
August 2026 - Question of the Month - Which Benefit Plans are Subject to the HIPAA Privacy Rules?
August 2026 - Question of the Month - Which Benefit Plans are Subject to the HIPAA Privacy Rules?
8/4/2026
Question
Which benefit plans are subject to the HIPAA Privacy Rules?
Answer
The HIPAA Rules do not directly apply to employers or to employment-related records, even those that contain medical information.
Although employers are not directly regulated by HIPAA, the HIPAA Rules apply to them through their role as health plan sponsors. Compliance obligations vary considerably depending on whether a health plan is level funded or fully insured and the employer’s involvement in plan administration. Employers sponsoring fully insured plans with limited access to PHI have minimal obligations, while those administering level funded plans have more responsibilities.
Identify Health Plans and Funding
Because the HIPAA Rules directly apply to health plans, employers should identify their health plans as an initial compliance step. In general, all employer-sponsored plans that provide or pay for healthcare are subject to the HIPAA Rules. The following table provides examples of common employer-sponsored welfare benefits and indicates whether they are considered health plans subject to the HIPAA Rules.
| Type of Welfare Benefit | Subject to HIPAA Rules? |
|---|---|
| Medical plans | Yes |
| Dental and vision plans | Yes |
| Prescription drug plans | Yes |
| Health flexible spending accounts (FSAs) | Yes |
| Health reimbursement arrangements (HRAs) | Yes |
| Individual coverage HRAs (ICHRAs) | Yes |
| Excepted benefit HRAs (EBHRAs) | Yes |
| Qualified small employer HRAs (QSEHRAs) | Yes |
| Dependent care FSAs | No |
| Adoption assistance FSAs | No |
| Health savings accounts (HSAs) | No, but the high deductible health plans (HDHPs) offered with HSAs are subject to the HIPAA Privacy Rules |
| Disease-specific policies, such as cancer policies | Yes, if they provide coverage for medical care |
| Life insurance | No |
| Disability insurance | No |
| Section 125 premium-only plans | No |
Also, a health plan’s funding impacts the scope of an employer’s HIPAA obligations for the plan. In addition to identifying their health plans, employers should confirm whether each health plan is fully insured or level funded. Employers with level funded health plans have significant compliance obligations under the HIPAA Rules. In contrast, the compliance responsibility for fully insured health plans may be minimal, particularly when the employer does not receive PHI from the issuer for plan administration purposes.
Review Privacy Notice Requirements
The HIPAA Rules require certain health plans and issuers to provide a Notice of Privacy Practices to plan participants. The Privacy Notice must be written in plain language and must:
- Explain how the health plan or issuer may use and disclose an individual’s PHI;
- Describe the individual’s rights with respect to their PHI; and
- Summarize the health plan’s or issuer’s legal duties with respect to the PHI.
The Privacy Notice requirements for an employer’s health plan vary depending on whether the plan is level funded or fully insured, and, if the plan is fully insured, whether the plan sponsor has access to PHI for plan administration purposes, as explained in the following table:
| Type of Health Plan | Privacy Notice Requirements |
|---|---|
| Level funded health plans | Employers with level funded health plans must provide a Privacy Notice to new enrollees at the time of enrollment, within 60 days of material change to the notice, and upon a participant's request. Also, at least once every three years, the Privacy Notice must be redistributed, or participants must be notified that the notice is available with instructions for obtaining a copy. |
| Fully insured health plans | The insurer has the primary responsibility for a fully insured plan's Privacy Notice. However, employers with fully insured health plans that access PHI for plan administration purposes must maintain a Privacy Notice for the plan and provide it upon request. Employers without access to PHI (other than enrollment information, summary health information and information released pursuant to a HIPAA authorization) are not required to maintain or provide a Privacy Notice. |
Resources
- HIPAA 101 For Employers Guide
- Summary of the HIPAA Privacy Rule | HHS.gov
- Model Notices of Privacy Practices | HHS.gov
While every effort has been taken in compiling this information to ensure that its contents are totally accurate, neither the publisher nor the author can accept liability for any inaccuracies or changed circumstances of any information herein or for the consequences of any reliance placed upon it. This publication is distributed on the understanding that the publisher is not engaged in rendering legal, accounting, or other professional advice or services. Readers should always seek professional advice before entering into any commitments.