Skip to Main Content Back to Top Let's Talk
Home Blog What employers need to know about HIPAA privacy and security rules

What employers need to know about HIPAA privacy and security rules

Doctor typing medical information on a laptop in a hospital office
Higginbotham H logo

When most HR professionals think about HIPAA, they think about protecting employees’ medical information. While that’s certainly part of the law, HIPAA compliance for employer-sponsored health plans is often more nuanced than many HR team members realize.

Whether your organization sponsors a fully insured, level-funded or self-funded health plan, understanding your responsibilities under HIPAA’s Privacy, Security and Breach Notification Rules can help reduce compliance risk and protect sensitive health information.

Background on HIPAA

The Health Insurance Portability and Accountability Act (HIPAA), signed into law in 1996, was designed to improve the portability of health insurance coverage and establish standards for protecting individuals’ health information as electronic health care transactions became more common.

Later, the Health Information Technology for Economic and Clinical Health (HITECH) Act strengthened HIPAA’s privacy and security requirements and expanded many compliance obligations to business associates that handle protected health information.

Although employers themselves are generally not regulated directly by HIPAA, employer-sponsored group health plans often are. As a result, employers that sponsor group health plans typically have compliance responsibilities related to those plans.

Three Components of HIPAA Compliance

HIPAA compliance centers around three primary rules:

  1. Privacy Rule: Governs how protected health information (PHI) may be used and disclosed, establishes individuals’ rights regarding their health information and requires health plans to safeguard PHI
  2. Security Rule: Focuses specifically on protecting electronic protected health information (ePHI) by maintaining its confidentiality, integrity and availability
  3. Breach Notification Rule: Establishes requirements for identifying, evaluating and reporting breaches involving unsecured PHI

For employers, the extent of these obligations largely depends on two factors:

  1. Whether the health plan is fully insured, level-funded or self-funded
  2. For fully insured plans, whether the employer has access to PHI beyond limited enrollment information

What counts as protected health information?

Protected health information is individually identifiable health information that relates to an individual’s past, present or future physical or mental health and is maintained or transmitted by a covered entity or business associate. However, not every piece of employee medical information is considered PHI.

For example, employment records generally are not subject to HIPAA. This means information collected for employment purposes, such as drug testing results, Family and Medical Leave Act (FMLA) documentation or disability accommodation records, is typically governed by laws other than HIPAA.

Another important distinction is summary health information (SHI). SHI summarizes claims experience or health plan costs but removes nearly all personal identifiers. Employers that only receive SHI and enrollment information generally have fewer HIPAA obligations than employers that access identifiable PHI.

HIPAA Employer Responsibilities

An employer’s HIPAA responsibilities depend heavily on how its health plan is structured.

Fully Insured Plans

Employers with fully insured health plans generally fall into one of two categories, depending on the type of health information they can access:

  • Hands-Off Plans: If an employer only receives enrollment and disenrollment information along with summary health information, the plan is usually considered “hands-off.” These employers are exempt from many of HIPAA’s administrative privacy requirements. However, they must still respect employees’ HIPAA rights and cannot retaliate against employees who file good-faith complaints or require employees to waive those rights as a condition of plan enrollment.
  • Hands-On Plans: If an employer has access to PHI beyond enrollment and disenrollment information or SHI, such as claims data, it is generally considered a “hands-on” plan. In these situations, the employer assumes many of the same responsibilities under the HIPAA Privacy and Security Rules as a self-funded plan sponsor.

Level-Funded Plans

Level-funded plans often create confusion. Although employers may have limited access to PHI depending on the insurance carrier or third-party administrator, level-funded plans are typically treated as self-funded for HIPAA compliance purposes. This means that employers sponsoring these plans should generally comply with the full HIPAA Privacy and Security Rules.

Self-Funded Plans

Self-funded group health plans generally have broader HIPAA compliance responsibilities. Employers that receive PHI to perform plan administration functions must also follow HIPAA requirements that govern how that information is used and disclosed. Let’s explore these responsibilities for each of the three HIPAA rules.

HIPAA Privacy Rule Requirements

Employers sponsoring health plans for their employees must make sure those health plans, as covered entities, operate in compliance with HIPAA privacy requirements. However, the HIPAA Privacy Rule is clear that employers with hands-off plans are exempt from many of the administrative requirements of the Privacy Rule.

Plans that provide PHI to the employer for plan administration (typically hands-on, level-funded and self-funded plans) generally have more extensive HIPAA requirements. Depending on the arrangement, compliance requirements may include:

  1. Conduct an inventory of all PHI that is used to administer the health plan and document where the information is stored, how it is transmitted and who has access to it.
  2. Develop a set of written policies and procedures that address the plan’s use and disclosure rules, the handling of individual rights requests (including complaints) and the documentation of compliance with specific administrative requirements, such as a sanctions process and employee training.
  3. Name a privacy official.
  4. Develop and distribute a Notice of Privacy Practices.
  5. Develop and implement safeguards for protecting PHI from improper use and disclosure.
  6. Ensure the health plan documents, such as ERISA wrap documents, contain the required provisions governing the employer/plan sponsor’s use and disclosure of PHI for plan administration purposes.
  7. Identify business associates and ensure proper agreements are in place.

Two doctors in hospital hallway discussing an electronic patient record

HIPAA Security Rule Requirements

While the Privacy Rule applies to PHI in any format, the HIPAA Security Rule applies to group health plans that create, receive, maintain or transmit electronic protected health information. When an employer receives ePHI from the plan in order to perform plan administration functions, the plan documents must require the employer to appropriately safeguard that information.

For employers with access to ePHI, HIPAA Security Rule responsibilities generally include conducting a documented security risk analysis, maintaining written security policies and procedures, designating a security official, providing security awareness training and implementing appropriate administrative, physical and technical safeguards.

Employers with fully insured health plans that do not receive ePHI for plan administration generally have more limited compliance responsibilities. Still, even these employers should document their limited access, designate a security official, confirm their insurance carrier has appropriate safeguards in place and establish procedures for responding to potential breaches.

HIPAA Breach Notification and Reporting

The HIPAA Breach Notification Rule defines a breach as the unauthorized acquisition, access, use or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the information. There are three exceptions to this:

  1. An unintentional acquisition, access or use of PHI by a workforce member acting under the authority of a covered entity or business associate
  2. An inadvertent disclosure of PHI from one person authorized to access PHI to another person authorized to access PHI
  3. Unauthorized PHI disclosure in which an unauthorized person would not have reasonably been able to retain the information

If no exceptions apply, the impermissible use or disclosure of PHI is generally presumed to be a breach unless the covered entity (i.e., the group health plan) or business associate demonstrates through a risk assessment that there is a low probability that the PHI was compromised. According to the U.S. Department of Health and Human Services (HHS), this assessment should consider:

  • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
  • The unauthorized person who used the PHI or received the unauthorized disclosure
  • Whether the PHI was actually acquired or viewed
  • The extent of mitigation, including actions taken to reduce the risk associated with the use or disclosure

Responding to a Data Breach

The HITECH Act amended HIPAA to add breach notification requirements for unsecured PHI. Following the discovery of a breach, covered entities must notify:

  • Affected Individuals: No later than 60 days after discovery of the breach
  • The Media: No later than 60 days after discovery, if the breach affects more than 500 residents of a state or jurisdiction
  • HHS: No later than 60 days after the end of the calendar year in which the breach was discovered if fewer than 500 individuals were affected, or no later than 60 days after discovery of the breach if 500 or more individuals were affected

Building a Compliant Benefits Strategy

Managing employee benefits today involves much more than selecting health plans. It also requires understanding the compliance responsibilities that come with administering those plans.

Whether you’re evaluating your current benefits program, considering a new funding arrangement or looking for guidance on managing prescription drug costs, Higginbotham’s employee benefits team can help. Connect with a Higginbotham benefits consultant to discuss your benefits strategy and learn how we can help support your goals.

Not sure where to start? Talk to someone who wants to listen.

A great plan starts with a conversation. Let’s talk about what you need.

Let’s Talk

Request a Quote

Woman with glasses smiling in bright office looking off camera
Higginbotham H logo