Compliance and deadlines

HIPAA limits on benefits steering committees

Originally posted by

A benefits steering committee is built to do real work. Review claims trends, pressure-test the PBM, model the renewal, shape next year’s plan design. HIPAA lets a plan use protected health information for operations work under 45 CFR 164.506.

But that permission has two real limits: 1) use the minimum necessary; and 2) never use the data for employment decisions. That ban lives in 164.504(f), and it’s where trouble arises.

A member who is also a manager cannot carry what they saw about an employee’s cancer claim or mental health treatment into a promotion, a layoff, or a performance review.

And the committee almost never needs names. Aggregate cost by category shows where the money goes. A list of who is sick tells you nothing and creates real exposure.

The committees that hold up put this in writing. A short charter that names its members, limits them to plan administration, keeps them on aggregated or de-identified data, sets safeguards for any identifiable data, and states that plan data never drives employment decisions.

No magic words. Just some plain language that says that the committee, plan, and employers understand the rules and commit to following them.

When I look at how an employer set up its committee, the written policy is the first thing I check. What does yours say about employment decisions?

Sources

  • 45 C.F.R. § 164.506
  • 45 C.F.R. § 164.504(f)

Originally posted on LinkedIn, where the discussion and source links live in the comments.

About the author

Chris Vanderwolk is Director of Compliance and Innovation at OneDigital | Kistler Tiffany Benefits General Agency, where he helps brokers and employers navigate the regulatory complexity of employee benefits. An ERISA attorney with more than 19 years in the benefits industry, he specializes in translating what the law actually requires into language people can use.

All writing