Comment by warkdarrior

1 year ago

Depends who is selling that data. Some pharmacy delivery services or billing services may not be covered by HIPAA, since they are not necessarily "covered entities".

Is this true?

My understanding of HIPAA (possibly incorrect) is that it's attached to the data.

If a covered provider is leaking HIPAA covered data to a non-covered business associate entity... that's a big no-no and a fine.