HIPAA

HIPAA compliance church health information privacy

Many churches assume HIPAA applies whenever member health information comes up — a prayer request, a hospital visit, a benevolence request tied to a medical bill. In most of a church’s ordinary ministry, that assumption is wrong. HIPAA is narrower than people expect, and it turns on what an organization actually does, not on whether health information happens to be involved.

What HIPAA Actually Regulates

HIPAA — the Health Insurance Portability and Accountability Act — protects the privacy and security of protected health information (PHI), but only for “covered entities”: health care providers who transmit health information electronically in standard transactions, health plans, and health care clearinghouses, along with their “business associates” who handle PHI on their behalf. If an organization doesn’t fall into one of those categories, HIPAA’s rules simply don’t attach to what it does, however sensitive the information involved might be.

Is Your Church a HIPAA Covered Entity? Usually Not

A church’s ordinary ministry activities — prayer lists, pastoral counseling that isn’t billed to insurance, visitation notes, benevolence assistance — generally don’t make the church a covered entity, because none of that involves the electronic health care transactions HIPAA is built around. Information a member voluntarily shares with a pastor for prayer or care isn’t PHI under HIPAA at all. That doesn’t mean it’s fair game to share — it deserves the same discretion any church already applies to sensitive personal information — it just means a slip here isn’t technically a HIPAA violation the way it would be for a hospital or insurer.

That changes if a church operates something that functions like a health care provider or plan: a church-run clinic or counseling center that bills insurance electronically becomes a covered entity for that specific activity, even if the rest of the church’s operations stay outside HIPAA’s reach.

The Exception Most Churches Miss: Sponsoring a Health Plan

Here’s the situation that actually brings HIPAA into most churches’ operations: sponsoring a group health plan for staff. The U.S. Department of Health and Human Services explicitly includes church-sponsored health plans among covered health plans under HIPAA — the church as an employer isn’t the covered entity, but the plan itself is. There’s a narrow exception: a group health plan with fewer than 50 participants that’s administered solely by the employer that established it generally isn’t a covered entity.

Outside that exception, if your church sponsors a self-funded health plan for employees, that plan has to meet HIPAA’s requirements, and plan-related PHI needs to be kept separate from general HR and pastoral files — accessible only to whoever actually administers the plan, not to staff generally.

Common HIPAA Violations Where It Does Apply

Where HIPAA genuinely applies — a church health plan, or a church-run clinic that bills electronically — the common violations are consistent: disclosing PHI without proper authorization, inadequate safeguards against unauthorized access, missing privacy policies or workforce training, using PHI for purposes beyond what it was collected for, denying someone timely access to their own records, missing business associate agreements with vendors who handle PHI, and failing to provide required notification after a breach of unsecured PHI. The Department of Health and Human Services’ Office for Civil Rights enforces these requirements and can impose both civil and criminal penalties depending on severity.

Related Articles

Church Officer and Director Liability
Independent Contractors

Disclaimer: Every situation is different and particular facts may vary thereby changing or altering a possible course of action or conclusion. The information contained herein is intended to be general in nature as laws vary between federal, state, counties, and municipalities and therefore may not apply to any given matter. This information is not intended to be legal advice or relied upon as a legal opinion, course of action, accounting, tax or other professional service. You should consult the proper legal or professional advisor knowledgeable in the area that pertains to your particular situation.

Spread the word. Share this post!