Skip to Main Content
05/01/2026|3 minute read

Key Takeaways

  • OCR has made clear that employer‑sponsored plans are squarely within HIPAA’s enforcement scope—including financial settlements.
  • Employers should assess their plan’s HIPAA governance, controls, and vendor arrangements now.
  • And don’t forget ERISA . . . cybersecurity is now a top enforcement priority.

Non-healthcare companies are often surprised to learn that the Health Insurance Portability and Accountability Act (HIPAA) applies to their employer-sponsored health plans and that the company, in its capacity as employer and plan sponsor, is responsible for meeting HIPAA’s compliance obligations regardless of the company’s primary business. In today’s privacy and cybersecurity focused landscape, these 25-year-old compliance obligations have flown under the radar for most employers.

That is, until the recent enforcement announcement by the U.S. Department of Health and Human Services Office for Civil Rights (OCR), when the OCR announced four ransomware-related financial settlements, and one of them involved an employer-sponsored health plan.

That development is significant. While HIPAA included employer-sponsored health plans within the definition of a HIPAA covered entity, OCR is—for the first time in OCR’s enforcement history—applying its long-standing enforcement agenda directly to the employer health plan context. This activity is a reminder that HIPAA applicability is an overlooked legal risk for many major employers.

Employer-Sponsored Plans Are Within HIPAA’s Enforcement Perimeter

The legal framework has been clear for years. HIPAA applies to all “group health plans,” including both insured and self-funded plans, that (i) have 50 or more participants OR use a third-party administrator and (ii) provide payment for medical care.

What has changed is the enforcement signal. OCR’s recent action shows that employer-sponsored plans are not peripheral to HIPAA compliance and enforcement, particularly when a cybersecurity incident exposes the plan’s electronic protected health information (ePHI). The nature and extent of ePHI held by the employer sponsoring the health plan usually includes enrollment censuses, claims information, spend reports, and communications with employees about their health and welfare benefits.

HIPAA applies to the health plan, not to the plan sponsor in its capacity as an employer. But when the plan sponsor, on behalf of the plan, engages in certain activities involving ePHI—such as creating ePHI, maintaining systems that store it, or directing service providers such as third-party administrators to process it—OCR expects the HIPAA-regulated side of the organization to have compliant controls in place.

For an employer’s in-house counsel, human resources leaders, and benefits professionals, the message is straightforward: If the company creates, receives, maintains, or transmits health plan data, OCR may have jurisdiction over the company’s related operations.

OCR Is Leveraging Cyber Incidents to Examine Baseline Compliance

The recent settlements also reinforce a second theme: OCR continues to treat a cyber incident as the starting point, not the end point, of an investigation into an entity’s HIPAA compliance. When announcing settlements, OCR has repeatedly emphasized the HIPAA Security Rule’s risk analysis requirement and explained that regulated organizations must conduct an “accurate and thorough assessment” of the risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

That message is consistent with OCR’s enforcement of the HIPAA Security Rule more broadly. A ransomware event may trigger the OCR investigation, but OCR’s findings often focus on whether the entity had completed the foundational work required by the Security Rule before the incident occurred. In employer-sponsored plan settings, that means a plan sponsor cannot assume that general enterprise cybersecurity controls, standing alone, will satisfy OCR if the plan cannot show a documented and plan-appropriate HIPAA compliance structure— across the Privacy, Security and Breach Notification Rules.

What This Means for Plan Sponsors

The most important takeaway is not that every employer-sponsored plan is suddenly facing immediate enforcement risk—it is that OCR has made clear that it expects companies to safeguard their plan’s ePHI with the same rigor and compliance discipline that it expects from the hospital down the street.

Employers should use this moment to focus on core HIPAA obligations:

  • Review which benefits arrangements are HIPAA-covered plans; update privacy, security, and breach notification policies; and amend plan documents, as needed.
  • Identify where ePHI is created, received, maintained, or transmitted, and whether the company has a HIPAA security risk analysis and risk management plan specifically addressing health plan ePHI.
  • Assess the company’s vendor and business associate contracts and confirm whether incident response processes reflect the plan’s actual operations. If a ransomware incident affects systems used for plan administration, the response may require a HIPAA breach analysis with notification to plan participants and OCR, as well as other regulatory obligations. HIPAA applicability creates a more complicated incident response than does a standard employment-data event.
  • Don’t forget ERISA. The Employee Benefits Security Administration (EBSA)—the arm of the Department of Labor responsible for enforcing ERISA—has listed cybersecurity as a top enforcement priority, and there has been a significant increase in EBSA investigations focused on the cybersecurity of both retirement and welfare plans, including investigations focused solely on cybersecurity.

The Health Plan Compliance attorneys at BakerHostetler, which include members from both the Digital Assets and Data Management Practice Group and the Employee Benefits and Executive Compensation team, have helped hundreds of employers create a reasonable and sustainable HIPAA compliance program. Please reach out to Kimi Gordy, Jenny Mills, or your BakerHostetler attorney for more information.


Featured Insights