insurance essentials

Why HIPAA Doesn't Govern Fully Insured Workers' Compensation Plans

By 3 min read 113 views
Featured image for Why HIPAA Doesn't Govern Fully Insured Workers' Compensation Plans

HIPAA's privacy and security rules protect individually identifiable health information handled by covered entities—healthcare providers, health plans, and their business associates. Fully insured workers' compensation plans are insurance products sold by commercial carriers, not health‑care providers or health‑plan sponsors, so they fall outside HIPAA's definition of a covered entity. Consequently, the federal privacy safeguards that apply to medical records in a hospital or a health‑maintenance organization do not automatically extend to the claims data or medical records maintained by a workers' compensation insurer.

More from this site

Keep reading the latest coverage

Browse latest →

Regulatory framework that does apply

Workers' compensation data are instead governed by a patchwork of state statutes, the Fair Credit Reporting Act (FCRA) for background checks, and, where applicable, the General Data Protection Regulation (GDPR) for cross‑border employees. Most states require insurers to keep claim information confidential, but the standards differ widely—some mirror HIPAA‑like protections, others rely on broader privacy principles. In addition, the Employee Retirement Income Security Act (ERISA) may impose fiduciary duties on self‑insured employers, but it does not create a federal privacy rule comparable to HIPAA for fully insured carriers.

Practical implications for employers and insurers

Because HIPAA does not apply, employers cannot cite HIPAA compliance as a shield when a claim‑related data breach occurs. They must instead rely on state‑specific breach‑notification laws and contractual obligations in their insurance policies. Insurers, meanwhile, often adopt HIPAA‑style safeguards voluntarily to reassure clients and to align with industry best practices, but those measures are not mandated by federal law.

Key differences in data handling requirements

AspectHIPAA‑covered entitiesFully insured workers' comp plans
Applicable law45 CFR Part 164 (Privacy & Security Rules)State workers' comp statutes & other federal laws (e.g., FCRA)
Breach notification45 CFR 164.404 – 60‑day notification to individuals & HHSState‑specific breach‑notification timelines, often 30‑45 days
Minimum safeguardsAdministrative, physical, technical safeguards defined by HIPAAVaries by state; many insurers adopt similar safeguards voluntarily
EnforcementOCR civil penalties up to $1.5 million per violationState insurance regulators; penalties differ by jurisdiction

When HIPAA might still be relevant

If a workers' compensation claim is processed through a health‑plan sponsor—such as an employer‑provided health insurer that also administers the claim—HIPAA could apply to the portion of the record handled by that sponsor. In those hybrid situations, the data flow must be mapped to determine which entity is the covered entity for each segment of the information.

Best‑practice checklist for compliance

  • Identify the legal jurisdiction(s) governing each claim.
  • Confirm whether any third‑party service provider is a HIPAA‑covered entity.
  • Implement state‑required breach‑notification procedures.
  • Adopt HIPAA‑style safeguards voluntarily to reduce risk.
  • Document contractual privacy clauses with insurers and vendors.

Editor's pick

Keep exploring our latest stories

Fresh reads, picked daily.

Browse latest
Share: