Post a Job

Featured Jobs

Participant Service Manager

July Business Services
(Remote)

July Business Services logo

Transaction Coordinator II (Brokerage accts)

MAP Retirement
(Remote)

MAP Retirement logo

Regional Vice President

Loren D. Stark Company
(Remote / NJ / NV / TX)

Loren D. Stark Company logo

ESOP/KSOP Processing Specialist

BPAS
(Utica NY)

BPAS logo

Retirement - Client Services Manager

Navia Benefits
(Remote)

Navia Benefits logo

Plan Consultant II

MAP Retirement
(Remote)

MAP Retirement logo

Senior Retirement Plan Analyst - DC Plans

M2B Retirement Consulting LLC
(Remote / PA)

M2B Retirement Consulting LLC logo

Senior Retirement Plan Administrator

PlanPerfect, Inc.
(Remote)

PlanPerfect, Inc. logo

Client Service Manager

July Business Services (JULY)
(Remote)

July Business Services (JULY) logo

Participant Services Representative

BPAS
(Spokane WA / Hybrid)

BPAS logo

View More Employee Benefits Jobs

Free Publications

LinkedIn icon     Twitter icon     Facebook icon

News Archive

All News > HIPAA

Searchable archive of news items published in the BenefitsLink daily newsletters, from 1996 through June 30, 2026, when the newsletters ceased publication.

Tags: HIPAA  •  HRAs  •  Health Plan Design

Fisher Phillips Link to more items from this source
[Guidance Overview]
June 23, 2026

"For employers, the same analysis reaches self-insured group health plans. AI tools introduced by a TPA, PBM, or wellness vendor that touch plan PHI implicate the plan sponsor's HIPAA obligations and its vendor oversight duties."  MORE >>

Tags: HIPAA

Tags: HIPAA

Ogletree Deakins Link to more items from this source
[Guidance Overview]
June 8, 2026

"HHS and plan sponsor Star Group (SG) reached an agreement to resolve alleged HIPAA violations related to Star Group’s health plan, imposing $245,000 in fines and an extensive corrective action plan. The two-year corrective action plan will require the health plan to conduct a comprehensive HIPAA data security risk analysis, update training materials, and make annual reports to HHS. This enforcement action emphasizes the need for employers to prioritize security measures for health plan protected health information (PHI) and electronic protected health information (ePHI), as ransomware incidents can trigger government scrutiny and potential penalties under HIPAA."  MORE >>

Tags: HIPAA

HUB International Link to more items from this source
May 27, 2026

"Self-funded group health plans implicate HIPAA ... Ransomware is treated as a presumptive breach ... A thorough and comprehensive risk analysis is critical in the wake of a breach ... Questions employers should be asking: [1] Do we have policies and procedure in place for HIPAA Privacy and HIPAA Security? [2] What about Breach Notification protocols? [3] Are employees with access to PHI completing HIPAA training annually? [4] Do we have a written incident response procedure that addresses ransomware scenarios and HIPAA breach notification timelines?"  MORE >>

Tags: HIPAA

Holland & Hart LLP Link to more items from this source
[Guidance Overview]
May 21, 2026

"The HIPAA privacy and security rules generally apply to protected health information of deceased persons as well as the living.... As with living persons, HIPAA allows providers to use or disclose protected health information of deceased persons for purposes of treatment, payment, or the provider's healthcare operations, unless the provider has agreed otherwise."  MORE >>

Tags: HIPAA

WTW Link to more items from this source
[Guidance Overview]
May 18, 2026

"A recent resolution agreement between [HHS] and an employer-sponsored group health plan resulted in a $245,000 payment and a comprehensive corrective action plan. This serves as a timely reminder that the Security Rule's requirements apply squarely to plan sponsors, not just healthcare providers.... [This article discusses] the key details of this enforcement action ... what the required risk analysis entails and ... what you should prioritize to stay ahead of the curve."  MORE >>

Tags: HIPAA

Gallagher Link to more items from this source
May 18, 2026

"This checklist helps employers understand their obligations and opportunities when an employee notifies them of their new marriage. Questions often arise on possible election changes, beneficiary rights and organizational policies. This checklist captures common compliance issues and offers helpful suggestions to avoid complications down the road."  MORE >>

Tags: 401(k) Plans  •  Death Benefits & Life Insurance  •  HIPAA  •  Health Plan Administration

Tags: HIPAA

BakerHostetler Link to more items from this source
[Guidance Overview]
May 4, 2026

"While HIPAA included employer-sponsored health plans within the definition of a HIPAA covered entity, OCR is -- for the first time in OCR's enforcement history -- applying its long-standing enforcement agenda directly to the employer health plan context. This activity is a reminder that HIPAA applicability is an overlooked legal risk for many major employers."  MORE >>

Tags: HIPAA

Tags: HIPAA

BakerHostetler Link to more items from this source
Apr. 29, 2026

"Risk analysis remains the foundation of HIPAA Security Rule compliance and continues to be a key OCR enforcement focus. Business associates and vendors are a major source of healthcare cybersecurity risk, making third-party oversight essential. Incident response, workforce training and documented security decisions are now critical markers of a defensible compliance program."  MORE >>

Tags: HIPAA

Jackson Lewis P.C. Link to more items from this source
Apr. 27, 2026

"While HIPAA enforcement is common in the healthcare sector, actions directly against employer-sponsored group health plans are not as common. This case, coupled with DOL guidance for ERISA fiduciaries concerning cybersecurity, underscores a growing regulatory focus not only on traditional healthcare entities, but also on the plans and ecosystems maintained by employers under ERISA."  MORE >>

Tags: HIPAA

U.S. Department of Health and Human Services [HHS] Link to more items from this source
Apr. 21, 2026

27 pages. "OCR received 732 notifications of breaches of unsecured PHI affecting 500 or more individuals that occurred during 2023, representing an increase of 17% from the number of reports received in calendar year 2022. These reported breaches affected a total of approximately 113,173,613 individuals. The most commonly reported category of breaches was hacking, and the largest breach of this type involved approximately 11,270,000 individuals. OCR also received 68,315 reports of breaches affecting fewer than 500 individuals that occurred during 2023, with unauthorized access or disclosure as the most frequent type of breach reported. These smaller breaches affected a total of 269,290 individuals."  MORE >>

Tags: HIPAA

Vorys Link to more items from this source
[Guidance Overview]
Apr. 16, 2026

"The Conduent incident is one of the largest reported health care data breaches in U.S. history and appears to have involved sensitive personal and protected health information. Even when a breach occurs at a third-party subcontractor, the employers' health plans may still have obligations under HIPAA. Because of the significant potential penalties for failure to report a breach, it is important to for employers with self-funded group health plans to take prompt steps to assess whether the plan's data has been affected and whether any obligations have been triggered for the plan."  MORE >>

Tags: HIPAA

Constangy, Brooks, Smith & Prophete, LLP Link to more items from this source
[Guidance Overview]
Apr. 13, 2026

"If the provisions of the Final Rule are substantially similar to those in the Proposed Rule, it would raise the bar for demonstrating compliance with the HIPAA Security Rule. Under the proposed framework, incomplete documentation or informal practices will be harder to defend, particularly where an entity cannot show consistent, enterprise-wide governance. Organizations with mature, well-documented security programs will be better positioned to adapt, while others may need to reassess foundational compliance structures."  MORE >>

Tags: HIPAA

Miller Nash LLP Link to more items from this source
Mar. 20, 2026

"Employers should continue to exercise care to ensure that requests for medical records and similar information are justified by applicable law ... but can now be assured that, where necessary, HIPAA does not excuse the employee's obligation to provide it.... Employers should also continue to maintain medical records separately from personnel files, limit access to those with a need to know, and state in forms and notices how information will be used and protected, aligning with federal and state privacy obligations.​" [Trumper v. Women's Healthcare Assoc. LLC, No. 1010 (Ore. App. Nov. 26, 2025)]  MORE >>

Tags: HIPAA

Tags: HIPAA  •  Health Plan Administration  •  Reporting to Government Agencies

Haynes Boone Link to more items from this source
[Guidance Overview]
Mar. 12, 2026

"For plan sponsors, the potential lag between the date when mail is deposited at USPS and when it is actually processed and postmarked creates risk that time-sensitive materials (e.g., COBRA election notices, HIPAA certificates, decisions on benefit claims and appeals, summary plan descriptions, QDIA notices, fee disclosures and other required disclosures) may bear a postmark date later than intended, even if mailed before the deadline."  MORE >>

Tags: COBRA  •  HIPAA  •  Retirement Plan Administration

WTW Link to more items from this source
[Guidance Overview]
Mar. 6, 2026

"Group health plans can access a model notice as well as a Word version of a model notice on the HHS website. Under the HIPAA privacy rules, group health plans and other covered entities that receive, maintain or transmit certain SUD treatment records must update their NPPs to include specific content related to how they use or disclose the records. The deadline for updating the NPP was February 16, 2026."  MORE >>

Tags: HIPAA

Fisher Phillips Link to more items from this source
[Guidance Overview]
Mar. 3, 2026

"[1] Determine if your organization receives, maintains, or transmits PHI.... [2] Don't rely solely on TPA's policies.... [3] Designate a HIPAA Compliance Officer.... [4] Implement policies on uses and disclosures of PHI.... [5] Maintain a Notice of Privacy Practices (NPP) for your plan participants.... [6] Comply with the Security Rule and stay tuned for updates.... [7] Implement a business associate agreement (BAA) when required.... [8] Follow breach notification rules.... [9] Ensure ERISA fiduciary and cybersecurity oversight."  MORE >>

Tags: HIPAA

Holland & Hart LLP Link to more items from this source
[Guidance Overview]
Mar. 3, 2026

"As of February 16, 2026, the new rules governing the confidentiality of substance use disorder (SUD) records will be enforced. If they have not done so, federally assisted SUD programs (Part 2 Programs) who are covered entities under HIPAA will need to update their business associate agreements (BAAs) to ensure compliance with the new rules."  MORE >>

Tags: HIPAA

Fox Rothschild LLP Link to more items from this source
[Guidance Overview]
Feb. 27, 2026

"Health plans (including employer sponsors of self-insured group health plans) must update their published NPPs. Coming to the rescue of providers that waited to make the required changes to their Notices of Privacy Practices regarding SUD treatment records, the federal government itself waited until February 16 to update its model Notice of Privacy Practices to provide sample language that can be used to update or help draft NPPs for Part 2 compliance."  MORE >>

Tags: HIPAA

Thomson Reuters / EBIA Link to more items from this source
[Guidance Overview]
Feb. 26, 2026

"[T]he revised model notices can be a useful starting point, but plan sponsors should ensure that the final NPP language aligns with their actual practices and administration, and should coordinate updates with insurers, TPAs, and counsel. Given OCR's announcement of a civil enforcement program for confidentiality of SUD patient records, plan sponsors, group health plans, and business associates that receive and disclose information related to SUDs should act quickly to understand their obligations."  MORE >>

Tags: HIPAA

Sheppard Link to more items from this source
[Guidance Overview]
Feb. 24, 2026

"[1] Review and update consent forms facilitating release of SUD information to take advantage of the Final Rule's new flexibilities ... [2] Review and update Notices of Federal Confidentiality Requirements ... [3] Review and update Notices of Confidentiality Requirements ... [4] Revisit existing relationships with qualified service organizations (QPOs) to ensure appropriate agreements are in place. [5] Ensure that personnel handling SUD information receive training on the Final Rule's updates."  MORE >>

Tags: HIPAA