Photo of Lydia Parker

Lydia is a partner in the Employee Benefits + Executive Compensation Practice Group. She assists clients with the design and implementation of employee benefits plans, and regularly advises clients on the wide variety of compliance issues that arise in the administration of those plans. Lydia has broad experience with both tax-qualified retirement plans, such as 401(k), 403(b) and defined benefit plans, and nonqualified plans. She has worked extensively with clients on compliance issues related to both self-insured and fully-insured health and welfare benefits plans, including group health plans, severance plans, life insurance plans, and disability plans. Her experience with health and welfare benefits plans includes advising on ACA, COBRA, HIPAA, ERISA, and Internal Revenue Code compliance. Lydia also assists clients with the benefits and compensation aspects of mergers and acquisitions, the negotiation of administrative services agreements and other vendor contracts, governance and fiduciary issues, and the administration of claims and appeals.

Key Points

  • OCR reached two 2026 settlements — totaling $695,000 — with self-funded group health plans following ransomware breaches, marking a notable expansion of direct HIPAA enforcement against self-funded health plans.
  • Both plans were cited for failing to conduct an accurate and thorough risk analysis to identify vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) stored on plan sponsor systems.
  • Self-funded group health plans are HIPAA-covered entities with independent compliance obligations that are separate from those of their plan sponsors, third-party administrators, and business associates.
  • Plan sponsors should conduct a plan-specific HIPAA risk analysis that explicitly evaluates ePHI data flows and any connections between the plan’s systems and the employer’s corporate IT environment.
  • OCR corrective action plans in both cases require comprehensive risk analyses, policy updates, workforce training, and periodic compliance reporting — requirements plan sponsors should proactively implement.