I think it's still incorrect to disregard the entity. HIPAA only creates privacy obligations to Covered Entities and Business Associates.
It doesn't apply obligations to all people who might receive Protected Health Information.
If a hospital makes an error, and emails the medical charts for a public figure to a journalist, the journalist has no obligations under HIPAA. They would be free to publish the information, to store it without privacy safeguards, etc.
The data remains PHI, but the journalist is not required to follow the HIPAA privacy rule. Though, I again think it would generally be better if the voluntarily did so.
By my (again, also a non-lawyer understanding) the privacy rule is a venn diagram that only applies if:
- You are a Covered Entity or Business Associate, AND
- The data being handled is Protected Health Information