DOL Proposes New Electronic Delivery Safe Harbor for Group Health Plan DisclosuresA reminder that the July 23 proposed rule extending a notice-and-access electronic delivery safe harbor to ERISA group health plans is open for comment through September 21. The proposal mirrors the 2020 retirement-plan safe harbor but is website-only, with no direct email option, reflecting HIPAA privacy concerns, and it preserves unlimited free paper copies and a full opt-out for participants.
HIPAA for Self-Funded Plans and TPAs: The Covered Entity DistinctionA self-funded group health plan is generally a HIPAA covered entity, while the third-party administrator that processes its claims is a business associate. Constangy walks through what the distinction means for the compliance obligations on each side.
Clearing the Air: Tri-Agencies Issue Enforcement Relief on the Wellness Program “Full Reward” RequirementGroom situates the new tri-agency FAQ relief against the litigation wave that produced it: by the firm's count, the HIPAA wellness program rules have drawn more than 80 putative class actions claiming that premium surcharges for tobacco use violate ERISA. The relief addresses the midyear reward-timing and notice-disclosure questions; the broader surcharge fights, including the pending Sixth Circuit appeal in the Progressive case, remain in the courts.
FAQs About Affordable Care Act and HIPAA Implementation, Part 74Federal regulators will not enforce a rule requiring wellness program rewards to be paid retroactively to the start of the plan year when a participant meets a reasonable alternative standard midyear, as long as the plan pays the reward for the rest of the year. The guidance also confirms that the reasonable alternative standard notice is required only in materials that actually describe the program's terms, not in materials that merely mention it.
DentaQuest Breach Exposes Data of 15M People, a Record This YearA May cyberattack on DentaQuest, the dental and vision benefits administrator serving 32 million Americans, compromised the health data of at least 15 million individuals, the largest health data breach reported to federal regulators this year. Plan sponsors whose group plans use DentaQuest should be reviewing their business associate agreements and notification obligations.
DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber IncidentThe detailed accounting, published as notification letters began going out: names, Social Security numbers, member and Medicaid/Medicare identifiers, and dental and vision treatment and billing information, with independent analysis suggesting up to 23.4 million unique individuals, including 1.7 million Social Security numbers that appear to belong to children. Affected individuals are being offered 24 months of credit monitoring.
OCR Announces Notable HIPAA Enforcement Actions Against Self-Funded Group Health Plans Following Ransomware BreachesThe HHS Office for Civil Rights announced two separate HIPAA enforcement actions against self-funded group health plans following ransomware breaches, a signal that plan-level HIPAA compliance, not just the employer's, is squarely in OCR's sights.
First-Ever HIPAA Enforcement Against Self-Funded Health Plans: What Employers Need to KnowOn April 23, 2026, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced settlements with four health entities following investigations into ransomware breaches that exposed unsecured electronic protected health information (“ePHI”).