We're sorry, but OSHAcademy doesn't work properly without JavaScript enabled. Please turn on JavaScript or install a browser that supports Javascript.

625 HIPAA Privacy Training
Skip to main content

Health Plans

Health plans also include employer-sponsored group health plans, government and church-sponsored health plans, and multi-employer health plans. There are exceptions. For instance, a group health plan with fewer than 50 participants, which is solely administered by the employer that established and maintains the plan, is not considered a covered entity.

A person filling forms for a health plan with a calculator on the desk top.
Most health plans are considered covered entities.

Two types of government-funded programs are not considered health plans:

  1. Programs primarily not focused on providing or funding health care, like the food stamps program.
  2. Programs mainly engaged in direct health care provision, such as community health centers, or those granting funds for direct health care.

Some insurance providers, such as those offering only workers' compensation, automobile insurance, or property and casualty insurance, aren't considered health plans.

Privacy vs. Security

Privacy and security are closely linked:

  • Privacy concerns the "what" – it ensures that patients' health information is protected from unauthorized access.
  • Security addresses the "how" – it outlines the measures taken by agencies to safeguard this information.

The Department of Health and Human Services (HHS) states that most Security Rule violations arise because covered entities lack sufficient policies and procedures to protect personal information on their systems.

Knowledge Check Choose the best answer for the question.

1-5. Keeping healthcare information from unauthorized disclosures is an example of what type of protection?