HIPAA for Self-Funded Plans and TPAs: The covered entity distinction

Why it matters, and how to use it.

In our earlier post, we covered the basics. A self-funded group health plan is generally a covered entity within the meaning of the Health Insurance Portability and Accountability Act, while the third-party administrator that processes claims is a business associate.

Today we’ll cover a practical question many employers and benefits teams ask once the labels are clear: How to use the covered entity/business associate structure to limit liability, and what happens when Human Resources data, group policies, and real-world access to information blur the lines?

The Core Separation: You pay, the TPA handles the claims.

In a self-funded arrangement, the employer or plan it sponsors bears the financial risk. The TPA receives claims, adjudicates them, pays providers, and manages the day-to-day flow of protected health information.

That separation of roles is intentional. When the TPA is properly positioned as a business associate under a Business Associate Agreement, the self-funded plan can often isolate its HIPAA exposure. A breach that occurs entirely within the TPA’s systems is primarily the TPA’s problem to investigate and report (subject to the terms of the BAA). The plan still has oversight duties, but the practical risk is narrower.

Under HIPAA regulations, a TPA providing claims administration services to a group health plan is generally a business associate, not a covered entity.

An employer shouldn’t have PHI -- except when it does.

A common goal is to keep detailed protected health information out of the employer’s own systems. If HR never sees claims data, medical diagnoses, or treatment information, the theory goes, there is no risk of a HIPAA breach on the employer side. If there is a true separation, the only data HR should hold is that of a non-covered-entity employer for standard benefit administration purposes.

That theory holds only when the firewall is real. But in practice,

  • Plan sponsors often receive limited information for stop-loss reporting, claim audits, appeals, or plan design analysis.
  • Group policies and plan documents sometimes contain exceptions that authorize the plan sponsor to receive PHI for specific administrative functions.
  • Shared IT environments, email systems, or staff who wear both “HR” and “benefits administration” hats can inadvertently create pathways for PHI to reach employer systems.

When those pathways exist, the self-funded plan (the covered entity) remains responsible for protecting that information under HIPAA. HR employment records, by contrast, are generally governed by state privacy and employment laws, not HIPAA—unless the data originated from the plan and was improperly mixed.

Recent enforcement actions taken by the U.S. Department of Health and Human Services Office of Civil Rights against self-funded group health plans have made clear that the plan itself carries independent compliance obligations, separate from those of the plan sponsor and its TPA. Plans have been cited for failing to conduct an accurate and thorough risk analysis of electronic protected health information, including data that may reside on plan-sponsor systems.

Covered entities that also act as TPAs

Some organizations have dual roles. An insurer or benefits firm may sponsor its own self-funded plan -- making that plan a covered entity -- while also providing TPA services to other employers’ self-funded plans -- making it a business associate for those clients.

In those dual-role situations, the distinction becomes even more important:

  • Protected health information received while the entity is acting as a TPA for a client plan cannot be freely used for the company’s own underwriting, marketing, or other purposes.
  • Separate systems, access controls, and Business Associate Agreements are required to keep the roles clean.
  • A breach in one capacity does not automatically create liability in the other, provided the operational and contractual walls are maintained.

The “covered entity avenue” is therefore less about escaping regulation and more about correctly identifying the legal role that applies to any given data set or activity. Under the applicable regulations, a group health plan (including a self-funded plan) is a covered entity if it has 50 or more participants, or is administered by an entity other than the employer that established and maintains the plan.

Six ways to minimize liability

Based on recent OCR enforcement focus on self-funded plans and the practical realities, the following steps can help preserve the isolation the structure is meant to provide:

 No. 1: Maintain a true firewall

Keep PHI Planned separate from general HR and corporate systems. Use dedicated access controls, repositories, and (where possible) separate email or file environments for benefits administration functions. The OCR has emphasized the need for plan-specific safeguards that address any connections between plan electronic PHI and the employer’s corporate IT environment.

No. 2: Review group policy and plan document language

Identify any exceptions that authorize the plan sponsor to receive PHI. Confirm those exceptions are narrowly tailored and that corresponding safeguards exist under the plan’s HIPAA policies.

No. 3: Treat the TPA relationship as a real business-associate relationship

Execute and periodically update Business Associate Agreements that clearly allocate breach investigation, notification, and cost responsibilities. A covered entity must enter into a business associate agreement before allowing a TPA to create, receive, maintain, or transmit PHI on its behalf. More details are available here.

No. 4: Conduct a plan-specific risk analysis

The OCR has emphasized that self-funded plans must evaluate risks to electronic PHI, including any connections between the plan’s data flows and the employer’s corporate IT environment. A generic corporate risk assessment is not enough.

No. 5: Train dual-role staff

Employees who handle both employment records and plan administration need clear guidance on when information is PHI, as opposed to ordinary HR data, and which rules apply.

No. 6: Document the separation

Written policies, access logs, and incident-response playbooks that explicitly distinguish plan functions from employer functions are valuable for compliance and for demonstrating good-faith efforts if something goes wrong.

Conclusion

When paired with a properly structured TPA relationship, clear group-policy language, and disciplined operational firewalls, the covered-entity status of a self-funded plan can meaningfully limit the risk of HIPAA exposure.

Your organization may sponsor a self-funded plan, act as a TPA, or do both. If so, a focused review of your Business Associate Agreements, plan documents, and data-flow maps is a practical next step. The distinctions drawn above -- who pays, who handles the claims, what the group policy allows, and whether PHI truly stays isolated -- remain the best starting points for reducing the risk of liability.

Our data privacy team helps employers audit compliance, negotiate Business Associate Agreements, develop policies, and respond to incidents. We are available to review the HIPAA readiness of your self-funded plan. Contact us at cyber@constangy.com.

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek