That information is tainted with the restrictions and keeps them regardless of where it goes. If it gets disclosed outside of that it becomes a violation.
So nobody working for a hospital you get care for can disclose things. Nobody the hospital hires to provide services or handle your data, etc.
You can sign away those rights or give your own information away.
If the data doesn't come up through a relationship with a healthcare provider, it's not PHI.
There are some carve outs. For example, financial services companies don't have any additional privacy requirements if you buy a prescription with your Visa instead of cereal. That carve out was specifically added to the HIPAA legislation.
https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg...
Note that this is a high-level summary.
I think this just means health care industry and those who build systems for health care information?
Going to keep researching, but I don't think that it applies to literally every workplace.