BENEFITS DIGEST

Primary sources. Practical insight. Every weekday.

A publication of The Inner Firm

HIPAA & Health Data Privacy

8 item(s) · sort: newest first · title A–Z

DOL Proposes New Electronic Delivery Safe Harbor for Group Health Plan Disclosures
McDermott Will & Schulte · via JD Supra 2026-09-02 · issue № 45

A reminder that the July 23 proposed rule extending a notice-and-access electronic delivery safe harbor to ERISA group health plans is open for comment through September 21. The proposal mirrors the 2020 retirement-plan safe harbor but is website-only, with no direct email option, reflecting HIPAA privacy concerns, and it preserves unlimited free paper copies and a full opt-out for participants.

HIPAA for Self-Funded Plans and TPAs: The Covered Entity Distinction
Constangy, Brooks, Smith & Prophete, LLP · via JD Supra 2026-09-01 · issue № 43

A self-funded group health plan is generally a HIPAA covered entity, while the third-party administrator that processes its claims is a business associate. Constangy walks through what the distinction means for the compliance obligations on each side.

Clearing the Air: Tri-Agencies Issue Enforcement Relief on the Wellness Program “Full Reward” Requirement
Groom Law Group 2026-08-27 · issue № 41

Groom situates the new tri-agency FAQ relief against the litigation wave that produced it: by the firm's count, the HIPAA wellness program rules have drawn more than 80 putative class actions claiming that premium surcharges for tobacco use violate ERISA. The relief addresses the midyear reward-timing and notice-disclosure questions; the broader surcharge fights, including the pending Sixth Circuit appeal in the Progressive case, remain in the courts.

FAQs About Affordable Care Act and HIPAA Implementation, Part 74
DOL, HHS & Treasury 2026-08-26 · issue № 40

Federal regulators will not enforce a rule requiring wellness program rewards to be paid retroactively to the start of the plan year when a participant meets a reasonable alternative standard midyear, as long as the plan pays the reward for the rest of the year. The guidance also confirms that the reasonable alternative standard notice is required only in materials that actually describe the program's terms, not in materials that merely mention it.

DentaQuest Breach Exposes Data of 15M People, a Record This Year
Healthcare Dive 2026-08-11 · issue № 30

A May cyberattack on DentaQuest, the dental and vision benefits administrator serving 32 million Americans, compromised the health data of at least 15 million individuals, the largest health data breach reported to federal regulators this year. Plan sponsors whose group plans use DentaQuest should be reviewing their business associate agreements and notification obligations.

DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident
HIPAA Journal 2026-07-23 · issue № 30

The detailed accounting, published as notification letters began going out: names, Social Security numbers, member and Medicaid/Medicare identifiers, and dental and vision treatment and billing information, with independent analysis suggesting up to 23.4 million unique individuals, including 1.7 million Social Security numbers that appear to belong to children. Affected individuals are being offered 24 months of credit monitoring.

← All topics