Skip to main content
Employer Benefits IQ
HIPAA compliance

HIPAA for Employer Health Plans

HIPAA applies to employer health plans — not to employers as employers. That distinction matters enormously. The plan is a covered entity. The employer in its capacity as employer is not. The firewall between these two roles is one of the most commonly misunderstood and most frequently violated aspects of HIPAA compliance for self-funded plans.

What HIPAA applies to — and what it doesn't

The most important HIPAA concept for employers is the distinction between the health plan (a covered entity) and the employer (not a covered entity in its employment capacity). PHI flows through the plan. Employment records are not PHI. The firewall rule — which requires plan documents to restrict the employer's access to PHI — exists precisely to maintain this separation.

Self-funded health plans: The plan itself is a covered entity. Full privacy and security rule obligations apply.
Fully insured health plans: Limited obligations — primarily the firewall rule and plan document amendment. The carrier handles most compliance.
The employer acting as employer: HIPAA does not apply to the employer in its capacity as employer — only to the health plan. The firewall separates these roles.
Employer HR and payroll functions: Employment records are not PHI. HIPAA does not govern how employers handle employee HR data.
Workers' compensation: Workers' comp is not a health plan under HIPAA. Different privacy rules apply.
FSAs and HRAs: Flexible spending accounts and HRAs are health plans subject to HIPAA if they have more than one participant.

The firewall rule

The HIPAA firewall rule requires that plan documents restrict the employer's access to PHI from the health plan. The employer may only receive PHI from the plan for limited purposes — enrollment, disenrollment, eligibility determinations, and plan administration. The employer may not use PHI received from the plan for employment decisions. Violating the firewall — for example, using claims data to make termination decisions — is a HIPAA violation regardless of whether the employer intended harm.

Privacy rule requirements for self-funded plans

Privacy officer: Designate a privacy officer responsible for developing and implementing privacy policies and procedures.
Notice of Privacy Practices (NPP): Provide participants with a written NPP describing how PHI is used and disclosed. Must be provided at enrollment and upon request.
Minimum necessary standard: Use, disclose, and request only the minimum PHI necessary to accomplish the intended purpose.
Business associate agreements (BAAs): Execute BAAs with all vendors who receive PHI on behalf of the plan — TPAs, PBMs, stop-loss carriers, wellness vendors.
Participant rights: Provide participants with rights to access, amend, and receive an accounting of disclosures of their PHI.
Workforce training: Train all workforce members who handle PHI on privacy policies and procedures.

Security rule requirements for self-funded plans

The security rule applies to electronic PHI (ePHI). For most self-funded employers, the TPA handles the bulk of ePHI — but the employer's plan document must include security provisions, and the employer must ensure its TPA has executed a BAA that covers security obligations.

Security officer: Designate a security officer responsible for developing and implementing security policies.
Risk analysis: Conduct a thorough assessment of potential risks and vulnerabilities to electronic PHI (ePHI). Must be documented and updated regularly.
Risk management: Implement security measures sufficient to reduce identified risks to a reasonable and appropriate level.
Access controls: Implement technical policies to allow access to ePHI only to authorized persons.
Audit controls: Implement hardware, software, and procedural mechanisms to record and examine access to ePHI.
Transmission security: Implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic networks.

Common HIPAA violations for employer health plans

Sharing PHI with the employer's HR or payroll functions without a valid HIPAA authorization (firewall violation)
Failing to execute BAAs with all vendors who receive PHI — including cloud storage providers and IT vendors
Using PHI for employment decisions — termination, promotion, job assignment
Failing to conduct and document a security risk analysis
Inadequate access controls allowing unauthorized employees to view PHI
Failing to provide participants with a current Notice of Privacy Practices
Not training new employees who handle PHI before they access it
Failing to report a breach to HHS and affected individuals within required timeframes
Related tools
Compliance Health Check

Score your plan's HIPAA compliance posture.

SPD IQ™

AI review of your SPD for HIPAA and ERISA compliance gaps.

Free tool

Check your plan's HIPAA compliance posture

The Compliance Health Check evaluates your plan's HIPAA privacy and security program — BAAs, firewall provisions, privacy officer designation, and more.