Group Health Plan
A group health plan is health insurance coverage that is offered to a group of people, typically employees, by an employer, union, or association rather than purchased individually. In most cases, an employer or organization sponsors the plan so its members or workers can receive medical benefits while they are still working. Group plans differ from individual plans, which a person buys on their own.
A group health plan (GHP) is generally group medical or health insurance provided by an employer, union, or association to its employees or members. Group arrangements may involve a single employer or, in the case of association health plans, multiple employers joining together to offer benefits; size classifications such as 'large group' vary by state (in many states, 51 or more employees). Note that 'group health plan' also carries a specific regulatory meaning under HIPAA, where certain group health plans qualify as covered entities and are therefore subject to HIPAA Privacy, Security, and Breach Notification Rule obligations; the evidence provided here describes group health plans as an insurance concept and does not address that HIPAA-specific definition or scope. Readers should verify the precise HIPAA regulatory definition and any applicable thresholds against the current regulatory text, as additional requirements may apply under the HITECH Act and state law.
Why it matters
The term "group health plan" carries a dual significance that compliance professionals must handle carefully. In everyday usage it simply describes health insurance offered to a group of people, typically employees or members, by an employer, union, or association. Under HIPAA, however, "group health plan" also has a specific regulatory meaning: certain group health plans qualify as covered entities and are therefore directly subject to HIPAA Privacy, Security, and Breach Notification Rule obligations. Confusing the general insurance concept with the HIPAA-specific definition can lead to gaps in a compliance program, so the two meanings should be kept distinct.
For privacy and security officers, the practical importance lies in identifying whether a given group health plan meets the HIPAA covered entity definition and, if so, ensuring it addresses obligations across all three rules, recognizing that the Security Rule applies only to electronic protected health information (ePHI) while the Privacy Rule covers protected health information in all forms. The evidence provided here describes group health plans as an insurance concept and does not establish the HIPAA regulatory scope, so readers should verify the precise HIPAA definition and any applicable thresholds against the current regulatory text before drawing compliance conclusions.
Beyond HIPAA itself, group health plans may face additional or overlapping requirements under the HITECH Act and state law, and size-based classifications such as "large group" vary by state. Because these thresholds and definitions can differ across jurisdictions and change over time, treating a plan's compliance posture as settled based on the general insurance meaning alone is generally not advisable.
Who it's relevant to
Inside GHP
Common questions
Answers to the questions practitioners most commonly ask about GHP.