HIPAA Compliance Guide for Health Plans
Complete guide to HIPAA compliance for health plans, including covered entity obligations, enrollment data protection, and claims management requirements.
Quick Answer
Health plans are covered entities under HIPAA and must comply with all Privacy, Security, and Breach Notification Rules. This includes protecting member enrollments, medical underwriting data, eligibility information, and claims processing data. Health plans must implement technical safeguards, maintain audit logs, secure EDI transactions, and manage business associates who handle plan data.
Health Plan Covered Entity Status
Covered Entity Obligations
- Develop and implement written Privacy Rule policies and procedures
- Develop and implement written Security Rule technical safeguards
- Develop and implement written Breach Notification procedures
- Appoint a Privacy Officer responsible for policy development
- Appoint a Security Officer responsible for security implementation
- Conduct annual HIPAA compliance training for all workforce members
- Maintain documentation of all policies, procedures, and training
- Implement a complaints and resolution process for HIPAA violations
- Conduct HIPAA risk analysis at least biennially
- Maintain minimum 6-year retention of HIPAA-related records
Member Enrollment Data Protection
Enrollment Information Security
- Encryption for all enrollment applications and submission
- Secure collection of enrollment data (paper, online, phone)
- Protection of Social Security numbers in enrollment records
- Limited access to enrollment data by authorized staff only
- Audit logging of all enrollment data access and modifications
- Secure storage of completed enrollment applications
- Destruction procedures for rejected or cancelled applications
- Transmit enrollment data to payroll/employer with encryption
- Prevent unauthorized access to family member information
Medical Underwriting Data
- Medical information collected only when permitted by HIPAA
- Informed consent obtained before using medical history
- Limited underwriting questions on enrollment forms
- Secure handling of medical records from healthcare providers
- Restricted access to underwriting data (underwriters and medical directors)
- Documented underwriting decisions with evidence
- Securely destroy medical records when underwriting complete (if applicable)
- Confidentiality agreements with external underwriting vendors
- State-required waiting periods for pre-existing conditions applied
Eligibility Inquiry Requirements
Claims Adjudication Compliance
Claims Processing Rules Compliance
- Apply plan benefits according to current plan language
- Apply state insurance regulations correctly in benefit calculations
- Calculate copayments, coinsurance, and deductibles per plan design
- Apply accumulation limits (maximum out-of-pocket, deductibles)
- Process pre-authorization requirements before claim adjudication
- Network vs. out-of-network benefit application correctly
- Apply bundling or global surgery rules when applicable
- Manage concurrent treatment limitations and restrictions
- Apply member cost-sharing obligations correctly
- Document medical policy applications in claims
Claims Accuracy Assurance
- Monthly claims accuracy audit of sample (minimum 100+ claims)
- Documented corrective action for claims with errors
- Verification of provider credentials before claim payment
- Identification of duplicate claims using claim history
- Detection of unbundled procedures incorrectly processed
- Medical necessity review for high-cost or unusual claims
- Fraud indicators monitoring (duplicate billing, high-frequency claims)
- Appeals tracking to identify systemic adjudication issues
- Monthly reporting to management on claims error rates
Claims Data Retention and Destruction
Data Retention Requirements
- Maintain claims data minimum 6 years for HIPAA compliance
- Maintain claims data per state insurance regulations (often 7+ years)
- Retain supporting documentation (medical records, explanations)
- Maintain audit logs related to claims for 6 years minimum
- Archive aged claims to secure secondary storage with encryption
- Maintain claims dispute and appeal documentation
- Preserve claims data during litigation (legal holds)
- Document retention schedule and destruction procedures
- Implement automated retention enforced by systems
Data Destruction Procedures
- Secure deletion procedures for claims data past retention period
- Cryptographic erasure for encrypted claims archives
- Physical destruction for paper claims and records
- Certified destruction of backup tapes with claims data
- Destruction of claims data in vendor systems per BAA
- Documented destruction with certificates of destruction
- Verification that backups do not contain destroyed data
- Testing of destruction procedures annually
Member Privacy and Consent
Member Rights Fulfillment
- Provide access to medical records upon member request within 30 days
- Allow member amendment of medical records per procedures
- Provide accounting of disclosures for members upon request
- Respond to member privacy complaints within 30 days
- Allow member designation of emergency contacts
- Honor member requests for communication confidentiality
- Implement restrictions requested by members on data usage
- Provide member privacy rights information upon request
Business Associate Management
Business Associate Agreements
- Execute signed BAA with every vendor handling plan member data
- BAAs must include HIPAA-compliant terms and conditions
- Specify security requirements and safeguards vendors must maintain
- Define incident notification procedures and timelines
- Include audit rights to verify vendor compliance
- Require workforce security training programs
- Mandate encryption for data at rest and in transit
- Define subcontractor requirements and monitoring
- Establish data destruction procedures upon service termination
- Review and update BAAs annually
Vendor Compliance Monitoring
- Annual security assessment questionnaires from all vendors
- Documentation of vendor incident history and breaches
- SOC 2 Type II or other audit results review
- Verification of vendor insurance and cyber coverage
- Testing of vendor incident response procedures
- Audit of vendor handling of sensitive plan data
- Monitoring of vendor subcontractor compliance
- Verification of vendor employee background checks
- Documentation of all vendor monitoring activities
Reporting and Compliance Documentation
Required Documentation
- Documented Privacy Rule policies and procedures
- Documented Security Rule technical safeguards implementation
- Breach Notification Rule procedures documentation
- Risk analysis reports from biennial compliance assessments
- Evidence of Privacy Officer and Security Officer appointment
- Annual HIPAA compliance training rosters and completion certificates
- Business Associate Agreements with all vendors
- Minutes from privacy and security governance meetings
- Incident investigation documentation and closure reports
- Vendor security assessment results and corrective actions
Regulatory Reporting
- Breach notification to affected members (if >500 members, media notice required)
- Breach notification to HHS Office for Civil Rights
- State insurance commissioner notification as required
- Member notification within 60 days of breach discovery
- Documentation of notification efforts and results
- Response to regulatory inquiries and audits
- Annual reporting to state insurance regulators if required