Requirements for Group Health Plans
Except when the only ePHI disclosed to a plan sponsor is disclosed pursuant to 164.504(f)(1)(ii) or (iii), or as permitted under 164.508(a)(3)(i), a group health plan must ensure that its plan documents provide that the plan sponsor will reasonably and appropriately safeguard ePHI.
Implementation Guidance
Plan documents must require the plan sponsor to:
• Implement administrative, physical and technical safeguards that reasonably and appropriately protect ePHI
• Ensure that adequate separation between the plan and the plan sponsor, required by 164.504(f)(2)(iii), is supported by reasonable and appropriate security measures
• Ensure that any agent to whom it provides ePHI agrees to implement reasonable and appropriate security measures
• Report to the group health plan any security incident of which it becomes aware
Implementation approach:
- Identify precisely which ePHI flows to the plan sponsor and under what authority; enrolment and disenrolment information and summary health information carry different treatment
- Amend plan documents to carry each required provision. This is a plan document obligation, not a business associate agreement, and the two are frequently conflated
- Make the firewall between plan administration and employment functions real: restrict access to named individuals performing plan administration, and enforce it technically
- Name the individuals or classes permitted access in the plan documents, and keep that list current
- Train those individuals on their distinct obligations and record it
- Establish an incident reporting route from the sponsor back to the plan
- Flow the requirements to any agent or third-party administrator handling plan ePHI
- Retain plan documents and amendments for six years under 164.316(b)(2)
The recurring failure here is practical rather than legal: HR staff hold both employment and plan administration roles, and the separation exists on paper while the same person sees both sets of data with the same account.
Required Documentation
• Plan document amendments and their adoption records
• Description of ePHI flows between the plan, the sponsor and any third-party administrator
• Named individuals or classes permitted access for plan administration, kept current
• Adequate separation procedures and the technical measures enforcing them
• Access control configuration evidence showing the separation is enforced in systems
• Training records for individuals with plan administration access
• Agent and third-party administrator agreements carrying the requirements downstream
• Incident reporting procedure from sponsor to plan, and records of reports made
• Retention evidence for plan documents under 164.316(b)(2)
Best Practices
• Keep the list of permitted individuals short, named and reviewed at least annually
• Segregate plan administration data into a system or partition that employment-function staff cannot reach
• Train plan administration staff separately, because their obligations differ from general HIPAA training
• Review plan documents whenever the administrator, carrier or plan design changes
• Log access to plan ePHI and review it, particularly where staff hold dual roles
• Confirm third-party administrators carry the requirements to their own subcontractors
• Document the authority for each data flow so the 164.504(f) exceptions are applied deliberately
Common Violations
• A business associate agreement used in place of the plan document amendment, which does not satisfy the requirement
• Separation stated in policy while the same HR staff access plan and employment data with one account
• No current list of individuals permitted access for plan administration
• Plan ePHI held in general HR systems accessible to the whole HR function
• Agents and third-party administrators given plan ePHI without the requirements flowing down
• No route for the sponsor to report security incidents to the plan
• Plan administration staff receiving only general HIPAA training
• Summary health information treated as unrestricted
Testing Procedures
• Map actual ePHI flows and compare against the documented description
• Confirm the list of individuals permitted plan administration access is current and matches reality
• Test access controls to confirm separation is technically enforced, not merely stated
• Sample individuals holding both HR and plan administration duties and examine how their access is segregated
• Confirm training was delivered to those with plan administration access, with records
• Review agent and third-party administrator agreements for flow-down of the requirements
• Trace any incident reported by the sponsor through to the plan's response
• Confirm summary health information and enrolment data are handled under the correct authority
• Verify plan documents and amendments are retained for six years
Implementation Resources
Download expert-developed templates and checklists to implement this control:
Quick Facts
Related Controls
Explore other controls in the Organizational Requirements category.
Need Help Implementing This Control?
Our certified HIPAA experts can help you implement this control correctly and efficiently.