Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Employer Health Plans: Taking Responsibility for Your Business Associates

By Virginia McGarrity on July 13, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

The Anthem and Premera Blue Cross data breaches caused widespread panic throughout the employer health plan community earlier this year. For many, these data breach announcements served as a wakeup call for employer health plan sponsors to review and further refine their business associate contracts.

As a health plan sponsor, the employer is responsible for its health plan’s compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). In carrying out its responsibilities under the plan, an employer may delegate some or all of those responsibilities to one or more business associates, but the employer remains ultimately responsible for the plan’s HIPAA compliance. A “business associate” is any party providing services to the health plan that receives, or may receive, protected health information (PHI) from the health plan. A health plan typically has multiple business associates, which can include insurers, administrative service providers, consultants and claim administrators. It is, therefore, important that employer health plan sponsors be able to identify the health plan’s business associates and to have on file copies of their service agreements and business associate contracts.

Although HIPAA mandates certain provisions be included in business associate contracts, it became clear in the aftermath of these data breaches that many service agreements and business associate contracts lacked transparency. Accordingly, employers may need to review their business associate contracts for necessary revisions to reflect the lessons learned from the Anthem and Premera Blue Cross data breaches, namely:

  • clarifying the responsibilities of the employer health plan sponsor, the health plan and the business associate in the event of a data breach under both HIPAA and any applicable state breach notification laws;
  • refining liability and indemnification provisions in the event of a breach; and
  • describing the obligations of the business associate with respect to personally identifiable information (versus only addressing personal health information).

The recent large-scale data breaches serve as a reminder that HIPAA imposes significant responsibilities on group health plans and employers may wish to consider using this as an opportunity to review underlying business associate contracts so that they are prepared if their group health plans become subject to such a breach.

Photo of Virginia McGarrity Virginia McGarrity

Virginia McGarrity is a member in the firm’s Employee Benefits + Compensation Group whose practice addresses a broad array of issues relating to the design, drafting, and operation of qualified and nonqualified defined benefit and defined contribution plans, including 401(k), profit-sharing, employee stock…

Virginia McGarrity is a member in the firm’s Employee Benefits + Compensation Group whose practice addresses a broad array of issues relating to the design, drafting, and operation of qualified and nonqualified defined benefit and defined contribution plans, including 401(k), profit-sharing, employee stock ownership and Section 403(b), and Section 457(b) plans of tax-exempt organizations and governmental entities. Virginia counsels clients on a wide range of health and welfare benefits matters, including issues related to health care reform, cafeteria plans, health savings accounts, voluntary employee beneficiary associations, and other employee benefits arrangements. She also assists clients with compliance matters involving federal laws such as COBRA and HIPAA, as well as various state laws and regulations governing health and welfare plan design and administration, domestic partner coverage, continuation of coverage, and mandated benefits. Read her full rc.com bio here.

Read more about Virginia McGarrityEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo