Photo of Laura Ferguson

Laura counsels clients ranging from multinational banks to energy companies on a wide variety of employee benefits, executive compensation, and privacy and cybersecurity matters.

Key Points

  • OCR reached two 2026 settlements — totaling $695,000 — with self-funded group health plans following ransomware breaches, marking a notable expansion of direct HIPAA enforcement against self-funded health plans.
  • Both plans were cited for failing to conduct an accurate and thorough risk analysis to identify vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) stored on plan sponsor systems.
  • Self-funded group health plans are HIPAA-covered entities with independent compliance obligations that are separate from those of their plan sponsors, third-party administrators, and business associates.
  • Plan sponsors should conduct a plan-specific HIPAA risk analysis that explicitly evaluates ePHI data flows and any connections between the plan’s systems and the employer’s corporate IT environment.
  • OCR corrective action plans in both cases require comprehensive risk analyses, policy updates, workforce training, and periodic compliance reporting — requirements plan sponsors should proactively implement.