Skip to content
Benefits

If a Group Health Plan’s Business Associate Provides HIPAA Breach Notices, Must the Plan Also Send Notices?

EBIA Checkpoint News Staff  

· 5 minute read

EBIA Checkpoint News Staff  

· 5 minute read

QUESTION: A HIPAA business associate for our company’s group health plan experienced a breach of participants’ unsecured PHI and is preparing to send breach notifications to affected individuals. Must our plan also provide HIPAA breach notices, or may it rely on the business associate’s notifications?

ANSWER: If the business associate provides the required HIPAA breach notifications on behalf of the group health plan and the notices satisfy HIPAA’s timing, content, and delivery requirements, duplicate notice need not be sent. However, the group health plan should confirm that the notices were complete and compliant because the plan, as the HIPAA covered entity, remains responsible for ensuring that required breach notifications are made.

HIPAA’s breach notification rules apply to group health plans and business associates. However, business associates generally must notify the group health plan of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery, while group health plans are responsible for ensuring that required notices are provided to affected individuals, HHS, and, when applicable, the media. A business associate may perform notification tasks on behalf of a plan if the notices satisfy HIPAA’s requirements and the business associate has been authorized or directed to do so, typically through the business associate agreement or other breach-response arrangement.

For fully insured plans, the insurer is also a HIPAA covered entity. If a fully insured group health plan is “hands-off” with respect to PHI—meaning that the insurer handles PHI and the employer or plan sponsor receives only limited enrollment, disenrollment, or summary health information—then the group health plan typically has limited HIPAA privacy rule obligations. The insurer, as a covered entity, will generally handle HIPAA compliance for PHI it maintains in connection with the insured coverage. If the fully insured plan or plan sponsor is “hands-on” with respect to PHI, then the group health plan has additional HIPAA compliance responsibilities. But duplicate notices generally are not required if the insurer or business associate has already provided compliant notices on behalf of the appropriate covered entity.

Self-insured group health plans are responsible for breach notification compliance. Because many self-insured plans have no employees of their own, the employer or plan sponsor often performs administrative functions for the plan. But the covered entity remains the plan, not the employer acting in its employer capacity. If a business associate, such as a TPA, provides the required breach notices on the plan’s behalf, the plan generally does not need to send a second notice.

Group health plans should not assume that a business associate’s notification fully satisfies HIPAA merely because the business associate sent notices. The business associate agreement and any breach response provisions should be reviewed to determine whether the business associate was authorized or required to provide notices on the plan’s behalf. The plan should document the delegation of notice responsibilities; obtain copies or summaries of the notices; confirm the date and method of distribution; verify the affected population; confirm that required content was included; and determine whether HHS notice, media notice, or substitute notice was required and properly made. Covered entities also may want approval rights concerning the content of the notifications before they are sent.

If the business associate’s notices were incomplete, untimely, sent to the wrong population, or missing required content, or if it failed to provide required HHS, media, or substitute notices, the plan may need to provide corrective or supplemental notices. The plan should also consider whether state breach notification laws, contract terms, ERISA fiduciary considerations, or participant relation concerns call for additional action. Duplicate HIPAA notices are usually unnecessary and may confuse participants, but documentation that the required notices were properly made is essential.

For more information, see EBIA’s HIPAA Portability, Privacy & Security manual at Sections XX (“Enforcement of Privacy, Security, and EDI Rules”), XXIII (“How the Privacy and Security Rules Affect Group Health Plans and Plan Sponsors”), XXIV (“Business Associate Contracts”), and XXV (“Breach Notification for Unsecured PHI”). See also the manual’s Sample Checklist for Business Associate Contract Provisions, Sample Business Associate Contract Provisions, and Sample Business Associate Security Questionnaire (and the Guides to these sample documents), which may assist covered entities in addressing their business associates’ compliance with HIPAA’s privacy and security rules.

 

Take your tax and accounting research to the next level with Checkpoint Edge and CoCounsel. Get instant access to AI-assisted research, expert-approved answers, and cutting-edge tools like Advisory Maps and State Charts. Try it today and transform the way you work! Subscribe now and discover a smarter way to find answers.

More answers