HIPAA’s privacy and security

Why do HIPAA’s privacy and security requirements cover some health care entities and not others? How might an entity not covered by HIPAA pose a risk to a health care provider or organization?