Which groups at Stanford are subject to the HIPAA Privacy and Security Rules?
Entities covered by HIPAA are health care providers, health plans (including employer’s sponsored plans), and healthcare clearing houses (e.g., billing agent). Stanford Hospital, Lucile Packard Children’s Hospital, and portions of Stanford University are Covered Entities as health care providers. Health information collected and/or used by our medical staff and clinical research projects are PHI and subject to the Privacy and Security Rules. Since not all of Stanford University’s functions meet the definition of a Covered Entity, Stanford has excluded certain programs that have no need to create, use, receive or disclose PHI from the Covered Entity. For example, the School of Education and the School of Law are not included in the Stanford University HIPAA Components (SUHC). SUHC is the group of health care components of Stanford University that are its health care providers (e.g., School of Medicine, Vaden Health Center) and selected support units which by the nature of their function