One of the most common misconceptions in employee benefits compliance is that HIPAA only applies to large employers. It’s easy to see why this assumption exists. Employers often associate HIPAA with large organizations, complex health plans, and extensive healthcare operations.
But employer size alone does not determine whether HIPAA applies. The better question is how the employer’s health plan is structured and administered.
HIPAA’s Privacy and Security Rules can apply to employer-sponsored group health plans, regardless of whether the employer has hundreds of employees or a much smaller workforce. Limited exceptions exist, including for certain group health plans with fewer than 50 participants that the plan sponsor self-administers. However, being a small employer does not, by itself, eliminate HIPAA obligations.
This is often where employers get caught off guard. An employer may have a relatively simple benefits program and assume HIPAA is someone else’s responsibility because its insurance carrier or third-party administrator handles claims and other health plan functions. While those vendors may handle much of the day-to-day administration, that does not automatically mean the employer has no HIPAA responsibilities.
Depending on how the plan operates, an employer sponsored health plan may need to maintain HIPAA privacy policies and procedures, provide a Notice of Privacy Practices when required, establish safeguards for protected health information (PHI), enter into applicable business associate agreements, address the circumstances under which PHI may be disclosed to the plan sponsor, maintain appropriate firewalls between the plan and the employer, and train workforce members who have access to PHI.
At the same time, simply offering health coverage does not mean an employer automatically has access to PHI. Some employers intentionally structure their plans so health information stays primarily with the carrier or third-party administrator. Others may be more involved, interacting with enrollment information, eligibility issues, claims questions, billing information, or other health information. These differences can affect the HIPAA analysis.
Instead of asking, “Are we too small for HIPAA?” employers should consider:
- How is our health plan structured?
- Who administers it?
- What health information do we receive?
- What role do we play in plan administration?
The misconception that small employers are automatically exempt from HIPAA can create unnecessary compliance risk. HIPAA is not simply a large-employer requirement. It is a health plan compliance issue. Understanding that distinction is an important first step toward identifying the requirements that may apply and putting the appropriate safeguards and procedures in place.




