The short version
HIPAA binds three kinds of organization, called covered entities:
- Health plans. Insurers, HMOs, employer group health plans, Medicare and Medicaid.
- Healthcare clearinghouses. The billing intermediaries that reformat claims data between providers and insurers.
- Healthcare providers who send claims and similar transactions electronically, which in practice is nearly all of them.
It also reaches the vendors those organizations hire to handle health information for them, called business associates. A billing company or a records-storage service working for your hospital is covered because it's doing the hospital's work.
That's the whole list. If an organization isn't on it, HIPAA doesn't apply to them, no matter how sensitive the information is.
The thing most people get backwards
HIPAA restricts what your providers can disclose about you. It puts no limits on you.
You can tell anyone anything about your own health. You can share your test results, post your diagnosis, hand your records to a family member, or record your own appointment. None of that is a HIPAA problem, because HIPAA was never pointed at you.
A patient cannot violate HIPAA by sharing their own information. If you've ever been told you can't have or share something about your own care "because of HIPAA," that was wrong.
Where people think it applies but it doesn't
Your employer
Employers aren't covered entities. Health information your employer holds as your employer, like sick leave records, FMLA paperwork or a doctor's note you handed to HR, generally isn't protected health information under HIPAA at all.
Other laws may protect it, the Americans with Disabilities Act among them, but not this one. The exception is that an employer's health plan is a covered entity even when the employer isn't, so a company running a self-insured plan has to keep that plan's information walled off from ordinary employment decisions.
Your child's school
Student records, including health records held by a school, generally fall under FERPA rather than HIPAA. Most public schools aren't covered entities, even ones employing a nurse or a psychologist, because they don't run the electronic transactions that trigger HIPAA.
Most of the apps on your phone
A fitness tracker, a period tracker, a symptom diary you downloaded yourself: none of these are covered entities. They're handling your health information without HIPAA applying to any of it.
That surprises people, and it's the reason to read an app's privacy policy rather than assume a law is doing the work. Other rules do apply to these apps, including the Federal Trade Commission's health breach notification rule, but HIPAA generally isn't among them.
People who overhear things
A stranger in a waiting room, a friend you told, a relative who repeats your diagnosis at dinner. None of them are covered entities. It might be a betrayal. It isn't a HIPAA violation.
What HIPAA actually gives you
The part worth knowing is the part nobody invokes. HIPAA gives you rights over your own records:
- The right to get your records. Your providers have to give you a copy, generally within 30 days, in the form you ask for where they can manage it. They can charge a reasonable, cost-based fee, but they can't refuse because you owe them money. How to actually exercise it is its own guide.
- The right to ask for corrections. If something in your record is wrong, you can request an amendment. They don't have to agree, but they have to respond and let you file a statement of disagreement.
- The right to know where it went. You can request an accounting of certain disclosures.
- The right to direct it somewhere. You can tell a provider to send your records to a person or place you choose.
That first one matters more than people realize. If you're seeing providers in more than one health system, you are usually the only one entitled to all of it, and asking for a copy at each visit is the most reliable way to have a complete picture.
How this applies to Rootwise
Rootwise isn't a covered entity. It isn't a health plan, a clearinghouse, or a provider, and it isn't handling information on behalf of one. It's a tool you use directly, for your own records, so HIPAA doesn't govern it.
That's a statement about which law applies, not about how carefully we handle your information. Audio is deleted once your summary is saved, transcripts are never kept, summaries are readable only by you, and nothing is sold or shared. Our Privacy Policy sets out all of it, and the FAQ covers the common questions.
Keep your own copy
Rootwise turns an appointment into a plain-language summary and a task list you can put on your calendar, kept in one place you control rather than a portal belonging to one health system.
Join the Early Access ListThis is general information, not legal advice. HIPAA is a large rule with exceptions this page doesn't cover, and how it applies to a particular situation depends on facts we can't know. Nothing here creates an attorney-client relationship. If something turns on the answer, talk to a lawyer.
Reviewed August 2026. Rootwise does not diagnose, treat, or advise, and does not provide legal services.