On April 23, 2026, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced settlements with four health entities following investigations into ransomware breaches that exposed unsecured electronic protected health information (“ePHI”). While ransomware enforcement actions are not new, one of the four settlements stands out as a landmark: for the first time ever, HHS documented an enforcement action taken against a self-funded group health plan. A few months later, on June 18, 2026, OCR announced a second settlement with a self-funded group health plan.
Employers that sponsor self-funded health plans should note this development. Until now, HIPAA enforcement actions have largely focused on healthcare providers, insurers, and other traditional covered entities. These settlements with the Star Group, L.P. Health Benefits Plan (“SG Health Plan”) and Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (“Spencer Gifts Benefit Plan”) signal that OCR is prepared to hold employer-sponsored self-funded plans to the same standard.
What Happened
In October 2021 and January 2022, respectively, SG Health Plan and Spencer Gifts Benefit Plan (collectively, the “Plans”) each filed a breach report after a ransomware attack exposed the protected health information of individuals related to their Plans. The SG Health Plan and Spencer Gifts Benefit Plan breaches affected approximately 9,300 and 10,000 individuals, respectively. In both instances, HHS concluded through a subsequent investigation that the Plans failed to conduct a security risk analysis – a process under the HIPAA Security Rule that requires a covered entity to accurately and thoroughly assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI.
The terms of each settlement required the Plans to (i) submit a resolution payment (for SG Health Plan, the payment amount was $245,000 and for Spencer Gifts Benefit Plan, $450,000) and (ii) develop a Corrective Action Plan (CAP) requiring the Plans to conduct a comprehensive risk analysis, develop and implement a risk management plan, revise its HIPAA policies and procedures, and provide workforce training. Each CAP is subject to HHS review and approval over a two-year compliance term.
What Is a Security Risk Analysis?
Under the HIPAA Security Rule, every covered entity – including self-funded group health plans – must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI it creates, receives, maintains, or transmits. A compliant risk analysis should include:
- A defined scope that identifies all ePHI created, received, maintained, or transmitted by the employer on behalf of its health plan and the equipment or systems that create, receive, maintain or transmit that ePHI.
- Identification of threats and vulnerabilities to ePHI across all electronic equipment, data systems, and applications. Such threats and vulnerabilities may be natural, human, or environmental.
- An assessment of current security measures already in place.
- An impact and likelihood analysis evaluating the probability and criticality of potential risks.
- A risk rating for identified risks.
The risk analysis is not a one-time exercise. It must be reviewed and updated periodically in response to environmental or operational changes, security incidents, or other significant events. As the CAPs illustrate, a plan must also review areas like network segmentation and infrastructure, vulnerability scanning, logging and alerts, patch management, and whether adequate separation exists between the plan sponsor and the group health plan.
Once the risk analysis is complete, the entity must develop a risk management plan that implements security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Reasonableness and appropriateness is measured by what is feasible and applicable for each plan.
Thompson Hine Takeaways
1: If Your Systems Are Breached, OCR May Come Knocking
Historically, OCR has not conducted general audits for HIPAA compliance. If a complaint was lodged, OCR would investigate, but they did not randomly review for compliance concerns. However, in recent years, OCR has pivoted and has indicated that risk analysis is a priority. Further, OCR had previously never taken enforcement action against a self-funded group health plan. If your employer system is breached, OCR may investigate, and the investigation will include evaluation of your HIPAA security risk analysis. This pattern is illustrated by HHS’s recent annual reports to Congress, which summarize resolution agreements signed and civil monetary penalties assessed in 2023 and 2024. Of the 19 investigations resulting in resolution agreements or civil monetary penalties relating to cybersecurity issues, 17 of those cited the entity’s failure to conduct an accurate and thorough risk analysis as an indication of potential noncompliance. Additionally, the two settlements discussed in this blog post make clear that self-funded group health plans are squarely in OCR’s compliance crosshairs.
Employers should not assume that having strong enterprise-wide cybersecurity protections is enough. A separate, documented HIPAA security risk analysis specific to the health plan must be in place and kept up to date. In the event of a breach, employers should expect OCR to ask for not just the current risk analysis but also the prior version, and an outdated or missing analysis may draw scrutiny. Having strong firewalls and anti-virus software is not the same as having documented a compliant risk analysis and it is the documentation – not just the practices – that OCR will be looking for.
2: Use Your Resources
Many employers, particularly larger ones, engage outside vendors who specialize in HIPAA security assessments to conduct or assist with their risk analyses. This is often the most effective approach, as these vendors bring expertise in identifying technical vulnerabilities and mapping them to HIPAA requirements.
But for smaller employers who may not have the budget to hire a specialized vendor, there are still options. HHS has created a free, online Security Risk Assessment (SRA) Tool, which is specifically designed to help small and medium-sized healthcare practices comply with HIPAA’s risk analysis requirements. While the tool was originally developed with healthcare providers in mind, the underlying analysis should apply in the same manner to self-funded health plans.
3: Take Action
OCR’s recent investigatory actions make clear that conducting and documenting a current HIPAA security risk analysis is not optional. Employers who sponsor self-funded group health plans and have not recently conducted or reviewed their risk analyses should consider doing so now. Key steps include:
- Confirm that a risk analysis exists and is current. If one has never been done at the health plan level, if it has been several years since the last one was completed, or if circumstances like an office move or an acquisition render the last analysis inapplicable, begin the process.
- Create the right team. A HIPAA security risk analysis requires a multidisciplinary approach, involving representatives from Information Security, Benefits, and potentially even Facilities departments.
- Document everything. OCR will ask for documentation. The analysis, the risk management plan, and accompanying policies and procedures, support for implementation of the plan, and any remediation steps should all be in writing.
- Review and update regularly. A risk analysis from several years ago is unlikely to reflect current threats and vulnerabilities. Update the risk analysis in response to changes in the environment, to company operations, or any prior security incidents.
- Engage a vendor or use available tools. Whether through a specialized HIPAA security consultant or HHS’s free SRA Tool, get expert guidance through the process.
4: Don’t Wait
HHS has issued proposed regulations that may significantly change how covered entities would conduct a risk analysis and address a risk management plan. The regulations were originally scheduled to be finalized by May 2026, but the Trump Administration has moved them to the “long-term actions” category on its reginfo.gov website. They’re now targeting July 2027 for issuance of the final regulations, although there’s no guarantee that the regulations will be finalized by that date. Given the recent enforcement actions involving self-funded health plans, the increasing prevalence of cybersecurity issues despite robust security measures, and the uncertainty regarding when updated regulations will be issued, employers should consider acting now rather than waiting for the new regulations.
