Employee Benefits

Q4 Considerations: New HIPAA Privacy Considerations

November 15, 2024

Insights banner

Earlier this year, the Department of Health and Human Services (HHS) issued a Final Rule titled HIPAA Privacy Rule to Support Reproductive Health Care Privacy. The HHS guidance  directs HIPAA-covered entities, such as an employer sponsored health plan or its business associate, that if they receive a request for protected health information (PHI) that is  potentially related to reproductive healthcare, it must obtain a signed attestation from the requesting party that clearly states that the requested use or disclosure of PHI is not for any of the following prohibited purposes: 

1. To conduct a criminal, civil or administrative investigation into any person for the mere act of seeking, obtaining, providing or facilitating lawful reproductive healthcare;

2. To impose criminal, civil or administrative liability on any person for the mere act of seeking, obtaining, providing or facilitating lawful reproductive healthcare; 

3. To identify any person for any purpose described in 1 or 2.

Plan sponsors and their health plans also need to revise their Notice of Privacy Practices (NPP) provided to plan participants to make sure the NPP supports reproductive healthcare privacy, in addition to updating their Business Associate Agreements (BAAs) to reflect these new protections. Read more about the new rules here: https://aleragroup.com/insights/legal-alert-hipaa-privacy-rules-amended-require-protection-reproductive-healthcare.

    Alera Group, Inc. is aware that there are persons fraudulently impersonating our company by using fake internet domains that appear to look like our legitimate services. If you are contacted by someone claiming to work for Alera Group, or any of our partners, please carefully review the email address and domain. If you have a relationship with our company, please contact us directly and not through any information that is provided in such an email. Please be extremely careful in responding to such emails with personal and financial information, sharing passwords, or any other information of value. Alera Group, or any of our partners, will never send ACH instructions via email and thus we strongly recommend that you verify the authenticity of each wire transfer request by calling your Alera Group contact using the number you have previously called.