Skip to main content
Category: Regulatory Framework

Group Health Plan

Also known as: GHP, group health insurance, group coverage, group medical insurance
Simply put

A group health plan is health insurance coverage that is offered to a group of people, typically employees, by an employer, union, or association rather than purchased individually. In most cases, an employer or organization sponsors the plan so its members or workers can receive medical benefits while they are still working. Group plans differ from individual plans, which a person buys on their own.

Formal definition

A group health plan (GHP) is generally group medical or health insurance provided by an employer, union, or association to its employees or members. Group arrangements may involve a single employer or, in the case of association health plans, multiple employers joining together to offer benefits; size classifications such as 'large group' vary by state (in many states, 51 or more employees). Note that 'group health plan' also carries a specific regulatory meaning under HIPAA, where certain group health plans qualify as covered entities and are therefore subject to HIPAA Privacy, Security, and Breach Notification Rule obligations; the evidence provided here describes group health plans as an insurance concept and does not address that HIPAA-specific definition or scope. Readers should verify the precise HIPAA regulatory definition and any applicable thresholds against the current regulatory text, as additional requirements may apply under the HITECH Act and state law.

Why it matters

The term "group health plan" carries a dual significance that compliance professionals must handle carefully. In everyday usage it simply describes health insurance offered to a group of people, typically employees or members, by an employer, union, or association. Under HIPAA, however, "group health plan" also has a specific regulatory meaning: certain group health plans qualify as covered entities and are therefore directly subject to HIPAA Privacy, Security, and Breach Notification Rule obligations. Confusing the general insurance concept with the HIPAA-specific definition can lead to gaps in a compliance program, so the two meanings should be kept distinct.

For privacy and security officers, the practical importance lies in identifying whether a given group health plan meets the HIPAA covered entity definition and, if so, ensuring it addresses obligations across all three rules, recognizing that the Security Rule applies only to electronic protected health information (ePHI) while the Privacy Rule covers protected health information in all forms. The evidence provided here describes group health plans as an insurance concept and does not establish the HIPAA regulatory scope, so readers should verify the precise HIPAA definition and any applicable thresholds against the current regulatory text before drawing compliance conclusions.

Beyond HIPAA itself, group health plans may face additional or overlapping requirements under the HITECH Act and state law, and size-based classifications such as "large group" vary by state. Because these thresholds and definitions can differ across jurisdictions and change over time, treating a plan's compliance posture as settled based on the general insurance meaning alone is generally not advisable.

Who it's relevant to

Employers and Plan Sponsors
Employers, unions, and associations that offer group coverage to their employees or members are the organizations that sponsor these plans. They should determine whether their group health plan meets the HIPAA covered entity definition, because that determination generally drives which HIPAA obligations apply. This should be verified against the current regulatory text rather than assumed.
Privacy and Security Officers
Officers responsible for HIPAA compliance need to distinguish the general insurance meaning of "group health plan" from the HIPAA-specific regulatory definition. Where a plan qualifies as a covered entity, they must address Privacy Rule obligations for protected health information in all forms and Security Rule obligations for ePHI, along with Breach Notification Rule requirements.
Compliance and Legal Professionals
Legal and compliance staff should confirm whether state law size classifications (such as the 51-or-more-employees "large group" threshold in many states) and additional requirements under the HITECH Act or state law apply, since these may impose obligations beyond HIPAA and vary by jurisdiction.
Association Health Plan Administrators
Administrators of association health plans, where multiple employers join together to offer medical benefits, should be aware that the multi-employer structure can affect how the plan is classified and which regulatory obligations attach, and should verify these against current guidance.

Inside GHP

Definition Under HIPAA
A group health plan is generally an employee welfare benefit plan that provides medical care to employees or their dependents, whether through insurance, reimbursement, or otherwise. Under the HIPAA rules it is one type of health plan that can qualify as a covered entity, subject to the Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule as applicable.
Covered Entity Status
As a health plan, a group health plan generally meets the definition of a covered entity, meaning HIPAA obligations attach directly to it rather than only flowing through contractual relationships. The specific obligations depend on factors such as size and whether the plan is self-insured or fully insured.
Plan Sponsor Relationship
A group health plan is typically established or maintained by a plan sponsor (commonly an employer or union). The plan and the sponsor are distinct; the sponsor is generally not itself the covered entity, and disclosures of PHI to the sponsor are subject to specific Privacy Rule conditions, often including plan document amendments and certifications.
Protected Health Information Scope
The Privacy Rule applies to PHI held by the group health plan in all forms, including oral, paper, and electronic. The Security Rule applies only to electronic protected health information (ePHI), and its administrative, physical, and technical safeguards apply to that subset.
Business Associate Arrangements
Group health plans frequently rely on third parties such as third-party administrators, pharmacy benefit managers, and other vendors that handle PHI. These parties are generally business associates, and obligations flow to them through business associate agreements, with similar terms flowing to subcontractors.
Applicable HIPAA Rules
A group health plan is generally subject to the Privacy Rule (PHI in all forms), the Security Rule (ePHI safeguards), the Breach Notification Rule (notification obligations following a breach), and the Enforcement Rule (administered by HHS OCR). The precise application can vary by plan characteristics.

Common questions

Answers to the questions practitioners most commonly ask about GHP.

Is a group health plan considered a business associate of the employer that sponsors it?
No, this is a common point of confusion. A group health plan is itself a covered entity (or a component of one) under HIPAA, not a business associate of its sponsoring employer. The plan sponsor (the employer) is a separate party, and specific rules govern when and how PHI may flow between the plan and the sponsor. The employer generally is not automatically subject to HIPAA simply by sponsoring the plan; obligations attach through the plan and through defined relationships. Readers should verify the specific arrangements against current regulatory text, as plan structures vary.
Does HITRUST certification of a group health plan or its vendors establish that the plan is HIPAA compliant?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, but certification is not a legal requirement and does not by itself establish HIPAA compliance. A group health plan remains directly accountable to HHS OCR for its obligations under the applicable HIPAA rules regardless of any HITRUST certification it or its vendors may hold. Certification may support a compliance program but should not be treated as a substitute for meeting HIPAA requirements. Verify certification scope against the current HITRUST CSF version.
Which HIPAA rules apply to a group health plan?
As a covered entity, a group health plan is generally subject to the Privacy Rule, which covers PHI in all forms including oral, paper, and electronic; the Security Rule, which governs only electronic PHI (ePHI); the Breach Notification Rule; and the Enforcement Rule. The specific obligations depend on the plan's structure and functions. Note that the HITECH Act and state laws may impose additional requirements, so readers should confirm the full set of applicable obligations against current regulation.
When can a group health plan disclose PHI to its plan sponsor?
In most cases, before a group health plan discloses PHI to the plan sponsor for plan administration functions, the plan documents generally must be amended to establish permitted uses and disclosures and to require the sponsor to safeguard the information and limit its use. Certain limited disclosures, such as summary health information for specified purposes or enrollment and disenrollment information, may be treated differently. The precise conditions should be verified against the current Privacy Rule text, as this is a specialized area.
Do the same obligations apply to fully insured and self-insured group health plans?
Not necessarily. The scope of a group health plan's HIPAA obligations can differ depending on whether the plan is fully insured or self-insured and on how much PHI the plan or sponsor creates, receives, maintains, or transmits. Fully insured plans that do not handle PHI beyond limited exceptions may have reduced obligations in some respects. Because these distinctions turn on specific facts, readers should confirm their plan's status and the resulting requirements against current regulatory guidance.
What Security Rule safeguards should a group health plan address for its ePHI?
To the extent a group health plan creates, receives, maintains, or transmits ePHI, it generally must implement administrative, physical, and technical safeguards under the Security Rule. These include both required implementation specifications and addressable ones; addressable does not mean optional, but rather that the plan must assess whether the specification is reasonable and appropriate and, if not, document why and implement an equivalent alternative where appropriate. The specific safeguards should be determined through a risk analysis and confirmed against current regulatory requirements.

Common misconceptions

The employer that sponsors a group health plan is automatically the HIPAA covered entity.
The group health plan itself is generally the covered entity, not the sponsoring employer. The plan and its sponsor are distinct, and disclosures of PHI from the plan to the sponsor are typically permitted only under specific Privacy Rule conditions, which may include plan document amendments and certifications. Sponsors should verify their obligations against the current regulatory text.
Because the Security Rule applies, all information the group health plan holds is covered only by electronic safeguards.
The Security Rule governs only electronic protected health information (ePHI) through administrative, physical, and technical safeguards. The Privacy Rule separately covers PHI in all forms, including oral and paper, so a group health plan generally must address both electronic and non-electronic information.
A group health plan and its vendors are all regulated the same way because they all touch member data.
HIPAA obligations attach through defined relationships. The group health plan is generally a covered entity, while vendors that handle PHI on its behalf are typically business associates whose obligations flow through business associate agreements. Similar terms generally flow down to subcontractors rather than HIPAA regulating every vendor directly and identically.

Best practices

Confirm whether the group health plan qualifies as a covered entity and identify how its size and funding structure (self-insured versus fully insured) affect which HIPAA obligations apply, verifying against the current regulatory text.
Clearly separate the roles of the group health plan and its plan sponsor, and ensure any disclosures of PHI to the sponsor are supported by the required Privacy Rule conditions, such as plan document amendments and certifications.
Maintain executed business associate agreements with third-party administrators, pharmacy benefit managers, and other vendors handling PHI, and ensure comparable terms flow down to subcontractors.
Address PHI in all forms under the Privacy Rule (oral, paper, and electronic) while applying administrative, physical, and technical safeguards to ePHI under the Security Rule, treating addressable specifications as requiring evaluation rather than as optional.
Establish breach notification procedures consistent with the Breach Notification Rule so the plan can meet its obligations following an incident, confirming current requirements with HHS OCR guidance.
Check whether state law or the HITECH Act imposes additional requirements beyond HIPAA, and remember that adopting a framework such as the HITRUST CSF does not by itself establish HIPAA compliance.