If your organization sponsors a self-funded health plan, you're a Covered Entity. This isn't just a technicality, it's a compliance obligation that federal regulators are actively enforcing. The Office for Civil Rights (OCR) recently settled a $450,000 enforcement action with Spencer Gifts LLC following a ransomware attack that exposed ePHI of over 10,000 plan participants. The investigation revealed a common issue: organizations running corporate health plans without conducting risk analyses or implementing HIPAA policies.
This guide provides the framework you need to build and maintain compliant health plan operations.
Scope: What This Guide Covers
This guide addresses HIPAA compliance obligations for organizations that sponsor employer-sponsored group health plans, specifically:
- Self-funded (self-insured) health plans
- Level-funded health plans
- Flexible benefits and welfare benefit plans
Out of scope: Fully insured plans where the insurance carrier assumes primary compliance responsibility. If you write a check to a carrier and they handle everything else, your compliance burden is minimal. If you're self-funding and managing claims internally or through a TPA, keep reading.
Key Concepts and Definitions
Covered Entity status triggers
Your health plan becomes a Covered Entity under HIPAA if it meets either condition:
- It has 50 or more participants, OR
- It uses a Third-Party Administrator (TPA) to manage claims, enrollment, or benefits administration
The TPA delegation misconception
Hiring a TPA doesn't transfer your compliance obligations. You may delegate administration through a Business Associate Agreement (BAA), but you remain primarily responsible for implementing HIPAA Privacy and Security policies. If ePHI touches your HR systems, payroll files, or corporate email, you're directly accountable.
Lateral network access
When corporate IT infrastructure and health plan systems share network pathways, a breach in one domain can provide attackers lateral movement into health plan servers. This is how the Spencer Gifts breach unfolded: attackers gained VPN access, moved laterally across the network, and encrypted servers containing plan participant data.
Requirements Breakdown
Security Rule: Risk Analysis (45 C.F.R. § 164.308(a)(1)(ii)(A))
Required action: Conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
What "accurate and thorough" means:
- Identify where all ePHI resides (claims databases, enrollment files, HR systems, backup servers)
- Document potential threats (ransomware, insider access, vendor vulnerabilities)
- Assess current safeguards and identify gaps
- Assign risk levels and prioritize remediation
Frequency: This isn't a one-time exercise. Risk analysis must be ongoing. Conduct formal assessments annually at minimum, and whenever you add new systems, vendors, or data flows.
Privacy Rule and Security Rule: Policies and Procedures (45 C.F.R. § 164.316(a) & § 164.530(i)(1))
Required action: Implement written policies and procedures covering Privacy, Security, and Breach Notification requirements.
Essential policy domains:
- Access controls (who can view/modify ePHI)
- Workforce training and sanctions
- Incident response and breach notification
- Business Associate oversight
- Audit controls and monitoring
- Data retention and disposal
Breach Notification Rule: Reporting Obligations
If you discover a breach affecting 500 or more individuals, you must notify OCR within 60 days. Smaller breaches get reported annually. The Spencer Gifts breach affected 10,023 individuals and was reported to OCR in January 2022, triggering the multi-year investigation.
Implementation Guidance
Step 1: Inventory Your ePHI Touchpoints
Map every system that stores, processes, or transmits plan participant data:
- TPA platforms and portals
- Internal HR databases
- Payroll systems
- Email archives containing claims correspondence
- Backup and disaster recovery systems
Don't assume ePHI stays confined to your TPA's environment. If enrollment data syncs to your HRIS, or if HR staff email claim documents, you're handling ePHI directly.
Step 2: Segment Health Plan Systems from Corporate IT
Implement network segmentation to prevent lateral movement. Your health plan data should sit on isolated servers with strict access controls. If an attacker compromises a corporate workstation, they shouldn't be able to pivot directly into your benefits administration environment.
Technical controls to implement:
- VLANs or separate network zones for health plan systems
- Multi-factor authentication for any health plan access
- Role-based access controls (limit access to job function)
- Logging and monitoring for unusual access patterns
Step 3: Formalize Policies Before You Need Them
The Spencer Gifts investigation found that the organization operated without compliant HIPAA policies until after the breach occurred. Don't make that mistake.
Draft and implement policies covering:
- Workforce access authorization and termination procedures
- Incident response protocols (who gets notified, what gets documented, when you escalate)
- Vendor management and BAA requirements
- Training schedules and documentation
Step 4: Train Your Workforce and Document It
Everyone who touches ePHI needs HIPAA training. That includes:
- HR staff managing enrollment
- IT teams supporting health plan systems
- Finance personnel processing premium payments
- Executives with access to plan reports
Keep training logs for at least six years. If OCR investigates, they'll ask for proof.
Common Pitfalls
Pitfall 1: Assuming your TPA handles everything
Your TPA manages claims and enrollment, but they don't implement your internal policies, train your workforce, or secure your corporate network. You're still the plan sponsor and the Covered Entity.
Pitfall 2: Treating risk analysis as a checkbox
A risk analysis isn't a static document you generate once and file away. It's a living process. When you add a new HR system, migrate to cloud storage, or switch TPAs, your risk profile changes. Update your analysis accordingly.
Pitfall 3: Ignoring the corporate IT-health plan boundary
If your corporate VPN provides direct access to health plan servers, you've created a compliance vulnerability. Attackers exploit these shared pathways. The Spencer Gifts breach began with VPN access and spread laterally to health plan systems.
Pitfall 4: Undocumented compliance efforts
You might have strong security practices in place, but if you can't prove it with documentation, it doesn't count during an investigation. Maintain records of risk analyses, policy reviews, training completions, and vendor agreements.
Quick Reference Table
| Requirement | Citation | Action Required | Documentation Needed |
|---|---|---|---|
| Risk Analysis | 45 C.F.R. § 164.308(a)(1)(ii)(A) | Identify ePHI locations, assess vulnerabilities, prioritize remediation | Written risk analysis report, updated annually or when systems change |
| Policies and Procedures | 45 C.F.R. § 164.316(a) & § 164.530(i)(1) | Implement written Privacy, Security, and Breach Notification policies | Policy documents, version control, distribution records |
| Workforce Training | 45 C.F.R. § 164.530(b) | Train all workforce members who handle ePHI | Training logs, completion certificates, retained for 6+ years |
| Audit Controls | 45 C.F.R. § 164.312(b) | Implement systems to record and examine ePHI access | Access logs, monitoring reports, incident response records |
| Business Associate Agreements | 45 C.F.R. § 164.308(b)(1) | Execute BAAs with TPAs and vendors who handle ePHI | Signed BAA documents, vendor compliance attestations |
| Breach Notification | 45 C.F.R. § 164.404-414 | Report breaches affecting 500+ individuals within 60 days | Breach investigation reports, notification records, OCR submissions |
Bottom line: If you sponsor a self-funded health plan, you can't outsource accountability. Build your compliance program proactively, document everything, and segment your networks. OCR's enforcement actions make it clear that corporate health plans face the same scrutiny as traditional healthcare providers.



