Yes, HIPAA applies to a self-funded health plan, and in 2026 the HHS Office for Civil Rights started collecting money to prove it. In April, a Connecticut energy provider's self-funded employee health plan paid $245,000 after a ransomware attack exposed the records of 9,316 members. In June, the self-funded plan of the retailer Spencer Gifts paid $450,000 over a 2021 ransomware attack that hit 10,023 people. Neither employer is in healthcare. One sells heating oil, the other sells novelty gifts. Both sponsor a group health plan, and under HIPAA that plan is a covered entity with the full set of Security Rule obligations attached to it.
The thing most people get wrong is where the liability sits. The regulated entity is not the company. It is the plan, a legal creature with no staff, no servers and no bank account, which borrows all three from its sponsor. That is why the settlements are signed by "Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans" and "Star Group, L.P. Health Benefits Plan" rather than by the companies. It is also why the second assumption fails: that because a third-party administrator processes the claims, the TPA carries the compliance burden. In both 2026 cases the ransomware landed on the employer's own network, on infrastructure the IT team almost certainly did not have tagged as in scope for HIPAA.
This page is for the IT manager or security lead at a mid-sized company that self-funds its medical benefits, which is common once headcount runs into the high hundreds. It covers what triggers HIPAA liability for the plan, the documents OCR's corrective action plans demand, and the work to do before someone asks you for a risk analysis you have not written.
Why the plan is the covered entity and the company is not
A self-funded plan, sometimes called self-insured, means the employer pays medical claims out of its own money instead of buying coverage from a carrier. It usually hires a third-party administrator to process claims and run the network, and it usually buys stop-loss insurance to cap a catastrophic year. What it does not do is transfer the risk, or the regulatory status, to an insurer.
HIPAA's covered entities are health care providers who bill electronically, health care clearinghouses, and health plans. A group health plan is a health plan. Nothing in the definition asks what the sponsoring company sells. Holland & Knight put the consequence in one line in its April 2026 client alert: "Companies that operate completely outside the healthcare industry can sponsor health plans."
So the plan is separately regulated, and it has to comply using the sponsor's people and systems. When the HR benefits analyst opens an appeal file on a laptop, that laptop is in scope. When the file server holds a spreadsheet of enrollment and claims data pulled from the TPA portal, that server is in scope. When ransomware encrypts both, OCR's question is not whether the company had a security program. It is whether the plan had one.
What OCR actually investigates
A breach affecting 500 or more people gets reported to OCR, and OCR opens an investigation. Since 2024 it has run what it calls the Risk Analysis Initiative, a deliberate campaign against one specific failure: the absence of an accurate and thorough analysis of risks to the confidentiality, integrity and availability of electronic protected health information. That obligation is at 45 C.F.R. § 164.308(a)(1)(ii)(A), and HHS noted in its April 2026 announcement that it has been in force since 2005.
The Spencer Gifts settlement is OCR's 20th enforcement action tied to a ransomware investigation and the 14th under the Risk Analysis Initiative, according to HHS and confirmed in Nixon Peabody's July 2026 analysis. Both counts matter to you for the same reason: they tell you what OCR asks for first. It asks for the risk analysis that existed before the attack, and if there is not one, the rest of the investigation is a formality.
The Spencer Gifts timeline is worth reading closely. The attack ran from November 24 to November 26, 2021. Employees found it in January 2022 when they could not reach the company VPN, which is how BankInfoSecurity describes the discovery; the same report attributes the attack to the now-defunct Conti gang. The plan filed its breach report with OCR on January 24, 2022. Names, addresses, ZIP codes, phone numbers, email addresses and Social Security numbers were exposed for 10,023 plan members. The settlement was announced more than four years later. OCR's findings were a missing risk analysis and missing policies and procedures, citing § 164.308(a)(1)(ii)(A) along with § 164.316(a) and § 164.530(i)(1), the provisions that require documented policies under the Security and Privacy Rules, per HIPAA Journal.
The energy company's case went one step further. OCR found an impermissible disclosure of PHI, no thorough risk analysis, and no complete inventory of the facilities, equipment, data systems and applications that store, transmit or process ePHI. The corrective action plan requires the plan to build that inventory first and then feed it into the risk analysis, which is the correct order and the one most plans skip.
| Question | Fully insured, sponsor takes summary data only | Self-funded, ePHI stays at the TPA | Self-funded, sponsor staff and systems handle ePHI |
|---|---|---|---|
| Is the plan a covered entity? | Yes, but the carrier holds the ePHI | Yes | Yes |
| Does the sponsor need a Security Rule program for the plan? | Minimal, where it receives only summary health information and enrollment and disenrollment data | Limited to whatever it touches, which is rarely nothing | Yes, on every system in the ePHI inventory |
| Where did the 2026 breaches actually happen? (Troutman Pepper Locke, Aug 2026) | Not represented in these cases | Not represented in these cases | Both: ransomware hit plan sponsor systems, not TPA systems |
| Whose risk analysis did OCR demand? (HHS, Apr and Jun 2026) | Carrier's, in practice | The plan's, covering vendor-held ePHI as well | The plan's, covering sponsor-held ePHI |
| Penalty on the public record in 2026 | None in these announcements | None in these announcements | $245,000 (Apr 2026) and $450,000 (Jun 2026) |
| Who signs the corrective action plan? (HHS, Jun 2026) | Not applicable here | The plan, with the sponsor executing it | The plan, with the sponsor executing it, for two years |
The work, in the order OCR asks for it
What follows mirrors the sequence in the two corrective action plans: inventory, risk analysis, risk management plan, policies, distribution, training, reporting. Running it before an incident costs a fraction of running it under OCR supervision, because nobody is approving your drafts on a deadline.
Before you start, get these in place. If you cannot tick all of them, the first three steps below are where you spend your time.
-
Written confirmation of whether the plan is self-funded, fully insured, or a mix by benefit
Medical may be self-funded while dental and vision are insured. The answer can differ per component, and each component is a health plan.
-
The current plan documents and the administrative services agreement with the TPA
Nixon Peabody's advice after the Spencer Gifts settlement is to use these documents to state explicitly who carries which HIPAA duty.
-
A named privacy official and security official for the plan
The corporate CISO can hold the role, but the appointment has to name the plan.
-
A list of everyone who touches plan data: benefits, HR, payroll, finance, IT, and anyone handling appeals
-
Access to the TPA portal audit logs, or a request in to get them
-
Executive sign-off that this is plan work, not an IT side project
The ERISA Litigation & Compliance blog recommends a standing team across IT security, benefits and facilities, because no one of those three can see the whole ePHI footprint.
1. Draw the line around the plan. Write down, in one page, which benefit components are self-funded and which data the sponsor receives beyond enrollment and summary information. You are done when benefits and IT both sign it. Half a day, and it decides the scope of everything after.
2. Inventory every asset that creates, receives, maintains or transmits plan ePHI. Facilities, equipment, data systems, applications. This is the finding OCR made against the energy company's plan, and the first thing its corrective action plan requires. Include the HR file share, the benefits mailbox, the laptop of whoever handles appeals, the payroll system if deductions carry diagnosis-linked data, the wellness vendor, the stop-loss carrier's submissions, and the TPA's portal. You are done when every line has an owner, a location and a note on whether it is encrypted. Expect one to three weeks of part-time work, most of it interviews rather than scanning.
3. Paper the vendors. Every entity handling plan ePHI on the plan's behalf needs a business associate agreement, and the administrative services agreement should say who does what. Check that the TPA, pharmacy benefit manager, broker, COBRA administrator and wellness vendor each have one on file and that the signatory was the plan. You are done when the list from step 2 and the BAA list match, with no orphans on either side. A week, plus however long vendor legal takes.
4. Conduct the risk analysis at plan level. This is the step that decides the case. A corporate-wide security assessment is not a plan risk analysis unless it names the plan, its ePHI assets, and the specific threats and vulnerabilities to the confidentiality, integrity and availability of that data, with likelihood and impact for each. HHS publishes a free Security Risk Assessment Tool, which the ERISA Litigation & Compliance analysis recommends for plans that are not buying a consultant. You are done when the document carries a scope statement, a date, a named author, and a row for every asset from step 2. Two to six weeks depending on whether you do it in-house.
5. Turn the findings into a risk management plan. OCR does not just want the list of risks. Both corrective action plans require a risk management plan, subject to OCR review and approval, that says what gets fixed, by whom, by when. Accepting a risk is allowed if the decision is documented and someone senior signed it. You are done when every high and medium finding has an owner and a date. A week to write, months to execute.
6. Write the three sets of policies OCR cited. Privacy, Security and Breach Notification, at the plan level. Spencer Gifts was cited for failing to implement reasonable and appropriate policies under all three. Do not borrow a hospital template wholesale; a plan has no treatment operations and a plan-specific document is shorter and more defensible. You are done when the policies refer to your actual systems and your actual TPA by name. Two to four weeks.
7. Distribute the policies and train the workforce, with records. The corrective action plan requires distribution to the workforce and documented HIPAA training. "Documented" means an attendance record with names and dates that survives the departure of whoever ran it. Train the people on the step 1 list, not the whole company, unless the whole company touches plan data. Half a day per session, plus the tracking.
8. Build the breach runbook, and connect it to the service desk. Spencer Gifts found its ransomware because employees complained they could not reach the VPN. That is how these things surface. The runbook needs a rule that a suspected outage affecting systems on the ePHI inventory goes to the plan's privacy official the same day, because the Breach Notification Rule's clock runs from discovery, not from the date you finish the forensics. For a breach affecting 500 or more individuals, notice to affected people and to the HHS Secretary is due without unreasonable delay and no later than 60 days after discovery. You are done when a tabletop exercise produces a named person who files, and they know the portal.
9. Re-run it and keep the old versions. Enforcement looks backwards. HHS's finding against Spencer Gifts was that the plan failed to conduct an accurate and thorough risk analysis prior to the breach. A risk analysis written after an incident does not cure the violation, it just proves you can do one. Re-run annually and whenever you change TPA, add a vendor, or move plan data into a new system. Keep every dated version, because the one that matters is whichever was current on the day of the attack.
The failures OCR wrote into these settlements
These are not generic mistakes. Each one appears in the 2026 record.
The corporate risk assessment stood in for the plan's. Both settled cases cite the same root failure, and both employers had functioning IT departments. The tell is a risk assessment document that discusses the company's crown-jewel systems and never uses the words "health plan" or "ePHI". Fix: re-scope, do not re-title. An appendix naming plan assets and plan-specific threats, dated and signed, is the minimum.
No asset inventory, so the risk analysis had nothing to analyse. OCR found the energy company's plan had no complete inventory of facilities, equipment, data systems and applications handling ePHI. The tell is a risk analysis that assesses categories ("email", "file storage") rather than named systems. Fix: build the inventory first, as the corrective action plan requires, then redo the analysis against it.
The TPA was assumed to be carrying the compliance. Troutman Pepper Locke's August 2026 summary of both cases makes the point sharply: the ransomware hit plan sponsor systems, not administrator systems. A perfect TPA does not help when the ePHI is sitting on your file server. Fix: step 2 above. The inventory answers this question on paper rather than in argument.
Nobody expected a retailer's HR share to be a HIPAA target. Conti did not go looking for protected health information at a novelty gift chain. It encrypted what was there. The attack path was ordinary and the regulatory consequence was not. Fix: treat the plan ePHI inventory as a tagging exercise on systems you already defend, not as a separate estate.
Assuming the fine tracks the number of records. It does not. Spencer Gifts affected 10,023 people and paid $450,000. Assured Imaging, settled in the same year, affected 244,813 people and paid $375,000. BankInfoSecurity reads that contrast as OCR pricing the depth and duration of the compliance failure rather than the headcount. Fix: stop estimating exposure from your enrollment number.
Late notification as a separate finding. Among the four April 2026 settlements, Assured Imaging was cited for untimely breach notification on top of the risk analysis failure. It is worth being precise about Spencer Gifts here, because the timeline gets repeated loosely: the attack window was November 24 to 26, 2021, and the breach was reported to OCR on January 24, 2022. What took years was OCR's resolution, not the filing. The public materials we have do not cite Spencer Gifts for untimely notification; they cite missing policies, including breach notification policies. If you see the case described as a three-year reporting delay, that is not what the HHS announcement says.
Training that happened but was not recorded. Both corrective action plans require documented training and distribution of policies to the workforce. An investigator asking "show me" is asking for the roster, not the deck. Fix: keep completion records with the policy version number they were trained on.
Cases where the answer changes
Your plan is fully insured and the company sees nothing but summary data. The carrier holds the ePHI and carries the weight. A sponsor that receives only summary health information and enrollment and disenrollment data has a much lighter set of obligations. The moment HR starts handling individual claims questions or appeals, that changes, and it changes quietly.
The plan is self-administered and very small. The regulation's own definition of "health plan" at 45 C.F.R. § 160.103 excludes a group health plan with fewer than 50 participants that is administered solely by the employer that established it. Most self-funded arrangements at a mid-sized company fail both halves of that test, since they run through a TPA and cover more than 50 people. Check it rather than assume it.
You have a mix of components. Medical self-funded, dental insured, a health FSA, an EAP, an on-site clinic. Each is assessed on its own. Spencer Gifts' settling entity was its "Flexible Benefits and Welfare Benefit Plans", plural, which is the shape most of these programs have.
The breach happens at the TPA rather than at you. The TPA is a business associate and has its own direct liability, but the plan's own obligations do not lapse. OCR's April 2026 sweep included Consociate Inc., a benefits administrator, fined $225,000 over a breach affecting 136,539 people that began with a phishing attack in July 2020 and ended in ransomware deployed in November and December 2021. Both sides of the relationship got investigated that year.
You are already under a corrective action plan. The rules become tighter and dated. Both 2026 CAPs run two years under OCR monitoring, and the risk management plan goes to OCR for approval. At that point you are not choosing your own remediation schedule.
The plan is old, or the systems are. No help. HHS made a point of noting in the April 2026 announcement that the risk analysis requirement has applied since 2005. There is no grandfathering argument available.
What it cost those two employers, and what the work costs you
The settlement figure is the visible cost and probably not the largest one. Both plans also owe two years of OCR-monitored corrective action: a full risk analysis, a risk management plan submitted for OCR approval, rewritten policies, workforce distribution, documented training and periodic reports back to the agency. That is the same work described in the section above, done on someone else's schedule with someone else's approval gate, plus counsel. None of the sources put a number on what executing those CAPs cost the two employers, so treat that as unquantified rather than small.
The April 2026 announcement gives the scale of the sweep these plans were caught in: four entities, $1,165,000 combined, more than 427,000 individuals affected. The other three were an imaging provider, a women's health group and a benefits administrator, the kind of organisations that expect HIPAA enforcement. The plan of an oil and propane distributor sat in that list alongside them.
On the other side of the ledger, the entry cost is lower than most security work. HHS's Security Risk Assessment Tool is free. The inventory and the interviews are staff time you already pay for. The expensive parts are the ones you would want anyway: encryption on the file shares that hold claims data, MFA on the benefits mailbox, backups that survive a ransomware event. Spencer Gifts' loss was not exotic. It was a 2021 Conti intrusion of the kind that hit thousands of mid-sized companies, and the difference between those companies and this one was a regulated health plan sitting on the encrypted drives.
There is also a signal in the enforcement pattern that deserves a plain reading. Two cases is a pattern, not a trend, and OCR has not announced a self-funded plan initiative. But the Risk Analysis Initiative is announced, it is at 14 actions as of June 2026, and it now has two worked examples of the agency going to the employer's plan directly rather than to its administrator. What would settle the question is a third and fourth case in the same shape. Until then, the honest statement is that OCR has shown it will do this, twice, and that nothing about either case was unusual enough to suggest they were singled out.
Effective cybersecurity starts with Security Rule compliance, ensuring that Security Rule provisions are implemented before a cyberattack occurs.
Comments
No comments yet. Be the first to comment!
Leave a Comment