BUSINESS LITIGATION Missouri State Guide

HIPAA Compliance for Missouri Businesses: What's Required

ARTICLE
Read time
8 min read
Updated
June 10, 2026
QUICK ANSWER

HIPAA is a federal law, and it does not apply to every Missouri business that touches health information. It reaches only two kinds of organizations: covered entities — health plans, health-care clearinghouses, and most health-care providers — and the business associates (vendors) that handle protected health information on their behalf. If you are one of these, you must safeguard health data under HIPAA's Privacy, Security, and Breach Notification Rules; if not, HIPAA generally leaves you alone, even though other laws may not.

This guide explains who must comply, what HIPAA requires, how a covered organization differs from a business that merely handles some health data, what enforcement looks like, and how HIPAA interacts with Missouri's own confidentiality and breach-notification rules. Because the details are fact-specific and the regulations change, treat this as a framework, not a substitute for advice tailored to your operations.

What HIPAA is — and that it is federal

The Health Insurance Portability and Accountability Act (HIPAA) is a federal statute, implemented through regulations at 45 C.F.R. Parts 160 and 164 and enforced by the U.S. Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR). Nothing in the Missouri Revised Statutes "is" HIPAA — Missouri law can add obligations on top of it, but HIPAA itself is purely federal.

HIPAA protects protected health information (PHI) — individually identifiable health information a regulated organization holds or transmits, whether on paper, electronically, or spoken. One feature surprises many business owners: HIPAA creates no private right of action. An individual harmed by a HIPAA violation cannot sue the offending business under HIPAA itself. Enforcement runs through OCR (and, for some violations, the U.S. Department of Justice), not private HIPAA lawsuits. Affected individuals may have other claims under state law, but the statute itself is government-enforced.

Who must comply: covered entities and business associates

HIPAA's obligations attach to your role, not merely to the fact that you possess health data.

Covered entities

A covered entity is one of three:

  • Health plans — health insurers, HMOs, employer-sponsored group health plans, and similar payers.
  • Health-care clearinghouses — organizations that process health information into or out of standard formats (for example, billing clearinghouses).
  • Health-care providers who transmit health information electronically in connection with certain standard transactions, such as billing a health plan. A Missouri physician's office, dental practice, hospital, pharmacy, or physical-therapy clinic that bills insurance electronically is the classic covered entity.

Business associates

A business associate is a person or company that creates, receives, maintains, or transmits PHI on behalf of a covered entity — billing companies, cloud-hosting and EHR vendors, document-shredding services, IT consultants with record access, and law or accounting firms that handle PHI for a provider. Business associates are directly liable under HIPAA for much of the Security Rule and parts of the Privacy Rule — they are not merely contract partners. A business associate's own subcontractors that handle PHI are themselves business associates, so the obligations flow down the chain.

What HIPAA requires: the three rules

HIPAA's substantive duties live in three rules.

  • The Privacy Rule governs how PHI may be used and disclosed. It limits disclosures to the minimum necessary, requires patient-facing notices of privacy practices, and gives individuals rights to access, amend, and obtain an accounting of disclosures of their records.
  • The Security Rule requires administrative, physical, and technical safeguards for electronic PHI (ePHI) — a written risk analysis, access controls and unique user IDs, audit logging, encryption where reasonable and appropriate, training, and contingency planning. It applies only to electronic PHI; the Privacy Rule covers PHI in any form.
  • The Breach Notification Rule requires notifying affected individuals and HHS — and, for larger breaches, the media — when unsecured PHI is breached. Notice to individuals is generally required without unreasonable delay and no later than 60 days after discovery; breaches affecting 500 or more residents of a state trigger faster, broader notice.

Business associate agreements (BAAs)

A foundational requirement is the business associate agreement (BAA) — a written contract a covered entity must put in place before sharing PHI with a vendor, and that a business associate must in turn execute with its subcontractors. The BAA obligates the vendor to safeguard PHI, use it only as permitted, and report breaches. For a Missouri provider using an outside billing service, EHR platform, or cloud host, a missing or stale BAA is among the most common and most avoidable compliance gaps OCR finds.

Covered vs. "just handles some health data"

The single most misunderstood point about HIPAA is that it is role-specific, not health-data-specific. Holding health-related information does not, by itself, make a business subject to HIPAA. Consider the contrast:

  • A dermatology clinic that bills insurers electronically is a covered entity; everything it does with PHI runs through HIPAA.
  • A fitness studio, wellness app, or employer wellness program may collect a great deal of health-related data yet not be a covered entity or business associate at all, so HIPAA generally does not reach it.

If your business is neither a covered entity nor a business associate, HIPAA usually does not apply even though you hold health-related data — but that data is not unregulated. The FTC Act can reach unfair or deceptive data practices, and Missouri's breach-notification statute (below) reaches the personal information you hold regardless of HIPAA. Escaping HIPAA is not escaping all obligations.

Enforcement and penalties

HIPAA is enforced primarily by OCR, which investigates complaints, conducts compliance reviews, and resolves matters through corrective-action plans or monetary settlements.

  • Civil penalties are tiered by culpability — from violations the organization neither knew about nor could reasonably have avoided, up through willful neglect that goes uncorrected. Per-violation amounts rise with each tier, are adjusted annually for inflation, and carry substantial annual caps per identical provision.
  • Criminal liability is possible for knowingly obtaining or disclosing PHI in violation of HIPAA, prosecuted by the U.S. Department of Justice; penalties rise when the conduct involves false pretenses or intent to sell or misuse the information, and can include imprisonment.

Because there is no private right of action under HIPAA, the enforcement risk is governmental, not patient lawsuits brought under HIPAA itself.

How HIPAA interacts with Missouri law

HIPAA sets a federal floor, not a ceiling: it expressly does not preempt state laws that are more protective of individuals' health information. So a Missouri covered entity must satisfy HIPAA and any stricter Missouri requirements that apply. Two Missouri overlays matter most:

  • Missouri data-breach notification — RSMo § 407.1500. Independent of HIPAA's Breach Notification Rule, RSMo § 407.1500 requires a business that owns or licenses personal information about Missouri residents to notify affected individuals without unreasonable delay when that information is breached in a way that poses a risk of harm; notice to the Missouri Attorney General may also be required above a statutory threshold. A single incident — say, a stolen unencrypted laptop with patient names and Social Security numbers — can trigger both HIPAA breach duties and the RSMo § 407.1500 duty at once.
  • Missouri medical-confidentiality and records rules. Missouri's professional-licensing and physician-patient confidentiality principles, and its rules on access to and release of medical records, can impose duties alongside HIPAA. Where Missouri demands more, the more protective rule governs.

Do not assume HIPAA compliance alone discharges every obligation — confirm the Missouri-specific layer, especially before responding to a breach.

Frequently Asked Questions

Is HIPAA a Missouri law or a federal law?

HIPAA is a federal law — the Health Insurance Portability and Accountability Act, with rules at 45 C.F.R. Parts 160 and 164, enforced by the U.S. Department of Health and Human Services through its Office for Civil Rights. Missouri's own confidentiality and breach-notification rules can add obligations, but HIPAA itself is federal.

Does my business have to comply with HIPAA just because it has health data?

Not necessarily. HIPAA applies to covered entities (health plans, clearinghouses, and most providers) and their business associates — not to every business holding health-related information. If you are neither, HIPAA generally does not apply, though the FTC Act and Missouri's breach statute (RSMo § 407.1500) may still reach that data. It turns on your role, not the data type.

What is a business associate agreement, and do I need one?

A business associate agreement (BAA) is a written contract HIPAA requires before a covered entity shares PHI with a vendor that handles it on the entity's behalf — a billing company, cloud host, or IT contractor. A HIPAA-covered Missouri provider generally needs a BAA with each such vendor, and business associates need BAAs with their subcontractors.

Can an individual sue my business under HIPAA?

No — HIPAA creates no private right of action, so an individual cannot sue your business under HIPAA itself. Enforcement runs through the Office for Civil Rights (and the Department of Justice for criminal matters). Affected individuals may still pursue separate claims under state law, but not under the HIPAA statute.

What does the HIPAA Security Rule require?

The Security Rule requires administrative, physical, and technical safeguards for electronic PHI — a written risk analysis, access controls, audit logging, encryption where reasonable and appropriate, training, and contingency planning. It covers electronic PHI specifically; the Privacy Rule covers PHI in any form.

If we have a breach, do we follow HIPAA or Missouri's breach law?

Often both. HIPAA's Breach Notification Rule and Missouri's RSMo § 407.1500 operate independently, and one incident can trigger each set of duties at once. Because HIPAA sets a federal floor and Missouri can require more, assess both — promptly — and meet the stricter timeline that applies.

This guide provides general legal information about HIPAA and related Missouri law and is not legal advice. It does not create an attorney-client relationship. HIPAA obligations depend heavily on your organization's role, the data you handle, and the current text of the applicable federal regulations and Missouri statutes; consult a qualified Missouri attorney about your situation, and act promptly if you suspect a data breach.