Why it matters, and how to use it.
In our earlier post, we covered the basics. A self-funded group health plan is generally a covered entity within the meaning of the Health Insurance Portability and Accountability Act, while the third-party administrator that processes claims is a business associate.
Today we’ll cover a practical question many employers and benefits teams ask once the labels are clear: How to use the covered entity/business associate structure to limit liability, and what happens when Human Resources data, group policies, and real-world access to information blur the lines?
The Core Separation: You pay, the TPA handles the claims.
In a self-funded arrangement, the employer or plan it sponsors bears the financial risk. The TPA receives claims, adjudicates them, pays providers, and manages the day-to-day flow of protected health information.
That separation of roles is intentional. When the TPA is properly positioned as a business associate under a Business Associate Agreement, the self-funded plan can often isolate its HIPAA exposure. A breach that occurs entirely within the TPA’s systems is primarily the TPA’s problem to investigate and report (subject to the terms of the BAA). The plan still has oversight duties, but the practical risk is narrower.
Under HIPAA regulations, a TPA providing claims administration services to a group health plan is generally a business associate, not a covered entity.
An employer shouldn’t have PHI -- except when it does.
A common goal is to keep detailed protected health information out of the employer’s own systems. If HR never sees claims data, medical diagnoses, or treatment information, the theory goes, there is no risk of a HIPAA breach on the employer side. If there is a true separation, the only data HR should hold is that of a non-covered-entity employer for standard benefit administration purposes.
That theory holds only when the firewall is real. But in practice,
- Plan sponsors often receive limited information for stop-loss reporting, claim audits, appeals, or plan design analysis.
- Group policies and plan documents sometimes contain exceptions that authorize the plan sponsor to receive PHI for specific administrative functions.
- Shared IT environments, email systems, or staff who wear both “HR” and “benefits administration” hats can inadvertently create pathways for PHI to reach employer systems.
When those pathways exist, the self-funded plan (the covered entity) remains responsible for protecting that information under HIPAA. HR employment records, by contrast, are generally governed by state privacy and employment laws, not HIPAA—unless the data originated from the plan and was improperly mixed.
Recent enforcement actions taken by the U.S. Department of Health and Human Services Office of Civil Rights against self-funded group health plans have made clear that the plan itself carries independent compliance obligations, separate from those of the plan sponsor and its TPA. Plans have been cited for failing to conduct an accurate and thorough risk analysis of electronic protected health information, including data that may reside on plan-sponsor systems.
Covered entities that also act as TPAs
Some organizations have dual roles. An insurer or benefits firm may sponsor its own self-funded plan -- making that plan a covered entity -- while also providing TPA services to other employers’ self-funded plans -- making it a business associate for those clients.
In those dual-role situations, the distinction becomes even more important:
- Protected health information received while the entity is acting as a TPA for a client plan cannot be freely used for the company’s own underwriting, marketing, or other purposes.
- Separate systems, access controls, and Business Associate Agreements are required to keep the roles clean.
- A breach in one capacity does not automatically create liability in the other, provided the operational and contractual walls are maintained.
The “covered entity avenue” is therefore less about escaping regulation and more about correctly identifying the legal role that applies to any given data set or activity. Under the applicable regulations, a group health plan (including a self-funded plan) is a covered entity if it has 50 or more participants, or is administered by an entity other than the employer that established and maintains the plan.
Six ways to minimize liability
Based on recent OCR enforcement focus on self-funded plans and the practical realities, the following steps can help preserve the isolation the structure is meant to provide:
No. 1: Maintain a true firewall
Keep PHI Planned separate from general HR and corporate systems. Use dedicated access controls, repositories, and (where possible) separate email or file environments for benefits administration functions. The OCR has emphasized the need for plan-specific safeguards that address any connections between plan electronic PHI and the employer’s corporate IT environment.
No. 2: Review group policy and plan document language
Identify any exceptions that authorize the plan sponsor to receive PHI. Confirm those exceptions are narrowly tailored and that corresponding safeguards exist under the plan’s HIPAA policies.
No. 3: Treat the TPA relationship as a real business-associate relationship
Execute and periodically update Business Associate Agreements that clearly allocate breach investigation, notification, and cost responsibilities. A covered entity must enter into a business associate agreement before allowing a TPA to create, receive, maintain, or transmit PHI on its behalf. More details are available here.
No. 4: Conduct a plan-specific risk analysis
The OCR has emphasized that self-funded plans must evaluate risks to electronic PHI, including any connections between the plan’s data flows and the employer’s corporate IT environment. A generic corporate risk assessment is not enough.
No. 5: Train dual-role staff
Employees who handle both employment records and plan administration need clear guidance on when information is PHI, as opposed to ordinary HR data, and which rules apply.
No. 6: Document the separation
Written policies, access logs, and incident-response playbooks that explicitly distinguish plan functions from employer functions are valuable for compliance and for demonstrating good-faith efforts if something goes wrong.
Conclusion
When paired with a properly structured TPA relationship, clear group-policy language, and disciplined operational firewalls, the covered-entity status of a self-funded plan can meaningfully limit the risk of HIPAA exposure.
Your organization may sponsor a self-funded plan, act as a TPA, or do both. If so, a focused review of your Business Associate Agreements, plan documents, and data-flow maps is a practical next step. The distinctions drawn above -- who pays, who handles the claims, what the group policy allows, and whether PHI truly stays isolated -- remain the best starting points for reducing the risk of liability.
Our data privacy team helps employers audit compliance, negotiate Business Associate Agreements, develop policies, and respond to incidents. We are available to review the HIPAA readiness of your self-funded plan. Contact us at cyber@constangy.com.
- Associate Attorney
As a member of our Rapid Response Team, Brittany assists clients in responding to a variety of cyberattacks including system intrusions, business email compromises, ransomware, and the recovery of fraudulently transferred ...
- Partner
He brings over ten years of combined incident response and risk management experience to his role on our Rapid Response Team. During the seven years prior to joining the Constangy Cyber Team, Matt worked at a boutique incident ...
The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation.



