Photo of Emily D. Zimmer

Emily counsels clients on a wide range of employee benefit and executive compensation issues, including issues related to corporate mergers and acquisitions. She routinely advises on the design, implementation, and administration of qualified and non-qualified retirement plans and welfare benefit programs, including wellness programs, health care accounts such as HRAs, Health FSAs, and HSAs, adoption reimbursement programs, and educational assistance programs.

Key Points

  • OCR reached two 2026 settlements — totaling $695,000 — with self-funded group health plans following ransomware breaches, marking a notable expansion of direct HIPAA enforcement against self-funded health plans.
  • Both plans were cited for failing to conduct an accurate and thorough risk analysis to identify vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) stored on plan sponsor systems.
  • Self-funded group health plans are HIPAA-covered entities with independent compliance obligations that are separate from those of their plan sponsors, third-party administrators, and business associates.
  • Plan sponsors should conduct a plan-specific HIPAA risk analysis that explicitly evaluates ePHI data flows and any connections between the plan’s systems and the employer’s corporate IT environment.
  • OCR corrective action plans in both cases require comprehensive risk analyses, policy updates, workforce training, and periodic compliance reporting — requirements plan sponsors should proactively implement.