Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

HIPAA Refresher for Workplace Wellness Programs

By Virginia McGarrity on April 26, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

Now more than ever, workplace wellness programs are becoming increasingly popular among employers. A common concern many employers have is how to design a meaningful workplace program intended to improve the health of participating employees while complying with HIPAA’s privacy and security rules. Although employers are not covered entities, HIPAA may apply to an employer’s workplace program if it is part of the group health plan. In a blog post last year, OCR Director Jocelyn Samuels sought to further explain how employers can use health data collected for wellness program purposes and what measures are necessary to protect health information under HIPAA.

The blog described several key points on how wellness information must be protected under HIPAA:

  • Employers are not permitted to use or disclose health data for employment-related actions or anything not specifically allowed by HIPAA (e.g., marketing).
  • The employer, on behalf of the group health plan, must establish firewalls or other security measures to ensure the data cannot be accessed for employment functions (e.g., employers or manages using health data to make job decisions).
  • Should collected health data be accidentally or deliberately disclosed to an unauthorized third party, or otherwise accessed by an unauthorized individual, the group health plan has a responsibility to notify HHS and all persons who had their data exposed or disclosed in accordance with the HIPAA Breach Notification Rule.

The penalties for failing to comply can include investigations into potential violations, corrective action, and civil penalties of more than $50,000 for each HIPAA violation. Those penalties can increase to a maximum of $1.5 million per calendar year for multiple violations of the same provision.

Photo of Virginia McGarrity Virginia McGarrity

Virginia McGarrity is a member in the firm’s Employee Benefits + Compensation Group whose practice addresses a broad array of issues relating to the design, drafting, and operation of qualified and nonqualified defined benefit and defined contribution plans, including 401(k), profit-sharing, employee stock…

Virginia McGarrity is a member in the firm’s Employee Benefits + Compensation Group whose practice addresses a broad array of issues relating to the design, drafting, and operation of qualified and nonqualified defined benefit and defined contribution plans, including 401(k), profit-sharing, employee stock ownership and Section 403(b), and Section 457(b) plans of tax-exempt organizations and governmental entities. Virginia counsels clients on a wide range of health and welfare benefits matters, including issues related to health care reform, cafeteria plans, health savings accounts, voluntary employee beneficiary associations, and other employee benefits arrangements. She also assists clients with compliance matters involving federal laws such as COBRA and HIPAA, as well as various state laws and regulations governing health and welfare plan design and administration, domestic partner coverage, continuation of coverage, and mandated benefits. Read her full rc.com bio here.

Read more about Virginia McGarrityEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo