164.314(b)(1) Organizational Requirements

Requirements for Group Health Plans

High Risk Moderate Medium

Except when the only ePHI disclosed to a plan sponsor is disclosed pursuant to 164.504(f)(1)(ii) or (iii), or as permitted under 164.508(a)(3)(i), a group health plan must ensure that its plan documents provide that the plan sponsor will reasonably and appropriately safeguard ePHI.

Implementation Guidance

Except where the only ePHI disclosed to a plan sponsor is disclosed under 164.504(f)(1)(ii) or (iii), or as authorised under 164.508, a group health plan must ensure its plan documents require the plan sponsor to reasonably and appropriately safeguard ePHI it creates, receives, maintains or transmits on the plan's behalf. The requirement sits at 164.314(b)(1), and the specifications at 164.314(b)(2).

Plan documents must require the plan sponsor to:
• Implement administrative, physical and technical safeguards that reasonably and appropriately protect ePHI
• Ensure that adequate separation between the plan and the plan sponsor, required by 164.504(f)(2)(iii), is supported by reasonable and appropriate security measures
• Ensure that any agent to whom it provides ePHI agrees to implement reasonable and appropriate security measures
• Report to the group health plan any security incident of which it becomes aware

Implementation approach:
- Identify precisely which ePHI flows to the plan sponsor and under what authority; enrolment and disenrolment information and summary health information carry different treatment
- Amend plan documents to carry each required provision. This is a plan document obligation, not a business associate agreement, and the two are frequently conflated
- Make the firewall between plan administration and employment functions real: restrict access to named individuals performing plan administration, and enforce it technically
- Name the individuals or classes permitted access in the plan documents, and keep that list current
- Train those individuals on their distinct obligations and record it
- Establish an incident reporting route from the sponsor back to the plan
- Flow the requirements to any agent or third-party administrator handling plan ePHI
- Retain plan documents and amendments for six years under 164.316(b)(2)

The recurring failure here is practical rather than legal: HR staff hold both employment and plan administration roles, and the separation exists on paper while the same person sees both sets of data with the same account.

Required Documentation

• Plan documents containing each provision required by 164.314(b)(2)
• Plan document amendments and their adoption records
• Description of ePHI flows between the plan, the sponsor and any third-party administrator
• Named individuals or classes permitted access for plan administration, kept current
• Adequate separation procedures and the technical measures enforcing them
• Access control configuration evidence showing the separation is enforced in systems
• Training records for individuals with plan administration access
• Agent and third-party administrator agreements carrying the requirements downstream
• Incident reporting procedure from sponsor to plan, and records of reports made
• Retention evidence for plan documents under 164.316(b)(2)

Best Practices

• Enforce separation with distinct system roles and separate accounts, not just written policy
• Keep the list of permitted individuals short, named and reviewed at least annually
• Segregate plan administration data into a system or partition that employment-function staff cannot reach
• Train plan administration staff separately, because their obligations differ from general HIPAA training
• Review plan documents whenever the administrator, carrier or plan design changes
• Log access to plan ePHI and review it, particularly where staff hold dual roles
• Confirm third-party administrators carry the requirements to their own subcontractors
• Document the authority for each data flow so the 164.504(f) exceptions are applied deliberately

Common Violations

• Plan documents never amended to include the required security provisions
• A business associate agreement used in place of the plan document amendment, which does not satisfy the requirement
• Separation stated in policy while the same HR staff access plan and employment data with one account
• No current list of individuals permitted access for plan administration
• Plan ePHI held in general HR systems accessible to the whole HR function
• Agents and third-party administrators given plan ePHI without the requirements flowing down
• No route for the sponsor to report security incidents to the plan
• Plan administration staff receiving only general HIPAA training
• Summary health information treated as unrestricted

Testing Procedures

• Review plan documents and confirm every provision required by 164.314(b)(2) is present
• Map actual ePHI flows and compare against the documented description
• Confirm the list of individuals permitted plan administration access is current and matches reality
• Test access controls to confirm separation is technically enforced, not merely stated
• Sample individuals holding both HR and plan administration duties and examine how their access is segregated
• Confirm training was delivered to those with plan administration access, with records
• Review agent and third-party administrator agreements for flow-down of the requirements
• Trace any incident reported by the sponsor through to the plan's response
• Confirm summary health information and enrolment data are handled under the correct authority
• Verify plan documents and amendments are retained for six years

Implementation Resources

Download expert-developed templates and checklists to implement this control:

Quick Facts

Control ID 164.314(b)(1)
Category Organizational Requirements
Risk Level High
Difficulty Moderate
Est. Cost Medium
Timeframe 2-4 months
Last Updated Sep 3, 2026

Need Help Implementing This Control?

Our certified HIPAA experts can help you implement this control correctly and efficiently.