Health information privacy

HIPAA Compliance for Employers and Group Health Plans

A practical guide to determining when HIPAA applies, separating employment records from plan records, and building safeguards around protected health information.

Last reviewed: August 21, 2026United States · FederalPrimary-source reviewed
Important distinction: HIPAA generally does not regulate an employer simply because it employs people or maintains employment records containing health information. An employer-sponsored group health plan may be a HIPAA covered entity, and the employer may take on plan-administration responsibilities that require strict separation and safeguards.

Who HIPAA regulates

The HIPAA Privacy, Security, and Breach Notification Rules apply to covered entities and business associates. Covered entities include health plans, health care clearinghouses, and covered health care providers. A group health plan is generally a covered entity, except for a self-administered plan with fewer than 50 participants. The plan is treated separately from the employer or plan sponsor.

Employment records are different

Health-related information held by an employer in its employment capacity is generally an employment record rather than protected health information under HIPAA. Other federal and state laws may still govern confidentiality, disability information, leave records, workers' compensation, genetic information, and workplace medical files.

When the plan shares PHI with the employer

A group health plan may disclose protected health information to a plan sponsor for specified plan-administration functions only when the applicable HIPAA conditions are satisfied. Those conditions can include plan-document restrictions, certification by the plan sponsor, limits on who may access PHI, and a prohibition against using plan PHI for employment-related actions.

Core compliance controls

  • Document which legal entity and workforce roles handle plan PHI.
  • Maintain required privacy policies, notices, authorizations, and individual-rights procedures.
  • Perform and document a Security Rule risk analysis for electronic PHI.
  • Use administrative, physical, and technical safeguards appropriate to the risks.
  • Execute compliant business associate agreements before vendors handle PHI.
  • Train relevant workforce members and apply access controls based on role.
  • Maintain incident response, breach assessment, notification, and documentation procedures.

Fully insured plans

A fully insured group health plan can have reduced administrative obligations when the plan sponsor receives only summary health information and enrollment or disenrollment information. The analysis changes if the sponsor receives additional PHI or performs plan-administration functions.

Primary sources

This resource is provided for general educational purposes and does not constitute legal, privacy, cybersecurity, safety, or other professional advice. Requirements and individual circumstances vary. Confirm current rules with authoritative sources and qualified advisors.

One Response

Leave a Reply

Your email address will not be published. Required fields are marked *

jQuery(document).ready(function($) { $('#thumbs-up').click(function(e) {e.preventDefault(); $('input[name="response"]').val('yes'); $('.elementor-form').submit(); // Trigger form submission }); $('#thumbs-down').click(function(e) { e.preventDefault(); $('input[name="response"]').val('no'); $('.elementor-form').submit(); // Trigger form submission }); });