HIPAA and BAA Considerations for ICHRA Vendors: 2026 Guide

HIPAA and BAA Considerations for ICHRA Vendors: what applies, what’s in a BAA, subcontractor duties, and due diligence. Get the 2026 checklist.
Written by

TL;DR

An ICHRA is a group health plan, which makes it a HIPAA covered entity. Any vendor that administers your ICHRA and handles protected health information (PHI) qualifies as a business associate and must sign a Business Associate Agreement (BAA). But a signed BAA alone doesn’t guarantee compliance. Employers need to verify that vendors have real security controls, manage their subcontractor chains, and maintain audit-ready documentation.

Schedule a free consultation to discuss ICHRA compliance with a licensed advisor.

Key Terms at a Glance

Before getting into the specifics of HIPAA and BAA considerations for ICHRA vendors, it’s worth grounding a few foundational terms. Visit the full ICHRA glossary for additional definitions.

HIPAA (Health Insurance Portability and Accountability Act): A federal law that sets national standards for protecting sensitive patient health information. It applies to covered entities and their business associates.

PHI (Protected Health Information): Any individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate. In ICHRA administration, this includes premium invoices, enrollment status, coverage type, and reimbursement records.

Covered Entity: One of three types of organizations subject to HIPAA: health plans, healthcare providers who transmit health information electronically, and healthcare clearinghouses. An ICHRA is a health plan.

Business Associate (BA): A person or organization that performs functions involving PHI on behalf of a covered entity. ICHRA administration platforms, TPAs, and related service providers typically qualify.

BAA (Business Associate Agreement): A legally required contract between a covered entity and a business associate that establishes how PHI will be used, protected, and handled throughout and after the relationship.

Why HIPAA Applies to ICHRAs

This is the point that trips up most employers. Many assume that because an ICHRA “just reimburses premiums,” it doesn’t involve real health information. That assumption is wrong.

An ICHRA is a group health plan under federal law, regardless of employer size. Group health plans are one of the three categories of covered entities under HIPAA, as defined in 45 CFR § 160.103. This means every ICHRA, from a five-person startup to a 500-person company, carries HIPAA obligations.

Even premium-only ICHRAs generate PHI. Premium invoices reveal insurer identity, coverage type, enrollment status, and family member information. Reimbursement records show which employees are claiming what amounts. All of this qualifies as protected health information.

The scope of those obligations does vary by employer size:

  • Employers with fewer than 50 full-time employees are still subject to the HIPAA Privacy Rules, which control how and when PHI can be shared with the sponsoring company.
  • Employers with 50 or more full-time employees (ALEs) must address the full range of HIPAA requirements, including the Privacy Rule, Security Rule, and Breach Notification Rule.

Because ICHRA is a group health plan, it also triggers other federal compliance requirements. Understanding your COBRA obligations when replacing group coverage is one example of the broader regulatory picture.

What Makes an ICHRA Vendor a Business Associate

Any vendor that creates, receives, maintains, or transmits PHI on behalf of your ICHRA plan is a business associate under HIPAA. For ICHRA administration, this covers a wide range of activities:

  • Processing and approving reimbursement claims
  • Verifying employee insurance coverage and enrollment
  • Reviewing receipts or substantiation documents
  • Hosting employee data on cloud infrastructure
  • Running payment processing for reimbursements
  • Providing AI chatbots or eligibility tools that interact with employee health data

As Foley & Lardner LLP noted in their analysis, an ICHRA vendor will generally be acting as a business associate under HIPAA and must meet specific compliance obligations.

The Self-Administration Trap

Some small employers try to administer their ICHRA internally to save money. This creates a direct HIPAA problem. When employers review employee medical receipts, premium invoices, or coverage documentation themselves, they’re exposing the company to PHI in ways that HIPAA restricts. Practitioners consistently flag this as a compliance risk. The whole point of using a third-party administrator is to create a privacy layer between the employer and employee health information.

If you’re weighing the tradeoffs, this guide on whether you need a TPA walks through the practical considerations. For employers handling the claims approval process, understanding where PHI enters the workflow is critical.

What a BAA Must Include

A BAA is not a formality. It’s a binding contract with specific provisions required by federal regulation under 45 CFR § 164.504(e). Here’s what the agreement must cover:

Permitted and required uses of PHI. The BAA must describe exactly how the business associate can use and disclose PHI. Any use outside what’s specified in the contract or required by law is prohibited.

Safeguard requirements. The business associate must implement appropriate administrative, physical, and technical safeguards to prevent unauthorized use or disclosure of PHI. This includes encryption, access controls, and workforce training.

Breach notification obligations. The BAA must require the business associate to report any unauthorized use or disclosure of PHI to the covered entity, including breaches of unsecured PHI as defined under the HIPAA Breach Notification Rule. Negotiate specific timelines here; the faster you learn about a breach, the faster you can respond.

Subcontractor flow-down. The business associate must ensure that any subcontractors with access to PHI agree to the same restrictions and conditions. This is a critical provision that gets overlooked regularly.

PHI at termination. The BAA must specify what happens to PHI when the contract ends. The default requirement is that all PHI is returned to the covered entity or destroyed. If that’s not feasible, protections must remain in force indefinitely.

Right to terminate. The covered entity should retain the right to terminate the agreement if the business associate materially breaches its HIPAA obligations.

The Subcontractor Chain

One of the most overlooked HIPAA and BAA considerations for ICHRA vendors involves downstream subcontractors. Your ICHRA vendor likely doesn’t do everything in-house. They use cloud hosting providers, payment processors, data analytics tools, and increasingly, AI-powered features. Each of these subcontractors that touches PHI needs its own downstream BAA.

This isn’t optional. Since the HITECH Act (and the subsequent HIPAA Omnibus Final Rule), subcontractors of business associates are directly subject to HIPAA. If your ICHRA vendor subcontracts a function that involves PHI disclosure, a downstream BAA must be in place between the vendor and that subcontractor.

The practical implication: when evaluating ICHRA vendors, ask not just whether they’ll sign a BAA with you, but whether they have BAAs in place with every subcontractor that accesses PHI. A vendor that can’t answer this question clearly is a red flag.

AI Tools Deserve Special Attention

ICHRA platforms increasingly use AI chatbots for eligibility verification, benefits questions, and enrollment support. Any AI vendor processing PHI must operate under a BAA that outlines permissible data use and safeguards. Generative AI tools like chatbots or virtual assistants may collect PHI in ways that create unauthorized disclosure concerns, especially if the tools weren’t designed with HIPAA compliance in mind. Foley & Lardner flagged this as an emerging risk area for digital health vendors in 2025.

When evaluating vendors that offer AI features, ask specifically how those tools handle PHI, whether the AI subprocessor is covered by a BAA, and whether PHI is used to train models (it shouldn’t be).

Beyond the Signature: Vendor Due Diligence Checklist

Here’s a reality that compliance professionals on forums and in practitioner communities consistently emphasize: some vendors will sign a BAA without having meaningful security controls in place. The conversation typically goes like this. The customer asks if the vendor is HIPAA compliant. The vendor says yes. The customer asks for a BAA. The vendor signs it. What nobody discussed is whether the vendor actually meets the technical and administrative requirements the BAA obligates them to implement.

A signed BAA is the starting point, not the finish line. According to industry surveys, 44% of companies have experienced a data breach caused by a vendor.

Use this checklist when evaluating ICHRA vendors:

Security certifications. Ask for a SOC 2 Type II report or HITRUST certification. A signed BAA plus a current security attestation is materially stronger than a signed BAA alone. Remodel Health, for example, publicly states it holds HIPAA, HITRUST, and SOC 2 Type II certifications, setting a useful benchmark.

Encryption. Confirm that data is encrypted both at rest and in transit. This is a baseline expectation, not a bonus feature.

Incident response plan. Ask to see the vendor’s incident response procedures. How quickly will they notify you of a breach? What’s their remediation process?

Employee training. Request documentation showing that the vendor’s workforce receives regular HIPAA training.

Access controls and audit logging. Thatch’s ICHRA evaluation guide advises employers to ask vendors to demonstrate their audit trail setup, including who can access PHI and how access events are logged.

Data retention policies. The IRS requires 7 years of ICHRA record keeping. Your vendor’s retention and destruction policies should align with this requirement while also meeting HIPAA obligations.

State privacy law compliance. Several states (Texas, California, Washington, and others) impose privacy requirements that go beyond HIPAA. Confirm that vendors comply with the laws of every state where your employees are located.

For a broader framework, the vendor selection checklist covers additional technology and operational criteria beyond HIPAA.

ICHRA Plan Documents Must Address HIPAA

HIPAA compliance isn’t just about your vendor relationship. Your ICHRA plan documents themselves must incorporate HIPAA provisions. Legal plan documents should include ICHRA policies covering monthly reimbursement amounts, class structure, claims processes, and information on HIPAA and other privacy procedures.

Specifically, the plan document should:

  • Designate a HIPAA privacy officer (or officers) who will be authorized to access participants’ PHI
  • Establish procedures for handling PHI within the plan
  • Outline the circumstances under which PHI may be disclosed to the plan sponsor

Employers must also deliver a Notice of HIPAA Privacy Practices to participants. This is one of several required notices (alongside COBRA, CHIP, Medicare Part D, and others) that employer health plans must provide.

For guidance on structuring your plan documents, including class design and allowance frameworks, see the guide on designing eligibility criteria for benefit classes.

Penalties for Getting It Wrong

HIPAA enforcement is not theoretical. The Office for Civil Rights (OCR) collected over $9.9 million in settlements across 22 enforcement actions in 2024 alone, with BAA deficiencies cited as a contributing factor in multiple cases.

The penalty structure scales with culpability:

Violation Category Penalty Per Violation Annual Maximum
Unknowing $127 Up to $63,973
Reasonable cause $1,280 Up to $63,973
Willful neglect (corrected) $12,794 Up to $63,973
Willful neglect (not corrected) $63,973 Up to $1,919,173

OCR has extracted settlements of $31,000, $500,000, $750,000, and $1,550,000 specifically for missing or deficient BAAs.

The vendor side of the equation is equally concerning. Recent data shows that third-party vendors cause 72% of healthcare data breaches. This makes vendor vetting not just a compliance exercise but a core risk management function.

For employers navigating the full picture of ICHRA audit and compliance requirements, the audit and reporting standards guide covers ERISA and ACA obligations alongside HIPAA.

How a Dedicated ICHRA Platform Helps

The HIPAA and BAA considerations for ICHRA vendors all point toward a single practical conclusion: employers shouldn’t be handling PHI directly. A dedicated ICHRA administration platform creates the necessary separation between employer and employee health information while automating the compliance-heavy parts of plan administration.

A well-built platform handles substantiation, reimbursement processing, coverage verification, and documentation without the employer ever seeing PHI. It maintains audit-ready records for the IRS’s 7-year retention requirement. It manages the BAA relationship and downstream subcontractor chain on the employer’s behalf.

When payroll-triggered reimbursement workflows, automated expense classification, and integrated eligibility verification are built into the platform, the compliance burden shifts from the employer’s HR team to the technology and compliance infrastructure of the vendor.

Schedule a demo to see how SimplyHRA’s platform handles ICHRA administration, compliance documentation, and employer-employee privacy separation.

Frequently Asked Questions

Does HIPAA apply to my ICHRA if I have fewer than 50 employees?

Yes. While smaller employers are exempt from some HIPAA provisions, they are still subject to the HIPAA Privacy Rules. These rules govern how your ICHRA can share protected health information with the sponsoring company. Employers with 50 or more full-time employees face the full scope of HIPAA, including the Security Rule and Breach Notification Rule.

What counts as PHI in an ICHRA?

More than most employers expect. Premium invoices, insurer identity, coverage type, enrollment status, family member information, reimbursement amounts, and any medical expense documentation all qualify as PHI. Even a simple record showing that an employee is enrolled in a specific health plan is protected information.

Can I administer my ICHRA without a BAA?

Not if any third party handles PHI on behalf of your plan. If you use a vendor for administration, claims processing, payment, hosting, or any function involving PHI, a BAA is legally required. Administering entirely in-house avoids the BAA requirement but creates direct HIPAA privacy exposure for the employer, which is why most compliance professionals advise against it.

What happens if my ICHRA vendor doesn’t have a BAA in place?

You’re both at risk. OCR has imposed settlements ranging from $31,000 to $1.55 million for missing BAAs. The covered entity (your ICHRA plan) and the business associate can both face penalties. Civil fines range from $127 to nearly $1.92 million per violation depending on the level of negligence.

Do my ICHRA vendor’s subcontractors also need BAAs?

Yes. Under the HITECH Act and the HIPAA Omnibus Final Rule, subcontractors of business associates are directly subject to HIPAA. If your ICHRA vendor uses cloud hosting, payment processors, or AI tools that access PHI, downstream BAAs must be in place between the vendor and each subcontractor.

How do I know if my ICHRA vendor is actually HIPAA compliant?

Don’t rely on the vendor’s word alone. Ask for a SOC 2 Type II report or HITRUST certification. Request documentation of their incident response plan, employee training program, encryption practices, and access controls. A signed BAA combined with a current security attestation provides much stronger assurance than a signature by itself.

Does using AI features in an ICHRA platform create additional HIPAA risks?

It can. AI chatbots and eligibility tools that process PHI must operate under a BAA. Generative AI tools may collect or process PHI in ways that create unauthorized disclosure concerns if they weren’t designed for HIPAA compliance. Ask vendors specifically how their AI features handle PHI, whether the AI subprocessor is covered by a BAA, and whether PHI is ever used for model training.

How long must ICHRA records be retained?

The IRS requires 7 years of record retention for ICHRA documentation. Your vendor’s data retention and destruction policies should align with this requirement. The BAA should also specify what happens to PHI at contract termination, whether it’s returned, destroyed, or subject to continued protection.

Stop Overpaying For Group Plans Your Team Doesn't Even Like
SimplyHRA lets employers set a fixed monthly ICHRA budget and gives each employee a pre-funded virtual card to buy the health coverage that fits their life—their doctors, their family, their state. No group plan renewals. No one-size-fits-all. Just $29/employee/month, all-in.
Latest posts

Related blogs

Interviews, tips, guides, industry best practices, and news.

ALE HRA Eligibility: 2026 ICHRA Rules & Affordability

Learn ALE HRA Eligibility for 2026: ICHRA affordability, safe harbors, employee classes, and reporting. Stay compliant—see examples and get a demo.
Read post

Budget Benefits With Per Employee Per Month HRA Pricing

Discover Budget Benefits With Per Employee Per Month HRA Pricing—predictable PEPM costs, no participation minimums, tax advantages. See 2026 tips.
Read post
SimplyHRA illustration: How much should you reimburse through an ICHRA?

How much should you reimburse through an ICHRA?

There is no ICHRA contribution limit, but affordability, the 3:1 age rule, and premium tax credits constrain it. How to set an allowance, with the math.
Read post