25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Survey Reveals HIPAA Compliance Issues with Group Health Plan Sponsors

Many group health plan sponsors are not fully compliant with the Health Insurance Portability and Accountability Act Rules, according to a recent survey by the integrated HR and benefits consulting, technology, and administration services firm, Buck.

The survey uncovered several areas where group health plan sponsors are noncompliant and revealed many group health plan sponsors are not prepared for a HIPAA compliance investigation or HIPAA audit.

The 2019 HIPAA Readiness Survey was conducted between April 29, 2019 and May 17, 2019 on 31 group health plan sponsors.

The survey uncovered several areas where important provisions of HIPAA Rules are not fully understood or are not being followed such as risk analyses, business associate agreements, HIPAA training for staff, and breach notifications.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Risk analyses are not being conducted as frequently as they should, so threats to the confidentiality, integrity and availability of ePHI may not be identified and managed. 42% of respondents were unsure when a HIPAA-compliant risk assessment was last conducted or that said it was last conducted more than 5 years ago. 10% said the last time a risk/threat analysis was conducted was more than 5 years ago.

Business associate agreements were another area where survey respondents highlighted potential HIPAA failures. 33% of respondents had not created an inventory of their business associates or were unaware whether an inventory had been created. 16% of respondents said they did not have current business associate agreements for certain vendors or were unaware if current BAAs had been obtained. 3% said they do not have current business associate agreements in place.

45% of respondents said privacy and security policies were updated in the past year, but 45% said they were updated between 1 and 5 years ago, and 3% said they had not been updated for at least 5 years.

Almost three quarters of respondents had prepared for breaches and had developed breach notification polices. 10% of respondents said they did not have policies in place covering breach notifications and 16% were unsure if they had policies covering breach notifications.

Refresher HIPAA training sessions are required to ensure employees are reminded of the importance of HIPAA compliance and understand their responsibilities under HIPAA. More than a third of respondents (35%) had last been offered HIPAA training between one and five years ago, with 13% admitting that HIPAA training was not ongoing and was only provided when onboarding staff. One in ten respondents said they did not know when training on HIPAA was last provided to employees.

Privacy and security policies and procedures must be implemented, but it is essential that those policies are followed by employees. To determine whether that is the case, operational reviews are required. These reviews show whether day-to-day working practices are HIPAA compliant. 23% of respondents said they had not conducted an operational review and 43% of respondents did not know if a review had been conducted.

In the event of a data breach, complaint, or audit, HIPAA failures are likely to be uncovered, which could easily result in a financial penalty for noncompliance. To avoid financial penalties, it is essential for group health plan sponsors to be fully aware of the requirements of HIPAA, have compliant policies and procedures in place, and to regularly assess their compliance efforts and ensure that, in the event of an audit, compliance can be demonstrated.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist