That’s not true.
(Following explanation has been edited significantly to accurately describe how HIPAA applies beyond insurance transactions; original was overly broad.)
HIPAA was centrally about insurance (it is the “Health Insurance Portability and Accountability Act”), and only covers providers who conduct certain insurance-related transactions electronically, but the privacy positions apply to conduct by those covered healthcare providers generally as well as the whole chain of insurance transactions connected to them (not just to the content of covered insurance transactions, or patients involved in those transactions), it was put in the bill to address concerns with the standardization and promotion of electronic transactions and standard identifiers for insurance transactions, which critics feared would result in a health care privacy apocalypse, but it applies beyond the scope of the insurance transactions.