According to HHS.gov, the only entities that must follow HIPAA regulations are health plans, most health care providers, and health care clearinghouses. Additionally, there are exceptions to the rule, including "preventing or controlling disease, injury, or disability".