Skip to main content

HIPAA Privacy & Security

Your self-funded plan is a covered entity. The obligation is yours.

Privacy programs, ePHI safeguards, vendor agreements, and breach readiness built at the plan level.

Last reviewed: · Applies to: General HIPAA privacy, security, and breach notification requirements

Primary source: HHS HIPAA for professionals. Dates, rates, thresholds, and penalty amounts change. Confirm the current figures against the primary source before acting.

Portions of this page are awaiting compliance review and are not represented as verified.

Why it applies to you

The insurer's BAA did not follow you.

Unlike fully insured plans where the insurer bears HIPAA responsibility, a self-funded plan is a covered entity under HIPAA. The employer — specifically the plan — must implement Privacy and Security Rules independently.

Many employers transitioning to self-funding are surprised to learn the insurer's BAA did not follow them. They now own the obligation.

What we build

A HIPAA program in four parts.

Privacy Rule Compliance

Establish a Notice of Privacy Practices, designate a Privacy Officer, train workforce members, and implement policies governing use and disclosure of Protected Health Information (PHI).

Security Rule — ePHI Safeguards

Self-funded plans that receive electronic PHI from TPAs are generally expected to implement administrative, physical, and technical safeguards. We conduct security risk analyses and gap remediation.

Business Associate Agreements

Vendors handling PHI on behalf of the plan — TPAs, stop-loss carriers, PBMs, EAPs — generally require a HIPAA-compliant BAA. We help draft and maintain your BAA inventory.

Breach Response & Notification

A reportable breach generally starts HHS and individual notification timelines. We help prepare breach response plans and support notification if an incident occurs.

Breach analysis

What triggers a breach obligation?

The questions we work through with plan sponsors when an incident surfaces.

The 60-day clock starts at discovery — not at confirmation

Discovery is the first day the incident is known, or reasonably should have been known, to anyone in the plan's workforce. Investigation time is inside the window, which is why the response plan has to exist before the incident does.

Not sure your HIPAA program would hold up?

We'll walk your PHI flows, BAA inventory, and incident plan in one session.

Schedule a consultation