By: HUB’s EB Compliance Team

The U.S. Department of Health and Human Services ("HHS") Office for Civil Rights ("OCR") announced in June 2026 a $450,000 settlement with the employer-sponsored group health plan of a national retail company, resolving an investigation into potential violations of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") Privacy and Security Rules. The investigation followed a November 2021 ransomware attack that compromised the protected health information ("PHI") of over 10,000 plan members, including names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers.

For employers, the settlement is a reminder that employer-sponsored group health plans are themselves covered entities under HIPAA, and that the Privacy and Security Rule obligations that apply to hospitals, insurers, and other traditional health care organizations also apply to their Plans.

Regulatory Background

Group health plans that create, receive, maintain, or transmit electronic PHI ("ePHI") are covered entities subject to the HIPAA Security Rule. The Security Rule requires covered entities to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the covered entity” and to “implement security measures sufficient to reduce identified risks to a reasonable and appropriate level”. Covered entities must also maintain written policies and procedures reasonably designed to comply with the Privacy, Security, and Breach Notification Rules and must train workforce members on those policies.

Separately, the Breach Notification Rule requires covered entities to report breaches affecting 500 or more individuals to HHS and to affected individuals without unreasonable delay (45 C.F.R. §§ 164.404, 164.408). In the settlement described above, OCR's investigation — opened after the plan's breach report — found that the plan had potentially failed to conduct the required risk analysis and had not implemented adequate Privacy, Security, and Breach Notification Rule policies and must train workforce members that “touch” ePHI and PHI on those policies.

Under the resolution agreement, the plan paid $450,000 and agreed to a two-year corrective action plan monitored by OCR, requiring the Plan to execute a risk analysis, revise their data privacy and security policies and procedures and train their workforce on said policies.

Implications for Plan Sponsors

Plan sponsors may incorrectly assume that HIPAA compliance obligations rest primarily with insurers, third-party administrators, or other vendors that handle claims data. This settlement confirms that OCR continues to hold the group health plan itself — and, by extension, the employer that sponsors and administers it — directly accountable for Security Rule compliance, regardless of the sponsor's core business. A missing or outdated risk analysis is among the most frequently cited deficiencies in OCR enforcement actions.

Employers that self-administer any portion of their group health plan's HIPAA compliance function, or that receive ePHI directly (for example, through enrollment platforms, wellness programs, or claims reporting), should not assume that a carrier's or third-party administrator's compliance program satisfies the plan's own obligations. Plan sponsors should also confirm that business associate agreements with vendors handling ePHI are current and that vendor security practices are reviewed periodically, since a vendor-side failure can still expose the plan to OCR scrutiny.

Action Items

  1. Confirm that a documented, accurate, and thorough risk analysis covering all PHI/ePHI created, received, maintained, or transmitted by the plan has been completed within the past 12 months and is updated annually and when systems or vendors change.
  2. Review and, if necessary, update HIPAA Privacy, Security, and Breach Notification Rule policies and procedures, and confirm they reflect the plan's current vendors and data flows.
  3. Verify that employees with access to plan PHI/ePHI have received role-specific HIPAA training, and document completion.
  4. Confirm that audit controls, access authentication, and encryption of ePHI in transit and at rest are implemented where reasonable and appropriate, consistent with the plan's risk analysis findings.
  5. Confirm business associate agreements are in place and current with all vendors handling plan PHI, and periodically request and document evidence of vendor security practices.
  6. Ensure an incident response plan is in place so that, if a breach occurs, the plan can meet Breach Notification Rule deadlines for notifying affected individuals and HHS.

Conclusion

This settlement reinforces that OCR treats ransomware incidents as an entry point for examining underlying Security Rule compliance, not merely the breach itself. Plan sponsors should treat the risk analysis requirement as a recurring compliance obligation rather than a one-time exercise, and should periodically confirm that both internal practices and vendor arrangements meet current HIPAA requirements. Additional OCR guidance and enforcement activity in this area is likely, and plan sponsors should monitor developments as they arise.

If you have any questions, please contact your HUB advisor. View more compliance articles in our Compliance Directory.

NOTICE OF DISCLAIMER
Neither Hub International Limited nor any of its affiliated companies is a law or accounting firm, and therefore they cannot provide legal or tax advice. The information herein is provided for general information only and is not intended to constitute legal or tax advice as to an organization’s or individual's specific circumstances. It is based on Hub International's understanding of the law as it exists on the date of this publication. Subsequent developments may result in this information becoming outdated or incorrect and Hub International does not have an obligation to update this information. You should consult an attorney, accountant, or other legal or tax professional regarding the application of the general information provided here to your organization’s specific situation in light of your or your organization’s particular needs.