Skip Navigation
Better Together | Risk Strategies to Join Brown & Brown  Learn More
  • Careers
  • Report a Claim
  • Contact Us
Risk Strategies Logo
  • Industries

    • Agriculture
    • Architects & Engineers
    • Aviation
    • Cannabis
    • Construction
    • Dental
    • Education
    • Entertainment
    • Financial Services
    • Fine Art
    • Healthcare
    • Law Firms
    • Marine & Yacht
    • Nonprofit & Human Services
    • Private Equity
    • Public Sector
    • Real Estate
    • Relocation
    • Transportation
    • Waste & Recycling
    • Wineries
  • Solutions

      • Captives
      • Casualty
      • Cyber
      • Environmental
      • International
      • Executive Risk Solutions
      • Property
      • Surety
      • Employee Benefits Overview
      • Benefit Administration and Technology
      • Benefits Compliance Support
      • Data & Analytics
      • Human Capital Advisory Services
      • International Benefits
      • Absence Management & Ancillary Programs
      • Voluntary & Lifestyle Benefits
      • Medicare
      • Financial & Wealth Overview
      • Retirement Plan Services
      • Executive Benefits
      • Life Insurance
      • Private Client Services Overview
      • Homeowners
      • Flood
      • Collections
      • Umbrella & Excess Liability
      • Auto
      • Collector & Exotic Car
      • Boat & Yacht
      • Travel Medical & Trip Insurance
      • Family Office
      • Cyber Insurance - Family Office
      • Cyber Insurance - Individuals
      • Specialty Coverages
      • Private Client Risk Resource Center
    • Reinsurance
      • Risk Management Services Overview
      • Analytics
      • Claims Management & Advocacy
      • Loss Control
      • Safety Consulting Services
      • Pro Safety Training Courses
      • Workers’ Comp: Premium Review & Recovery
  • Consulting

    • Consulting Overview
    • Actuarial Services
    • Healthcare Claim Audit Services
    • Health and Welfare
    • Mergers and Acquisitions
    • Pharmacy Consulting
    • Retirement Benefits
  • News and Insights

    • All Insights
    • Blog
    • Emergency Resource Centers
    • Employee Benefits Compliance Center
    • Events
    • Media Coverage
    • State of the Market Reports
    • Press Releases
    • Private Client Resources
    • Webinars
  • Company

    • About Us
    • Annual Report
    • Careers
    • Culture and Values
    • Diversity, Equity & Inclusion
    • Environmental, Social, & Governance
    • General Terms of Business
    • Leaders
    • Local Expertise
    • Mergers & Acquisitions
    • Recognition & Awards
    • Risk Strategies Foundation
    • Transparency and Disclosures
  • Join Us
    • Careers
    • Mergers & Acquisitions
  • Industries
    • Agriculture
    • Architects & Engineers
    • Aviation
      • Aviation Business Insurance - Manned Risk
      • Non-Owned Aviation
      • Unmanned Aerial System and Drones
    • Cannabis
    • Construction
      • Alternative Solutions
      • Financing & Pre-Construction
      • Insurance Solutions
      • Risk Management
      • Surety
    • Dental
      • Insurance for Dental Professionals
      • Dental Malpractice Insurance
      • BOP Insurance - Dental Practices & DSOs
      • Dental School Graduates
      • Dental Associates & Hygienists
      • Dental Practice Owners
      • Dental Service Organizations (DSOs)
    • Education
      • Employee Benefits for Education
      • Property, Casualty & Liability for Education
      • Student Health & Wellness
        • Student Health Brokerage and Consulting
        • Student Health Plan Administration
        • Student Health Insurance Plans
        • Solutions for Student Athletes
        • Student Health & Wellness Tools
        • Special Risk Insurance
    • Entertainment
      • Film & Television
      • Advertising Production Wrap Ups
      • Advertising/PR
      • Event Cancellation & Non-Appearance
      • Music & Touring
      • Theatrical Production & Live Performance 
      • Venue Insurance
    • Financial Services
      • Asset Managers
      • Banks & Non-Bank Lending
      • Collections
      • Consumer Financial Services
      • Financial Tech
      • Insurance Companies
    • Fine Art
      • Dealers and Auction Houses
        • Galleries
        • Private Art Dealers
      • Collections
        • Private Collectors
        • Coins, Paper Money & Numismatics Collections
        • Gold, Bullion & Precious Metal Collections
      • Artists
      • Museums and Foundations
        • Museums
      • Fine Art Packers / Shippers / Warehouses
    • Healthcare
      • Employee Benefits - Healthcare
      • Managed Care / Stop Loss
      • Medical Malpractice
      • Property & Casualty - Healthcare
      • Reinsurance
    • Law Firms
    • Marine & Yacht
      • Yacht Insurance For Individuals
        • Mega Yachts
        • Cruiser Insurance - Jackline
        • One-Design Insurance Program
        • Sailors Health Insurance Program
        • US Sailing Insurance Solutions
      • Commercial Marine Insurance
        • Aquaculture
        • Cargo & Transit Insurance Solutions
        • Crew Medical Insurance
        • Hull & Machinery
        • Marine Claims Service
        • Marine Construction
        • Marine Liability
        • Ports & Terminals
        • Protection & Indemnity
        • Recreational Marine Businesses
        • Sailing Organizations – Burgee Program
    • Nonprofit & Human Services
    • Private Equity
      • Crypto Companies
    • Public Sector
      • Public Safety Organizations & Municipalities
    • Real Estate
      • Commercial
      • Community Associations
      • Hospitality
      • Residential / Habitational
      • REITs
      • Retail
      • Specialty Programs
    • Relocation
      • Domestic Household Goods
      • Expat Renters & Living Insurance
      • Relocation Claims Service
      • International Household Goods
      • Supplemental Movers Coverage
      • Temporary Living Insurance
      • Vacant Home
    • Transportation
      • Business Auto Insurance
      • Last Mile Delivery
      • While Under Dispatch Insurance
      • Forwarding & Brokering
      • Workers' Compensation
    • Waste & Recycling
    • Wineries
  • Solutions
    • Commercial Insurance
      • Captives
      • Casualty
        • Analytics
        • Auto Liability & Physical Damage
        • Captives & Alternative Risk Financing
        • Claims Advocacy & Loss Control
        • Excess Liability
        • General Liability
        • Product Recall
        • Workers' Compensation
      • Cyber
        • Cyber Resolute
        • Cyber Risk Assessment and Analytics
        • Cyber Risk Response & Claims Advocacy
        • Cyber Insurance - Family Office
        • Cyber Insurance - Individuals
      • Environmental
        • Contractors Pollution Liability
        • Environmental Excess
        • Environmental Liability Transfer
        • Environmental Liability - Healthcare
        • Environmental Liability - Higher Education
        • Pollution Legal Liability
        • Environmental Liability - Private Equity
        • Professional Environmental Liability Insurance
        • Real Estate Development
        • Remediation Cost Cap
        • Secured Creditor Protection for Lenders
        • Underground Storage Tanks
      • International
      • Executive Risk Solutions
        • Executive Risk Solutions - Entertainment
        • Executive Risk Solutions - Financial Institutions
        • Executive Risk Solutions - Healthcare
        • Executive Risk Solutions - Real Estate
      • Property
        • Builder's Risk
        • Property Claims Services
        • Inland Transit and Ocean Cargo
        • Natural Hazard Catastrophe Modeling
        • Political Violence and Terrorism
        • Property Damage & Business Interruptions Valuations
        • Property Loss Prevention and Control
      • Surety
    • Employee Benefits
      • Employee Benefits Overview
      • Benefit Administration and Technology
      • Benefits Compliance Support
      • Data & Analytics
      • Human Capital Advisory Services
      • International Benefits
      • Absence Management & Ancillary Programs
      • Voluntary & Lifestyle Benefits
      • Medicare
    • Financial & Wealth
      • Financial & Wealth Overview
      • Retirement Plan Services
      • Executive Benefits
      • Life Insurance
    • Private Client Services
      • Private Client Services Overview
      • Homeowners
      • Flood
      • Collections
      • Umbrella & Excess Liability
      • Auto
      • Collector & Exotic Car
      • Boat & Yacht
      • Travel Medical & Trip Insurance
      • Family Office
      • Cyber Insurance - Family Office
      • Cyber Insurance - Individuals
      • Specialty Coverages
      • Private Client Risk Resource Center
    • Reinsurance
    • Risk Management Services
      • Risk Management Services Overview
      • Analytics
      • Claims Management & Advocacy
      • Loss Control
      • Safety Consulting Services
      • Pro Safety Training Courses
      • Workers’ Comp: Premium Review & Recovery
  • Consulting
    • Consulting Overview
    • Actuarial Services
    • Healthcare Claim Audit Services
    • Health and Welfare
    • Mergers and Acquisitions
    • Pharmacy Consulting
    • Retirement Benefits
  • News and Insights
    • All Insights
    • Blog
    • Emergency Resource Centers
      • Cybersecurity
      • Earthquake
      • Hurricane
      • Pandemic
      • Riot & Civil Unrest
      • Severe Storms
      • Violence & Active Shooter
      • Wildfire
      • Winter Weather
    • Employee Benefits Compliance Center
    • Events
    • Media Coverage
    • State of the Market Reports
    • Press Releases
    • Private Client Resources
    • Webinars
  • Company
    • About Us
    • Annual Report
    • Careers
    • Culture and Values
    • Diversity, Equity & Inclusion
      • BeHEARD Series
      • DE&I Structure
      • Employee Resource Groups
    • Environmental, Social, & Governance
    • General Terms of Business
    • Leaders
    • Local Expertise
    • Mergers & Acquisitions
    • Recognition & Awards
    • Risk Strategies Foundation
    • Transparency and Disclosures
      • General Terms of Business
      • Conflict of Interest Policy
      • Compensation Disclosure
      • Enterprise Risk Management
  • Join Us
    • Careers
      • Benefits & Wellness
      • Investing in Growth & Leadership
      • Life at Risk Strategies
      • Next Steps
    • Mergers & Acquisitions
      • Partnership Benefits
      • Why Join Us?
      • Onboarding & Integration
  • Careers
  • Report a Claim
  • Contact Us

You are about to leave Risk Strategies website and view the content of an external website.

You are leaving risk-strategies.com

By accessing this link, you will be leaving Risk Strategies website and entering a website hosted by another party. Please be advised that you will no longer be subject to, or under the protection of, the privacy and security policies of Risk Strategies website. We encourage you to read and evaluate the privacy and security policies of the site you are entering, which may be different than those of Risk Strategies.

OK
  • News and Insights
  • Blog
Subscribe

Subscribe via Email

  • News and Insights
  • Blog
May 10, 2024

HIPAA Final Rule Strengthening Reproductive Health Care Privacy

Employee Benefits
5 min read
Erica Honig, J.D., Senior Compliance Director, Employee Benefits
  • Facebook
  • X (Twitter)
  • LinkedIn
  • Email
HIPAA Final Rule Strengthening Reproductive Health Care Privacy
  • Facebook
  • X (Twitter)
  • LinkedIn
  • Email

Summary: On April 26, 2024, the Department of Health and Human Services (HHS) issued an update to the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. The final rule, originally released as a proposed rule in 2023 after the U.S. Supreme Court decision in Dobbs v. Jackson Women’s Health Organization, addresses the use and disclosure of protected health information (PHI) for reproductive health data. While this final rule is effective June 25, 2024, the compliance deadlines for the provisions of the rule are later in 2024 and beyond.

Self-funded group health plans will be impacted by this final rule and required to take certain compliance actions by the deadlines detailed below. Read on for more information.

HIPAA Privacy Rule Background

HHS adopted the HIPAA Privacy Rule in 2000, establishing national standards to protect individuals’ medical records and other personal health information. The HIPAA Privacy Rule imposes strict limits on the use, disclosure, and protection of PHI by regulated entities, meaning health care providers, health plans, health care clearinghouses, and their business associates.

The HIPAA Privacy Rule:

  • Imposes limits and conditions on the uses and disclosures of PHI that can be made without an individual’s authorization;
  • Provides individuals with rights over their PHI, including the right to receive a notice from covered entities about their privacy practices; and
  • Requires appropriate safeguards to protect the privacy of PHI.

The Privacy Rule applies to both self-funded and fully insured group health plans. However, employers that sponsor fully insured plans and do not have access to PHI (other than certain limited types) from their insurance carriers generally have much lighter compliance requirements under the Privacy Rule than self-funded plans.

Final Rule

The final rule arrives after a proposed rule was released in April 2023. Furthermore, in the wake of the Dobbs decision (click here for our previous alert) overturning Roe v. Wade, HHS issued guidance reminding regulated entities that reproductive health care information is protected under HIPAA.

This final rule adds a new category of prohibited uses and disclosures of PHI, prohibiting the use or disclosure of PHI by a regulated entity from the following:

  • Conducting a criminal, civil, or administrative investigation into or imposing liability on any person for merely seeking, obtaining, providing, or facilitating reproductive healthcare where it is lawful.
  • Identifying any person for the purpose of conducting such investigation or imposing liability.

The prohibition applies where a regulated entity reasonably determined that one or more of the following conditions exist, as stated in an HHS fact sheet:

  • The reproductive health care is lawful under the law of the state in which such health care is provided under the circumstances in which it is provided.

    Example: If a resident of one state traveled to another state to receive reproductive health care, such as an abortion, which is lawful in the state where such health care was provided.

  • The reproductive health care is protected, required, or authorized by Federal law, including the U.S. Constitution, regardless of the state in which such health care is provided.

    Example: If use of the reproductive health care, such as contraception, is protected by the Constitution.

Additionally, when a regulated entity did not provide the reproductive health care at issue, the final rule prohibits the use or disclosure of PHI when the person making the request does not provide sufficient information to overcome a presumption of legality. This presumption may be overcome if the person making the request provides information showing a substantial factual basis that the reproductive health care was unlawful under the circumstances in which it was provided.

Example: A law enforcement official provides a health plan with evidence that the information being requested is reproductive health care that was provided by an unlicensed person where the law requires that such health care be provided by a licensed health care provider.

New Attestation Requirement

The final rule includes a new attestation requirement. When a regulated entity receives a request for PHI that might relate to reproductive healthcare, a signed attestation must be obtained confirming that the PHI request is not for a prohibited purpose. This attestation requirement applies when the request is for PHI for any of the following:

  • Health oversight activities
  • Judicial and administrative proceedings
  • Law enforcement purposes
  • Disclosures to coroners and medical examiners

Regulated entities must comply with the new attestation requirement by December 23, 2024. HHS published a HIPAA model attestation form for covered entities and business associates to use for compliance purposes. Click here for this model attestation form.

Updated Notice of Privacy Practices

The Privacy Rule generally requires that a covered entity provide individuals with a Notice of Privacy Practices (NPP) to ensure that they understand how a covered entity may use and disclose their PHI, as well as their rights and the covered entity’s legal duties with respect to PHI.[1]

The final rule requires covered entities to inform individuals that their PHI may not be used or disclosed for a purpose prohibited under this final rule by updating their NPPs by February 16, 2026. Moreover, covered entities that handle certain substance use disorder (SUD) patient records must update their NPPs to detail new privacy protections for these records.

HHS intends to publish model NPP language for this purpose.

Next Steps for Self-Funded Plans

While the requirements of the final rule will primarily impact health care providers, self-funded group health plans are subject to certain provisions as covered entities under HIPAA.

Self-funded group health plans are advised to begin complying with this final rule by taking the following steps in conjunction with their own counsel and HIPAA compliance partners:

  1. Updating HIPAA Privacy Rule policies and procedures, as necessary
    • This includes incorporating the requisite attestation form into these policies and procedures to use when the plan receives requests potentially related to reproductive health care (Click here for the HHS model attestation form).
  2. Updating business associate agreements (BAAs), as necessary
  3. Conducting HIPAA training for workforce members
  4. Updating and distributing NPPs when HHS publishes model language for this purpose by February 16, 2026

Risk Strategies will provide updates when available, including when HHS publishes model language for updated NPPs.

In the meantime, contact us directly with any questions at benefits@risk-strategies.com.

 


[1] 4 45 CFR 164.520.

The contents of this article are for general informational purposes only and Risk Strategies Company makes no representation or warranty of any kind, express or implied, regarding the accuracy or completeness of any information contained herein. Any recommendations contained herein are intended to provide insight based on currently available information for consideration and should be vetted against applicable legal and business needs before application to a specific client. 

Related Posts

See all posts

Employee Benefits
11 min read
June 10, 2025

FMLA & Group Health Benefits Continuation: What Employers Need to Know

Summary: When an employee takes a leave of absence under the federal Family Medical Leave Act …
Read article
Employee Benefits
13 min read
May 29, 2025

House Tax & Spending Bill: Noteworthy Employee Benefit Changes

On May 22, 2025, the United States House of Representatives narrowly passed sweeping tax and …
Read article
Employee Benefits
2 min read
May 20, 2025

Missouri Paid Sick Leave Repealed: What Employers Need to Know

As we previously reported here, the Missouri paid sick leave (MO PSL) law requirements went into …
Read article
Risk Strategies Logo
  • Report a Claim
  • Contact
  • Terms of Use
  • Cookie Policy
  • Privacy Policy
  • Consumer Health Data Privacy Notice
  • Accessibility
  • Health Plan Transparency Compliance
  • Accessibility
  • Cookie Policy
  • Health Plan Transparency Disclosure
  • Privacy Policy
  • Terms of Use
©2025 Risk Strategies. All rights reserved.

Connect with Us

  • LinkedIn
  • X
  • Instagram
  • Facebook