HIPAA Privacy & Security

Your self-funded plan is a covered entity. The obligation is yours.

Privacy programs, ePHI safeguards, vendor agreements, and breach readiness built at the plan level.

Why it applies to you

The insurer's BAA did not follow you.

Unlike fully insured plans where the insurer bears HIPAA responsibility, a self-funded plan is a covered entity under HIPAA. The employer — specifically the plan — must implement Privacy and Security Rules independently.

Many employers transitioning to self-funding are surprised to learn the insurer's BAA did not follow them. They now own the obligation.

What we build

A HIPAA program in four parts.

Privacy Rule Compliance

Establish a Notice of Privacy Practices, designate a Privacy Officer, train workforce members, and implement policies governing use and disclosure of Protected Health Information (PHI).

Security Rule — ePHI Safeguards

Self-funded plans that receive electronic PHI from TPAs must implement administrative, physical, and technical safeguards. We conduct security risk analyses and gap remediation.

Business Associate Agreements

Every vendor handling PHI on behalf of the plan — TPAs, stop-loss carriers, PBMs, EAPs — requires a HIPAA-compliant BAA. We draft and maintain your BAA inventory.

Breach Response & Notification

A reportable breach triggers strict HHS and individual notification timelines. We prepare breach response plans and manage notification if an incident occurs.

Breach analysis

What triggers a breach obligation?

The questions we work through with plan sponsors when an incident surfaces.

The 60-day clock starts at discovery — not at confirmation

Discovery is the first day the incident is known, or reasonably should have been known, to anyone in the plan's workforce. Investigation time is inside the window, which is why the response plan has to exist before the incident does.

Not sure your HIPAA program would hold up?

We'll walk your PHI flows, BAA inventory, and incident plan in one session.

Schedule a consultation