If you sponsor a self-funded health plan, you're a Covered Entity under 45 CFR § 160.103. This means you have the same HIPAA obligations as a hospital. You're facing a compliance decision: handle everything internally, partner with specialists, or rely on your Third-Party Administrator (TPA).
Recently, Star Group Health Benefits Plan paid $245,000 to settle an OCR investigation after a ransomware attack exposed PHI for over 9,000 individuals. The core violation was a failure to conduct an accurate and thorough risk analysis. This penalty underscores the importance of choosing the right compliance model for your organization.
The Decision You're Facing
You must meet three categories of HIPAA Security Rule requirements: administrative safeguards (policies, training, risk analysis), physical safeguards (facility access, workstation security), and technical safeguards (access controls, audit logs, encryption). You can build and maintain this program internally, contract it to a compliance partner, or assume your TPA has it covered.
Choosing the wrong path leaves you exposed during an OCR investigation. The right choice depends on your workforce size, IT maturity, and risk tolerance.
Key Factors That Affect Your Choice
Internal IT and compliance staffing. Do you have dedicated IT security personnel who understand healthcare regulations? Can your HR or legal team write and maintain HIPAA policies, conduct annual risk analyses, and document everything OCR expects?
Plan complexity and data flow. If you're processing claims in-house or integrating multiple vendors (wellness platforms, telemedicine, pharmacy benefit managers), you're managing more touchpoints where ePHI moves. Each integration increases your risk surface and documentation burden.
TPA contract scope. Review your TPA agreement. Does it explicitly assign HIPAA Security Rule compliance responsibilities to the TPA, or does it limit their role to claims processing? Most TPAs handle claims data securely, but they don't conduct your risk analysis, train your workforce, or write your incident response plan. If the contract is silent on those duties, you still own them.
Tolerance for regulatory risk. An OCR investigation will request your most recent risk analysis, your policies and procedures, your training records, and your Business Associate Agreements. If you can't produce current, thorough documentation within days, you're negotiating from a weak position.
Path A: Build Compliance In-House
Choose this path if:
- You employ IT security staff with healthcare compliance experience
- You have legal or compliance personnel who can draft and update HIPAA policies annually
- Your plan administration is straightforward (single TPA, minimal vendor integrations)
- You're prepared to budget 200+ hours per year for risk assessments, policy updates, training delivery, and audit prep
- You want direct control over every compliance decision and timeline
What you'll need to execute:
Conduct an enterprise-wide risk analysis under § 164.308(a)(1)(ii)(A) that inventories where ePHI is created, received, maintained, or transmitted. Update it annually and after any significant system change. Develop written policies covering each Required and Addressable Specification in the Security Rule. Deliver role-based workforce training annually, with documentation proving attendance and comprehension. Maintain a sanction policy for violations. Establish an incident response protocol that triggers breach notification obligations under the Breach Notification Rule. Negotiate and execute Business Associate Agreements with every vendor that touches PHI.
The risk:
If your internal team misses a requirement or documents it poorly, you won't know until OCR requests your files. Compliance gaps discovered during an investigation convert into settlement negotiations, and you're building your defense after the fact.
Path B: Partner with a Compliance Specialist
Choose this path if:
- You lack in-house HIPAA expertise or your IT team is stretched thin
- You want a documented, auditable compliance program without hiring additional FTEs
- You need breach response support and don't want to figure out OCR notification timelines under pressure
- You prefer a turnkey solution that includes risk assessment, policy templates, training delivery, and ongoing updates as regulations evolve
What you'll get from a qualified partner:
A structured risk analysis that identifies specific vulnerabilities in your ePHI handling and produces a remediation roadmap. Customized policies and procedures that match your operational reality, not generic templates. Annual workforce training tailored to role-specific responsibilities (claims processors need different training than executives). Breach coaching and audit support if OCR opens an investigation. Regular updates when HHS issues new guidance or enforcement priorities shift.
The risk:
You're trusting an external party to understand your environment and deliver compliant documentation. Vet the partner carefully: ask for sample risk analysis reports, confirm they understand the distinction between Required and Addressable Specifications, and verify they offer breach response support, not just annual training modules.
Path C: Rely on Your TPA
Choose this path only if:
Your TPA contract explicitly assigns HIPAA Security Rule compliance responsibilities to the TPA in writing, and the TPA agrees to indemnify you for compliance failures within their scope.
Why this path is rarely viable:
Most TPA agreements limit the administrator's role to claims processing and member services. They'll secure their own systems and sign a Business Associate Agreement, but they won't conduct your risk analysis, train your workforce, or write your incident response plan. The plan sponsor remains the Covered Entity, and OCR will investigate you, not your TPA, if a breach occurs.
Review your contract. If it doesn't say "TPA will conduct an annual enterprise risk analysis for the Plan and provide documented policies meeting all HIPAA Security Rule specifications," you're still responsible for those tasks.
Summary Matrix
| Factor | In-House | Compliance Partner | TPA-Dependent |
|---|---|---|---|
| Staffing requirement | High (dedicated IT/compliance FTEs) | Low (vendor manages program) | Minimal (if TPA truly owns it) |
| Upfront cost | Low (internal labor) | Moderate (annual contract) | Low (bundled with TPA fees) |
| Ongoing effort | High (continuous updates, training, documentation) | Low (partner handles updates) | Minimal (if scope is clear) |
| Breach support | You coordinate with legal counsel | Partner provides OCR response coaching | Depends on contract terms |
| Audit readiness | Depends on internal rigor | Partner ensures documentation is current | High risk if TPA scope is unclear |
| Best for | Large employers with compliance teams | Mid-size plans without dedicated staff | Rarely a complete solution for plan sponsors |
If you're unsure whether your TPA has actually assumed your HIPAA obligations, request a copy of their most recent risk analysis for your plan and ask when they last trained your workforce. If they can't produce those documents, you're operating under Path A or Path B whether you intended to or not.
The Star Group settlement makes one thing clear: OCR expects employer-sponsored plans to meet the same standards as hospitals. Choose the compliance path that lets you produce thorough documentation on demand, because the next ransomware attack won't wait for you to figure out your responsibilities.



