Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

  • About HHS
  • Programs & Services
  • Grants & Contracts
  • Laws & Regulations
  • Radical Transparency
  • HIPAA for Individuals
  • Filing a Complaint
  • HIPAA for Professionals
  • Newsroom
Breadcrumb
  1. HHS
  2. HIPAA Home
  3. For Professionals
  4. FAQ
  5. Group Health Plans
  • Authorizations (30)
  • Business Associates (41)
  • Compliance Dates (2)
  • Covered Entities (14)
  • Decedents (9)
  • Disclosures for Law Enforcement Purposes (5)
  • Disclosures for Rule Enforcement (1)
  • Disclosures in Emergency Situations (2)
  • Disclosures Required by Law (6)
  • Disclosures to Family and Friends (28)
  • Disposal of Protected Health Information (6)
  • Facility Directories (7)
  • Family Medical History Information (3)
  • FERPA and HIPAA (10)
  • Group Health Plans (3)
  • Incidental Uses and Disclosures (10)
  • Judicial and Administrative Proceedings (8)
  • Minimum Necessary (14)
  • Notice of Privacy Practice (20)
  • Preemption of State Law (10)
  • Privacy Rule: General Topics (12)
  • Protected Health Information (2)
  • Public Health Uses and Disclosures (13)
  • Research Uses and Disclosures (20)
  • Right to an Accounting of Disclosures (8)
  • Right to File a Complaint (1)
  • Right to Request a Restriction (4)
  • Safeguards (13)
  • Security Rule (24)
  • Smaller Providers and Businesses (145)
  • Student Immunizations (8)
  • Transition Provisions (3)
  • Treatment, Payment, and Health Care Operations Disclosures (30)
  • Workers Compensation Disclosures (5)
  • Limited Data Set (6)
  • Marketing (17)
  • Marketing - Refill Reminders (16)
  • Personal Representatives and Minors (12)
  • Right to Access and Research (58)
  • Mental Health (35)
  • Health Information Technology (41)
  • Telehealth (11)

Group Health Plans

When the conditions set forth in 45 CFR 164.504(f) of the HIPAA Privacy Rule have been met.

Read the full answer

Yes. The Privacy Rule requires a health plan to remind enrollees of the availability of its Notice of Privacy Practices, as well as how to obtain a copy, no less frequently than once every 3 years.

Read the full answer

Does HIPAA permit one health plan to share protected health information (PHI) about individuals in common with a second health plan for care coordination purposes? 

Yes.

The HIPAA Privacy Rule permits a covered entity to disclose PHI to another covered entity for its own health care operations purposes, or for the health care operations of the entity receiving the information.  If the disclosure of PHI is for the health care operations of the recipient covered entity, the Privacy Rule requires that (i) each entity either has or had a relationship with the individual who is the subject of the PHI being requested, (ii) the PHI pertains to that relationship, and (iii) the disclosure is for a health care operation listed in paragraphs (1) or (2) of the definition of health care operations or for health care fraud and abuse detection or compliance.  45 CFR 164.502(a)(1)(ii); 45 CFR 164.506(c)(4).  Case management and care coordination are among the activities listed in paragraph (1) of the definition of health care operations.  45 CFR 164.501.  For example, if Covered Entity A provides health insurance to an individual who receives access to the provider network of another plan provided by Covered Entity B, Covered Entity A is permitted to disclose an individual’s PHI to Covered Entity B for care coordination, without the individual’s authorization.  45 CFR 164.506(c)(1).  Similarly, if an individual had been enrolled in a health plan of Covered Entity A and switches to a health plan provided by Covered Entity B, Covered Entity A can disclose PHI to Covered Entity B for Covered Entity B to coordinate the individual’s care, without the individual’s authorization. 

Although such disclosures are permitted, they are subject to the minimum necessary standard. 45 CFR 164.502(b).

Does the HIPAA Privacy Rule permit a covered entity to use and disclose PHI to inform individuals about other available health plans that it offers, without the individuals’ authorization, if the covered entity received the PHI for a different purpose?

Yes, in certain circumstances.  If a covered entity possesses or receives PHI about an individual, it can use or disclose such PHI where, and in the manner, permitted by the Privacy Rule.  45 CFR 164.502(a) and (b).  Covered entities are prohibited from using or disclosing PHI for marketing purposes without the individual’s authorization, unless the communications are subject to an exception.  45 CFR 164.508(a)(3)(i) (exception to marketing authorization for face-to-face communications by a covered entity to an individual and for promotional gifts of nominal value).  In addition, certain communications to individuals about products or services are specifically excluded from the definition of “marketing.”  45 CFR 164.501 (definition of marketing, para (2)).  One such exclusion from the definition of marketing is for communications to individuals regarding replacements to, or enhancements of, existing health plans, so long as the covered entity is not receiving financial remuneration for the communications.  45 CFR 164.501 (definition of marketing, para (2)(ii)(B)); see also 45 CFR 164.506(c)(1) and 45 CFR 164.501 (definition of “health care operations,” para (3)).  Thus, if these conditions are met, HIPAA permits a covered entity to use PHI in its possession about individuals to inform such individuals about the availability of other health plans it offers without the individuals’ authorization.  See 45 CFR 164.502(a)(1).  For example, in a situation where Plan A discloses PHI about an individual to Plan B (a separate covered entity), Plan B is permitted to send communications to the individual about Plan B’s health plan options that may replace the individual’s current plan (e.g, Medicare plans for individuals reaching the age of Medicare eligibility), without the individual’s authorization, so long as Plan B (1)  receives no remuneration for sending the communication to the individual, and (2) complies with any business associate agreement(s), where applicable.

Read the full answer
Back to top

Subscribe to Email Updates

Receive the latest updates from the Secretary and Press Releases.

Subscribe
  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • Press Room
  • HHS Archive
  • Accessibility Statement
  • Privacy Policy
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy
HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​

Follow HHS

Follow Secretary Kennedy