← Back to Blog

If Your Company Self-Funds Its Health Plan, You May Be a Covered Entity and Not Know It

An Enforcement Action Aimed Somewhere Unexpected

Most HIPAA coverage focuses on providers: clinics, hospitals, dental practices, therapists. But the law names three kinds of covered entity, and one of them is health plans. That category includes something a lot of employers do not think of as a health plan at all — the self-funded group health plan they sponsor for their own employees.

In 2026, OCR announced settlements totaling $695,000 with two self-funded group health plans following ransomware breaches. Both were cited for the same thing: failing to conduct an accurate and thorough risk analysis of the risks to electronic protected health information. The breach drew the investigation; the missing risk analysis produced the penalty. That is the pattern we have seen across nearly every enforcement action this year.

Self-Funded vs. Fully Insured: Why It Matters So Much

This distinction decides how much HIPAA you own, and many employers cannot say which side they are on.

In a fully insured arrangement, you pay premiums to an insurance carrier and the carrier bears the claims risk. The carrier is the covered entity. If the employer receives only summary information and enrollment data — and does not handle individual claims detail — the plan's obligations are comparatively light.

In a self-funded arrangement, the employer pays claims out of its own funds, usually with a third-party administrator processing them. Here the plan itself is a covered entity, and the employer sponsoring it takes on real obligations: a risk analysis covering the plan's ePHI, written policies, workforce training, safeguards, business associate agreements with the administrator and related vendors, and a breach notification process.

The trap is that a self-funded plan usually does not feel like a healthcare operation. It lives in HR or finance. The administrator handles the day-to-day. Nobody in the building thinks of themselves as working for a covered entity, so nobody does the things a covered entity is required to do — until a ransomware incident brings a regulator who does think of it that way.

The Questions That Tell You Where You Stand

If your organization sponsors a health plan for employees, work through these honestly:

  • Do we pay claims from our own funds? If yes, you are self-funded, regardless of who administers the plan for you. A stop-loss policy does not change this.
  • Does anyone here see individual claims information? Appeals, eligibility disputes, and escalated billing questions frequently put identifiable health information in front of HR staff. That is PHI, and it is being handled by your workforce.
  • Where does that information live? Email inboxes and shared drives are the usual answers, and both are usually outside whatever safeguards were designed for the plan.
  • Do we have a BAA with the third-party administrator? And with the broker, the wellness vendor, the COBRA administrator, and anyone else touching plan data?
  • Has anyone ever done a risk analysis covering the plan? For most employers the answer is no — or the IT risk assessment covered the company's systems generally and never addressed plan ePHI specifically.
  • Who is the plan's HIPAA contact? If the answer is "nobody in particular," that is the gap that produced both of this year's settlements.

The Firewall Requirement People Forget

There is a specific rule here that catches employers off guard. Plan information generally may not flow freely into employment decisions. HIPAA requires separation between the plan's functions and the employer's employment functions — documented in the plan documents, supported by access controls, and reflected in who can see what.

In practice that means the HR manager who administers benefits should not be able to browse claims detail for an employee whose performance is under review, and your systems should make that structurally difficult rather than relying on professionalism. It is one of the few places where HIPAA asks you to design around a conflict of interest, and it is routinely missed because the same person often wears both hats.

A Proportionate Starting Point

If this describes your organization, you do not need to build a hospital compliance program. You need to cover the plan:

Scope it. Write down what plan ePHI you actually hold, where it lives, and who can reach it. For most employers this is a surprisingly short list, and producing it is most of the work.

Run a risk analysis against that scope. This is the item both settlements turned on. Our risk assessment guide applies directly.

Paper the vendors. BAAs with the administrator and every downstream vendor handling plan data.

Train the handful of people who touch it. Usually two or three in HR. Training them well beats training everyone poorly.

Write down the separation. Who may access plan information, for what purpose, and how that is enforced.

Why This Is Worth an Afternoon

The employers penalized this year were not negligent in any dramatic way. They sponsored a benefit for their staff, outsourced the administration, and never learned that doing so made them a covered entity. That is an understandable mistake and an expensive one, and it is entirely avoidable with a few hours of scoping.

If you sponsor a self-funded plan, the useful question is not whether HIPAA applies — it very likely does — but whether anyone at your organization has ever been assigned to act on it.

Related Reading

Call to Action

Not sure whether your group health plan is in scope — or what covering it would involve? Take the 3-minute readiness quiz for a plain-language read, or schedule a walkthrough to see how risk analysis, policies, training, and BAAs fit together for a plan sponsor.

Ready to simplify your HIPAA compliance?

See how HIPAA Security Suite can protect your organization.

Request a Demo