Skip to main content
Category: Regulatory Framework

Health Plan

Also known as: Health Insurance Plan, Health Benefit Plan
Simply put

A health plan is an insurance policy or other arrangement that provides health services to individuals or pays for the cost of those services. Examples generally include individual and group plans as well as government programs such as Medicare and Medicaid. Under HIPAA, a health plan is one of the types of covered entities that must comply with HIPAA's privacy and security requirements.

Formal definition

Under HIPAA, a health plan is defined as an individual or group plan that provides, or pays the cost of, medical care. This category generally encompasses arrangements such as commercial health insurance issuers, employer- or union-sponsored group health plans (which may also fall under employee welfare benefit plan frameworks), and government programs including Medicare and Medicaid. As a covered entity, a health plan is directly subject to the HIPAA Privacy Rule (covering PHI in all forms), the Security Rule (covering ePHI), the Breach Notification Rule, and the Enforcement Rule as administered by HHS OCR. Practitioners should note that the precise statutory and regulatory scope of the term 'health plan', including specific inclusions and exclusions, is set out in the applicable HIPAA definitions and should be confirmed against the current regulatory text, as certain arrangements may be excepted. State law and the HITECH Act may impose additional obligations beyond those described here.

Why it matters

The health plan classification matters because it is one of the three types of covered entities that fall directly under HIPAA's requirements, alongside health care providers and health care clearinghouses. When an arrangement qualifies as a health plan, it becomes directly subject to the HIPAA Privacy Rule, the Security Rule, the Breach Notification Rule, and the Enforcement Rule as administered by HHS OCR. This means the obligations attach to the plan itself as a matter of law, not merely through a contractual relationship such as a business associate agreement.

Getting the classification right has practical consequences for compliance scope. Health plans handle protected health information across all forms, including enrollment, eligibility, claims, and payment data, so the Privacy Rule's coverage of PHI in all formats and the Security Rule's coverage of electronic PHI both apply. Employer- or union-sponsored group health plans add complexity because they may also fall under employee welfare benefit plan frameworks, which can bring additional obligations from other bodies of law beyond HIPAA.

Because the precise statutory and regulatory scope of the term includes specific inclusions and exclusions, and because certain arrangements may be excepted, a misclassification can lead an organization either to overlook HIPAA duties it actually owes or to apply requirements to an arrangement that is out of scope. Practitioners should also keep in mind that state law and the HITECH Act may impose additional obligations beyond those described in the core HIPAA definition.

Who it's relevant to

Health Insurance Issuers and Insurers
Commercial insurers that provide or pay for medical care generally qualify as health plans and are directly subject to HIPAA's Privacy, Security, Breach Notification, and Enforcement Rules as covered entities. They should confirm their specific status against the current regulatory text, since certain arrangements may be excepted.
Employer- and Union-Sponsored Group Health Plans
Group health plans established or maintained by an employer or an employee organization such as a union may qualify as health plans under HIPAA. These arrangements can also fall under employee welfare benefit plan frameworks, so sponsors should consider obligations from those frameworks in addition to HIPAA and check applicable requirements against current guidance.
Government Program Administrators
Programs such as Medicare and Medicaid are generally included within the health plan category, meaning the entities administering them are subject to HIPAA's requirements as covered entities.
Privacy and Security Officers
Compliance staff at organizations that may qualify as health plans need to confirm the entity's covered-entity status so they correctly scope Privacy Rule obligations (PHI in all forms) and Security Rule obligations (ePHI), and should verify inclusions, exclusions, and any additional state law or HITECH Act requirements against current guidance.

Inside Health Plan

Covered Entity Status
A health plan is one of the three categories of covered entities directly regulated under HIPAA, alongside health care providers who transmit health information electronically and health care clearinghouses. As a covered entity, a health plan is directly subject to the HIPAA Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule as administered by HHS OCR.
Scope of Included Plans
The term generally encompasses individual and group plans that provide or pay the cost of medical care. This typically includes group health plans, health insurance issuers, health maintenance organizations (HMOs), and certain government programs such as Medicare and Medicaid. The precise definition and any exclusions should be verified against the current regulatory text.
PHI in All Forms
Because a health plan is a covered entity, its Privacy Rule obligations extend to protected health information (PHI) in all forms, including oral, paper, and electronic. Its Security Rule obligations, by contrast, apply only to electronic protected health information (ePHI).
Business Associate Relationships
A health plan frequently engages vendors that create, receive, maintain, or transmit PHI on its behalf, such as third-party administrators or claims processors. These relationships generally require business associate agreements, through which certain HIPAA obligations flow to the business associate and, in turn, to subcontractors.
Required Safeguards
As a covered entity, a health plan must generally implement administrative, physical, and technical safeguards for ePHI under the Security Rule, addressing both required and addressable implementation specifications. Addressable does not mean optional; it requires assessment and either implementation or documented justification of an equivalent alternative.

Common questions

Answers to the questions practitioners most commonly ask about Health Plan.

Is a health plan the same thing as a health insurance company?
Not exactly. Under HIPAA, health plan is a defined category of covered entity that is broader than just insurance companies. While health insurance issuers are health plans, the term generally also includes other arrangements that provide or pay the cost of medical care, such as group health plans, HMOs, and certain government programs. Conversely, an entity can pay for care without necessarily meeting the regulatory definition. Readers should confirm how a specific arrangement is treated under the current regulatory text, as the defined meaning differs from the common usage of health insurance company.
Does a health plan only have obligations under the HIPAA Security Rule for electronic data?
No. As a covered entity, a health plan is subject to the full scope of HIPAA rules that apply to it, not just the Security Rule. The Security Rule governs only electronic protected health information (ePHI), but the Privacy Rule covers protected health information in all forms, including oral and paper. Health plans also have responsibilities under the Breach Notification Rule and are subject to the Enforcement Rule. Treating only electronic safeguards as the plan's obligations would understate its compliance responsibilities.
How does a health plan's status as a covered entity affect its relationships with vendors?
When a health plan discloses protected health information to a vendor that performs functions or services on its behalf, that vendor generally becomes a business associate, and the obligations typically attach through a business associate agreement. HIPAA does not directly regulate every vendor that touches data; the relationship and the agreement define which obligations flow through. Health plans should identify which vendors meet the business associate definition and ensure appropriate agreements are in place, verifying required content against current regulatory guidance.
What safeguards should a health plan consider when handling ePHI?
For electronic protected health information, the Security Rule organizes safeguards into administrative, physical, and technical categories, each with implementation specifications that are either required or addressable. Addressable does not mean optional; a health plan must generally either implement the specification, adopt a reasonable and appropriate alternative, or document why it is not applicable. Plans typically conduct a risk analysis to inform these decisions. For PHI in oral or paper form, the Privacy Rule's requirements apply instead of the Security Rule.
Does obtaining HITRUST certification satisfy a health plan's HIPAA obligations?
No. HITRUST is a private organization, and the HITRUST CSF is a certifiable control framework that some health plans use to structure and demonstrate their security programs. However, HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance. A health plan remains directly accountable to HHS OCR for its HIPAA obligations regardless of any certification. Certification may support a compliance program but should not be treated as a substitute for meeting the applicable regulatory requirements.
Are HIPAA's requirements the only rules a health plan needs to follow?
Not necessarily. HIPAA establishes a federal baseline enforced by HHS OCR, but health plans may face additional requirements. State laws can impose obligations beyond HIPAA, and the HITECH Act and other frameworks may add requirements as well. Where state law is more protective of individuals' information, it may apply in addition to HIPAA. Health plans should evaluate the full set of applicable federal and state requirements rather than assuming HIPAA alone is comprehensive, and verify specifics against current guidance.

Common misconceptions

A health plan and a health care provider are governed by identical HIPAA rules with no distinction.
Both are covered entities and share core HIPAA obligations, but they are distinct categories with different operational contexts. The applicable rules (Privacy, Security, Breach Notification, Enforcement) apply to a health plan based on its status as a covered entity, and specific requirements can vary based on function and the types of information handled.
A health plan's vendors are automatically regulated by HIPAA simply because they handle the plan's data.
HIPAA does not directly regulate every vendor that touches data. Obligations attach through defined relationships; a vendor that creates, receives, maintains, or transmits PHI on the plan's behalf generally becomes a business associate, and obligations flow through a business associate agreement rather than by mere data contact.
Obtaining HITRUST certification makes a health plan HIPAA compliant.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. HITRUST certification does not by itself establish HIPAA compliance, which is a legal obligation enforced by HHS OCR. Certification may support a compliance program but should not be treated as a substitute for meeting the regulation.

Best practices

Confirm the health plan's status as a covered entity and verify which specific plan types fall within scope against the current regulatory text, since definitions and exclusions are updated over time.
Apply Privacy Rule protections to PHI in all forms (oral, paper, and electronic) while recognizing that Security Rule safeguards apply specifically to ePHI.
Identify all vendors that create, receive, maintain, or transmit PHI on the plan's behalf, and ensure appropriate business associate agreements are in place before those relationships involve PHI.
Address both required and addressable implementation specifications for administrative, physical, and technical safeguards, documenting the rationale and any equivalent alternatives for addressable items rather than treating them as optional.
Treat any HITRUST CSF certification as a supporting element of a broader compliance program rather than as evidence of HIPAA compliance, and verify control mappings against the current HITRUST CSF version.
Consult current HHS OCR guidance for enforcement and breach considerations, and evaluate whether the HITECH Act or applicable state laws impose additional requirements beyond HIPAA.