HIPAA

HIPAA does not apply to your company. It applies to your health plan — and that is where employers get caught.

The rule everyone quotes is not the rule that binds you. Your business is not a covered entity. Your group health plan is, and the moment your HR team handles information that belongs to the plan, a specific set of obligations attaches to you as its sponsor. Penalties run from $145 to $2,190,294 a year, and the criminal provisions reach individuals, not just organizations.

Ask Us What Applies to Your Plan

Who Is Actually Covered

The employer is not the covered entity. The plan is.

This distinction decides almost every HIPAA question an employer asks, and almost nobody draws it correctly.

Your Employment Records Are Not PHI

A doctor’s note handed to a manager, an FMLA certification, a workers’ compensation file: these sit in your employment records, outside HIPAA. Other laws govern them, and the ADA is usually the one that matters.

The Plan Is a Covered Entity

Your group health plan is covered. So is the carrier, and so is any vendor handling claims. The plan’s information does not become yours just because you pay for the plan.

Where the Line Blurs

It blurs the moment your people touch plan data — a self-funded plan, an HRA or health FSA you administer, a wellness program tied to the plan, or an HR manager who takes a claim problem and calls the carrier.

Two Things You Can Receive Freely

Summary health information, when you are getting premium bids or deciding whether to change the plan, and whether an individual is enrolled. Those two move to a plan sponsor without the full apparatus.

Fully Insured and Hands-Off

A fully insured plan whose sponsor receives nothing beyond those two categories carries a much lighter load. Most employers assume they are here. Fewer are than think.

Business Associates

Anyone handling PHI on the plan’s behalf — third-party administrator, broker, benefits platform, COBRA vendor — needs a business associate agreement, and they carry their own liability under the rules.

See the whole compliance calendar →

What an FSA or HRA commits you to →

If Your Team Touches PHI

Four things have to be true before plan information reaches you.

These come from the plan-sponsor rules, and they are the part employers most often have never done.

1. The Plan Documents Say So

The plan document has to be amended to describe what the sponsor may do with the information, with protections that match the rule. A benefits guide is not a plan document, and a certificate of coverage is not either.

2. You Certify It in Writing

Before the plan discloses anything, the sponsor certifies that the documents have been amended and that it agrees to the restrictions. Until that certification exists, the disclosure is not permitted.

3. Named People, Limited Access

The documents must name the employees or classes of employees who may see plan information, and limit them to plan-administration work. This is the separation requirement — the firewall — and it has to be written down, not assumed.

4. Never for Employment Decisions

Plan information cannot be used for employment-related actions or for any other benefit. Not for an attendance question, not for a promotion, not for a layoff list. There also has to be a mechanism for resolving noncompliance when it happens.

Every notice you owe employees →

Fines and Fees

What it costs, at 2026 amounts.

Tier 1 — You Did Not Know

$145 to $73,011 per violation, and you could not reasonably have known. The floor is low; the ceiling is not.

Tier 2 — Reasonable Cause

$1,461 to $73,011 per violation. You knew, or should have, but it was not willful neglect.

Tier 3 — Willful Neglect, Fixed Fast

$14,602 to $73,011 per violation, where the failure was willful neglect and you corrected it within 30 days.

Tier 4 — Willful Neglect, Not Fixed

$73,011 to $2,190,294 per violation. The floor here is the ceiling of every other tier.

The Annual Cap

$2,190,294 for all violations of an identical provision in a calendar year. Effective for penalties assessed on or after 28 January 2026 [the figures are inflation-adjusted annually].

The Criminal Side Reaches People

Knowingly obtaining or disclosing health information: up to $50,000 and a year. Under false pretenses: $100,000 and five years. To sell it or for personal gain or malicious harm: $250,000 and ten years.

See What Else Your Plan Year Owes

The Breach Clock

Sixty days, and it starts at discovery.

Not at confirmation, not when the investigation finishes. Discovery is when the clock starts, and it is the detail that turns a manageable incident into a late one.

Individuals

Notice to each affected person without unreasonable delay and no later than 60 days after discovery.

500 or More in One State

Prominent media notice in that state or jurisdiction, on the same 60-day clock.

Health and Human Services

For a breach of 500 or more, notify within 60 days. Under 500, log it and report within 60 days after the calendar year ends.

Your Vendors

A business associate has 60 days from discovery to tell the plan. Your clock does not restart because theirs ran first.

Who Carries the Obligation

The covered entity remains responsible for notifying individuals. You can delegate the work to a vendor; you cannot delegate the responsibility.

What Is Coming

A Security Rule overhaul was proposed in January 2025 and drew more than 4,000 comments. It is not final — the current target for final action is 2027, which makes now the cheap time to get the basics in place.

How compliance works as a service here →

How We Help

Most of this is paperwork you only have to do once.

The obligations are unglamorous and finite. The exposure comes from never having done them.

Find Out What You Actually Touch

Self-funded or fully insured, what your HR team handles, which vendors see plan data, whether your wellness program pulls information back to you. That settles which of the rules above apply before anyone drafts anything.

Documents, Certification, Access List

Plan documents amended, the sponsor certification signed, and the named people written down with their access limited to plan administration. This is the part that makes the rest defensible.

Business Associate Agreements

Every vendor touching plan information gets one, and we check the ones you already have, because inherited agreements are often with companies you no longer use.

A Response Plan Before You Need One

Who is called, what gets documented, and where the 60-day clock starts. When a question runs past what a licensed insurance broker should answer alone, CPAs and ERISA attorneys are available through us.

Have Us Review Your Plan’s HIPAA Position

Meet the team that would handle it →

Questions We Get

What employers ask once they realize the plan is the covered entity.

Each of these comes up in the first conversation, usually in this order.

Does HIPAA apply to us as an employer?

Not directly. Your group health plan is the covered entity, and obligations reach you as the plan sponsor when you receive the plan’s information. Records you hold as an employer are not covered by HIPAA at all.

An employee gave us a doctor’s note. Is that a HIPAA problem?

No. That is an employment record. Handle it carefully for other reasons — the ADA, the FMLA, and plain good practice — but HIPAA is not the law in play.

We are fully insured. Are we exempt?

Lighter, not exempt. If the sponsor receives only summary health information and enrollment status, the load is small. Take claims detail, run an HRA or FSA, or handle appeals, and the full plan-sponsor rules apply.

Do we need a business associate agreement with our broker?

If the broker handles protected health information on the plan’s behalf, yes. The test is what the vendor touches, not what the vendor is called.

What does a violation actually cost?

It depends entirely on culpability. No knowledge starts at $145 per violation; willful neglect left uncorrected starts at $73,011 and runs to $2,190,294, which is also the annual cap for repeated violations of the same provision.

Can an individual go to jail for this?

The criminal provisions apply to people, not only organizations: up to a year for knowingly obtaining or disclosing health information, five years under false pretenses, and ten years where the intent is to sell it or profit from it.

A laptop went missing. How long do we have?

Sixty days from discovery to notify the individuals, and the same sixty for Health and Human Services if 500 or more people are affected. Under 500, you log it and report after the year ends.

Our vendor had the breach, not us.

The plan still notifies. The vendor owes you notice within 60 days of discovery, and you can have them do the mailing, but the obligation stays with the covered entity.

Can HR see claims to help an employee?

Only if the plan documents name those people, their access is limited to plan administration, and the sponsor has certified the amendment. Helping an employee is a good reason; it is not a substitute for the paperwork.

Is anything changing?

A significant Security Rule update was proposed in January 2025 and is still not final, with action now expected around 2027. Nothing about the current obligations is on hold in the meantime.

General information about HIPAA as it applies to employer-sponsored health plans, not legal advice. Plan-specific questions belong with ERISA counsel, and we will bring them in.

Let’s Get to Work

Send us your renewal.

We’ll tell you whether it looks competitive, where we see opportunity, and the five questions we’d put to your carrier. No cost, and no obligation to move anything.

What to send

The renewal letter
Your current plan summary
Contribution split by tier
Enrolled counts by tier

Four documents — two more if your group is 50 or more. Nothing else; every extra one is a reason to postpone.

CFH Insurance Consultants

An independent employee benefits consulting firm. We look at the entire benefits program — cost, plan performance, risk and administration.

Michigan41000 Woodward Avenue, Suite 350 East
Bloomfield Hills, MI 48304
248.370.8853
Colorado13540 Northgate Estates, Suite 100
Colorado Springs, CO 80921
719.425.2649
Texas16365 Park Ten Place, Suite 182
Houston, TX 77084
281.404.5670

Book a 30-minute call