Speaking Engagements
Healthcare Securities Class Actions, SEC Enforcement & Emerging Capital Markets Risks
September 2, 2026
The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) recently announced two separate settlements with self-funded employee group health plans, one sponsored by an energy provider and another sponsored by a national retailer (each, a Plan). The resolutions are notable as the first and second direct HIPAA enforcement actions against self-funded employer-sponsored group health plans, which are “covered entities” for HIPAA purposes.
Several years prior to the settlement, the Plan experienced a ransomware attack in which an unauthorized actor deployed ransomware on the plan sponsor’s systems and exfiltrated personally identifiable information, some of which included electronic protected health information (ePHI). The Plan reported the breach to the OCR, and the OCR’s subsequent investigation identified non-compliance by the Plan with HIPAA. In the enforcement action, the OCR specifically noted that the Plan failed to conduct an accurate and thorough risk analysis to identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of Plan ePHI on the plan sponsor’s systems. The Plan agreed to pay $245,000 and implement a monitored two-year Corrective Action Plan (CAP). The CAP requires the Plan to come into compliance with HIPAA by undertaking these requirements: conduct a comprehensive risk analysis for ePHI, develop and implement a risk management plan, update policies and procedures, and provide workforce training. The CAP requires the OCR’s approval of the risk management plan and revised policies, and the Plan must submit periodic reports to OCR with documentation proving and attesting to compliance with HIPAA.
This settlement arose after the Plan filed a breach report with the OCR detailing the Plan’s discovery of an unauthorized actor that accessed the plan sponsor’s network and deployed ransomware, encrypting data on the plan sponsor’s systems (including servers storing the Plan’s ePHI) and demanding a ransom. Upon investigation, the OCR found that the Plan failed to conduct an accurate and thorough risk analysis to identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of Plan ePHI, and failed to implement reasonable and appropriate policies and procedures to comply with the HIPAA Privacy, Security, and Breach Notification Rules. The Plan agreed to pay $450,000 and implement a monitored two-year CAP. The CAP requires the Plan to conduct a comprehensive risk analysis for ePHI, review and revise (as needed) its HIPAA Privacy, Security, and Breach Notification Rule policies and procedures, provide workforce training, and submit periodic reports to the OCR.
If you operate a self-funded group health plan, the following are key operational steps to consider based on the enforcement actions:
If you sponsor or administer a self-funded group health plan and would like assistance reviewing your current HIPAA compliance program, updating documentation, and/or preparing for potential OCR scrutiny, please contact a member of our Employee Benefits + Executive Compensation Practice Group. Our attorneys regularly counsel plans and plan sponsors on HIPAA compliance, risk analysis requirements, business associate agreements, and responding to OCR investigations. We are happy to help complete these steps and tailor required documentation to your plan’s specific structure and operations.
Ashley Golden, a 2026 summer associate with Troutman Pepper Locke who is not admitted to practice law in any jurisdiction, also contributed to this article.
This just in
Speaking Engagements
Healthcare Securities Class Actions, SEC Enforcement & Emerging Capital Markets Risks
September 2, 2026
Firm Events
Cocktails and Networking During MEDevice Boston
August 26, 2026 | 6:00 PM – 8:00 PM ET
Lifted Restaurant
450 Summer St, Boston, MA 02210
Speaking Engagements
The 2026 Multifamily Maturity Cliff: Reading the $162 Billion Refinancing Wave and the Engagements It Will Generate
August 26, 2026 | 1:00 PM – 3:10 PM ET
Webinar
Speaking Engagements
ILTACON 2026 Conference
August 23 – 27, 2026
Gaylord Opryland Resort & Convention Center
2800 Opryland Dr, Nashville, TN 37214