The group health plan exception is a two-branch rule for a group health plan that provides benefits solely through an insurer or HMO. If the plan receives only specified summary or participation and enrollment information, it need not maintain or provide an NPP. If it receives additional PHI, it maintains a notice and provides it on request, while the ordinary health-plan distribution provisions do not apply to that plan.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
The PHI boundary controls the branch
Under 45 CFR 164.520, the limited-information branch covers summary health information and specified participation, enrollment, or disenrollment information. Inventory what the plan actually creates or receives. Plan-document language alone cannot resolve a workflow that sends additional PHI to the sponsor or plan.
Start with the insurance structure and benefit arrangement, then map every inbound, outbound, stored, and user-accessible information flow. Include enrollment, eligibility, summary reporting, appeals, case management, wellness, stop-loss, audit, vendor, legal, finance, and sponsor support. Record sender, recipient, fields, identifiability, purpose, system, access role, frequency, and authority. Qualified benefits and privacy reviewers should classify the actual flow.
Apply the two branches to operational facts
When the plan provides benefits solely through an insurer or HMO and receives only the specified limited information, the described NPP maintenance and provision exception may apply. Preserve the branch decision, data-flow evidence, reviewers, date, and monitoring trigger. Do not treat absence of a local claims database as proof that no additional PHI reaches the plan.
If the plan creates or receives additional PHI, maintain the applicable notice and a request route under the branch described by the rule. Document how any ordinary health-plan distribution provisions differ for that plan. A generic insurer notice cannot automatically stand in for the plan's own notice when the plan has separate duties.
Insurer and plan duties remain distinct
Individuals generally receive notice from the insurer or HMO for insured benefits. The group health plan's exception analysis addresses its own notice duty. It does not decide plan-document amendments, sponsor access, certification, security, or another HIPAA obligation.
Keep insurer, HMO, group health plan, plan sponsor, employer, administrator, broker, and vendor roles explicit. Contract labels can help but do not replace workflow analysis. Restrict sponsor and workforce access through the appropriate controls, and route requests for the plan's notice to a trained contact. The exception does not authorize broader access or resolve a disclosure to the employer.
Reopen the analysis when data flows change
Appeals, care-management programs, new wellness services, analytics, audits, stop-loss reporting, litigation, internal administration, and vendor integrations can introduce member-level PHI. Require privacy review before launch and compare production data with the approved flow. Acquisitions, funding changes, insurer replacement, and self-funded components also warrant a new branch decision.
Monitor shared mailboxes, file transfers, system permissions, ticket attachments, and ad hoc spreadsheets. A documented policy can say the plan receives limited information while routine operations contradict it. Preserve findings and either stop the unsupported flow or update the NPP and related controls through qualified review.
Example with data flows
A plan maps eight inbound data flows. Seven contain only permitted limited information; one appeals file contains member-level clinical details. The plan cannot use the limited-information branch while that additional PHI flow continues. Record remediation or the request-only notice route before closure.
The plan suspends the unapproved transfer, preserves the evidence, and determines whether the appeals workflow belongs with the insurer or within a plan process that receives additional PHI. It documents the resulting branch, notice decision, access controls, and request route. A follow-up sample confirms that production data matches the approved design.
Exception-analysis checklist
- Confirm the insured structure and entities involved.
- Inventory actual data fields, systems, recipients, and access roles.
- Distinguish specified limited information from additional PHI.
- Record the branch decision, evidence, reviewers, and date.
- Keep insurer, plan, sponsor, employer, and vendor duties separate.
- Maintain the applicable notice and request route when required.
- Reassess after funding, appeals, vendor, service, or access changes.
Owner controls
Use the HHS notice guidance as orientation and obtain qualified benefits and privacy review. Maintain the insurance structure, data-flow map, PHI classification, sponsor access, applicable notice, request path, and change trigger.
Monitor approved flows, actual transfers, access changes, member-level files, request-route tests, branch reviews, and unresolved exceptions. Audit from system data back to the approved map and from the map into sampled production records. Retain the decision history so later reviewers can see when facts changed and which notice duty applied.
Require periodic attestations from system, benefits, legal, privacy, and vendor owners that the documented flows remain complete. Pair those attestations with technical evidence such as access lists, transfer logs, file schemas, and sampled records. Investigate any PHI found outside the map and preserve incident or corrective-action routing separately from the NPP branch decision.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni