ul>\n<p>So how can HIPAA factor into a negligence case? <strong>HIPAA has been used successfully to establish the &#8220;duty&#8221; element of negligence claims against medical organizations.<\/strong> For some years now, courts in many states have accepted HIPAA as the standard of care for the duties that healthcare providers owe to their patients, including the law&#8217;s provisions for security and privacy.<sup>1\u20134<\/sup><\/p>\n<p>Importantly, the success of these cases did not depend on the parts of HIPAA that determine who it applies to in its capacity as a federal law. In these negligence cases, it only mattered that there was a doctor\u2013patient relationship; that fact alone was enough for the courts to decide that the practices owed their patients a duty of HIPAA compliance, at least for the purposes of tort law.<sup>5<\/sup><\/p>\n<h2>That Is Confusing and Boring. Give Me the Summary!<\/h2>\n<p>First of all, rude: the law is fascinating. But, yes, it can be a little confusing or even daunting.<\/p>\n<p>Here&#8217;s the take-home summary:<\/p>\n<div class=\"keytakeaways\">\n<p><b>Key Takeaways:<\/b><\/p>\n<ul>\n<li><b>Many courts in the United States will use HIPAA as the standard of care for medical privacy and security, even in cases that are not within the strict scope of the law.<\/b><\/li>\n<li><b>This means that healthcare organizations can lose lawsuits because of HIPAA, even when the law does not directly apply to them.<\/b><\/li>\n<\/ul>\n<\/div>\n<h2>A Bonus Reminder About HIPAA Compliance and State Law<\/h2>\n<p>It&#8217;s also critical to remember that many states have passed their own <a href=\"http:\/\/www.nixonpeabody.com\/Texas_health_care_privacy_law_more_stringent_than_HIPAA\">medical privacy and security laws<\/a>. In general, HIPAA provides a <a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/faq\/399\/does-hipaa-preempt-state-laws\/index.html\">&#8220;floor&#8221; of privacy protection<\/a>, meaning that states cannot have laws that are more lenient than HIPAA. They can, however, have laws that are more strict or far-reaching than HIPAA, and many do. They are also free to make their laws apply to all healthcare providers, rather than following the scope limitations that are present in HIPAA.<\/p>\n<p>Understanding HIPAA is a good starting point, but it&#8217;s also important to be informed about any\u00a0<a href=\"http:\/\/www.healthinfolaw.org\/state\">health privacy laws<\/a> that your state has. Since these laws are guaranteed to be at least as strict as HIPAA, they end up functioning as a de facto mechanism to require HIPAA compliance, even from providers who might otherwise be exempt on a federal level.<\/p>\n<h2>And How Can I Be HIPAA Compliant?<\/h2>\n<p>We&#8217;ve got a <a href=\"https:\/\/sprucehealth.com\/blog\/easiest-complete-hipaa-compliance-checklist-youll-ever-see\/\">HIPAA-compliance checklist<\/a> to get you started and help make it easy! It&#8217;s not so bad; we promise. \ud83d\ude42<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Does HIPAA apply to cash-only or paper-chart practices?<\/h3>\n<p>Not always in the strict federal sense. HIPAA&#8217;s scope covers health plans, health care clearinghouses, and health care providers that conduct certain transactions electronically. A practice outside that scope can still be held to the HIPAA standard through state courts and state privacy law.<\/p>\n<h3>Can a practice be sued over HIPAA if HIPAA does not apply to it?<\/h3>\n<p>Effectively, yes. Only state attorneys general and the Secretary of HHS can bring formal actions under HIPAA itself, but patients can file state tort claims for things like negligence and invasion of privacy, and many courts use HIPAA as the standard of care in deciding those cases.<\/p>\n<h3>Do state privacy laws override HIPAA?<\/h3>\n<p>They cannot be more lenient. HIPAA sets a floor, and states are free to pass laws that are stricter or broader, including laws that apply to every healthcare provider rather than only those inside HIPAA&#8217;s federal scope. Many states have done exactly that.<\/p>\n<h3>What is the practical takeaway?<\/h3>\n<p>Assume the HIPAA standard applies to your practice and build around it, then check your own state&#8217;s health privacy law, which is guaranteed to be at least as strict. Spruce is a cloud-based platform for HIPAA-compliant communication, and every eligible organization receives a BAA as part of the terms of service at signup.<\/p>\n<p><em>This article is part of a series of posts relating to HIPAA law and regulation. The information provided is\u00a0meant as general guidance only and is not intended to be legal advice.<\/em><\/p>\n<hr \/>\n<p><strong>References:<\/strong><\/p>\n<ol>\n<li><em>Byrne v. Avery Center for Obstetrics and Gynecology<\/em>, P.C., 2014 WL 5507439 (Conn. Nov. 11, 2014)<\/li>\n<li><em>Acosta v. Byrum<\/em>, 638 S.E.2d 246, 249 (N.C. App. 2006).<\/li>\n<li><em>Sorensen v. Barbuto<\/em>, 143 P.3d 295, 298 (Utah Ct. App. 2006) aff\u2019d and remanded, 177 P.3d 614 (Utah 2008).<\/li>\n<li><em>Walgreen Co. v. Hinchy<\/em>, 21 N.E. 99, 105 (Ind. Ct. App. 2014) on rehearing, 25 N.E.3d 748 (Ind. Ct. App. 2015).<\/li>\n<li>Koch, D. D., JD &amp; RN. <a href=\"http:\/\/healthfinancejournal.com\/~junland\/index.php\/johcf\/article\/view\/67\">Is the HIPAA Security Rule Enough to Protect Electronic Personal Health Information (PHI) in the Cyber Age?<\/a> <i>J. Health Care Finance<\/i> <b>43,<\/b> (2016).<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Plenty of practices read the scope of HIPAA, notice they do not conduct the covered electronic transactions, and conclude the law does not reach them.<\/p>\n","protected":false},"author":1,"featured_media":1980,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"Does HIPAA Apply to Your Practice? Probably, Yes (2026) - Spruce Blog","description":"You can be outside HIPAA's federal scope and still lose a lawsuit over it. Why cash-only and paper-chart practices are not exempt in practice."},"footnotes":""},"categories":[14],"tags":[16,15],"different-template":[],"class_list":["post-1960","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hipaa","tag-compliance","tag-hipaa"],"acf":[],"_links":{"self":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/1960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/comments?post=1960"}],"version-history":[{"count":2,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/1960\/revisions"}],"predecessor-version":[{"id":6173,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/1960\/revisions\/6173"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media\/1980"}],"wp:attachment":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media?parent=1960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/categories?post=1960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/tags?post=1960"},{"taxonomy":"different-template","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/different-template?post=1960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}