How to Add ePHI Safeguards to Plan Documents in 60 Minutes

How to Add ePHI Safeguards to Plan Documents in 60 Minutes

Use a focused amendment package to add ephi safeguards to group health plan documents and create assessment-ready evidence in 60 minutes.

LakeRidge Team
July 19, 2026
9 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

You can add ephi safeguards to group health plan documents in 60 minutes by identifying the sponsor functions that handle electronic protected health information, preparing a targeted plan-document amendment with the four HIPAA Security Rule commitments, assigning an approver, and preserving an evidence packet. This quick-start approach addresses HIPAA 45 C.F.R. § 164.314(b)(1), but it is only defensible if the plan sponsor follows through with reasonable administrative, physical, and technical measures—especially for remote and hybrid workers.

What is the minimum-viable definition of compliant for this control?

For an external assessment, minimum viable compliance means the group health plan has plan documents that explicitly require the plan sponsor to safeguard ePHI that it creates, receives, maintains, or transmits on the plan’s behalf. The documentation must not merely say that the sponsor will “comply with HIPAA.” It should reflect the implementation specifications in § 164.314(b)(2) and support the Privacy Rule’s adequate-separation requirement in § 164.504(f)(2)(iii).

At the baseline, your plan-document amendment should require the sponsor to do four things:

  • Implement reasonable and appropriate administrative, physical, and technical safeguards for ePHI confidentiality, integrity, and availability.
  • Use security measures that support the required separation between employees performing plan administration and employees performing the sponsor’s employment, payroll, benefits strategy, or other non-plan functions.
  • Require agents and subcontractors receiving ePHI on behalf of the plan to implement reasonable and appropriate security measures.
  • Report security incidents of which the sponsor becomes aware to the group health plan.

For audit purposes, distinguish between drafted, approved, and adopted. A completed draft in 60 minutes is useful progress; it is not the same as an executed amendment. Your evidence should make that status unmistakable rather than overstating completion.

Assessment question Minimum evidence to assemble now What an auditor will test next
Do plan documents require sponsor safeguards? Plan amendment or restatement section with § 164.314(b) commitments Whether the amendment was properly approved and incorporated
Who may access plan ePHI? Named job roles and a short adequate-separation statement Actual access lists, role assignments, and HR/benefits boundaries
How are remote workers protected? Remote-work safeguards memo or policy reference MFA, managed endpoints, encryption, approved storage, and secure disposal
How are vendors controlled? List of ePHI vendors and contract-review owner Business associate agreements and security obligations
How are incidents reported? Incident reporting channel and plan-contact designation Incident procedures, logs, escalation records, and breach analysis

How do you add ephi safeguards to group health plan documents in the first 60 minutes?

The first hour should produce a narrow, reviewable amendment package—not a full security program rewrite. As an internal auditor, your objective is to establish the control language, identify the accountable owner, and document the operational assumptions that an external assessor will ask about.

Minutes 0–15: Confirm the plan and sponsor scope

Open the current group health plan document, wrap document, or plan amendment file. Confirm the legal plan name, plan sponsor name, plan administrator, and the business functions that handle ePHI. For a hybrid workforce, include benefits administration staff, HR personnel with delegated plan-administration duties, IT support teams with privileged access, and any remote employees authorized to access benefits systems.

Do not assume all HR staff are permitted to use plan ePHI. Adequate separation means the plan document should identify, by role or function, the employees who may perform plan administration and limit their use of ePHI to those duties.

Minutes 15–35: Prepare the targeted amendment language

Use language that is specific enough to map to § 164.314(b)(2) while allowing the organization to apply safeguards proportionate to its risk analysis. The following clause is a practical starting point for legal and benefits review:

The Plan Sponsor shall implement administrative, physical, and technical
safeguards that reasonably and appropriately protect the confidentiality,
integrity, and availability of electronic protected health information created,
received, maintained, or transmitted by the Plan Sponsor on behalf of the Plan.

The Plan Sponsor shall maintain security measures that support the separation
of Plan administration functions from the Plan Sponsor's other functions, shall
require its agents and subcontractors that receive such information to implement
reasonable and appropriate security measures, and shall report to the Plan any
security incident of which the Plan Sponsor becomes aware.

Add a companion adequate-separation statement identifying authorized functions, such as “Benefits Operations,” “Leave and Disability Administration,” and specifically designated benefits-system support personnel. Avoid naming individuals unless your organization can reliably update the document when staffing changes.

Minutes 35–50: Capture the remote and hybrid workforce safeguards

Plan documents do not need to list every technical setting, but your workpapers should connect the amendment to actual safeguards. Record the current state, gaps, and owners. For example, a remote benefits team may access ePHI only through Microsoft Entra ID accounts protected by phishing-resistant MFA or Microsoft Authenticator MFA, on Intune-managed Windows devices with BitLocker encryption enabled.

  • Remote access occurs through the organization’s VPN or approved SaaS applications using single sign-on and MFA.
  • Plan ePHI is not stored in personal email, personal cloud drives, unencrypted USB media, or locally saved spreadsheets unless specifically approved and encrypted.
  • Managed endpoints use device encryption, screen-lock settings, supported operating systems, endpoint protection, and remote-wipe capability where technically available.
  • Paper records used at home are minimized, stored out of view of household members, and returned or securely destroyed under the organization’s records procedures.
  • Benefits personnel report suspected misdirected emails, lost devices, unauthorized access, and malware alerts through the established security incident channel.

Minutes 50–60: Create the approval and evidence trail

Send the amendment package to the plan-document owner, benefits counsel, or authorized plan fiduciary under your organization’s governance process. Save the current plan document, redline, clean amendment, approval request, ePHI role list, and a dated control-status memo in an assessment folder. If signature will occur later, state “pending adoption” and identify the target date.

What should happen during Hours 0–4 after the amendment draft is complete?

Use the next three hours to verify that the promises made in the amendment are not contradicted by day-to-day practice. This is where an auditor can convert a document-only effort into a credible initial control implementation.

  1. Validate authorized access. Obtain an export from the benefits platform, such as Workday Benefits, ADP Workforce Now, or the carrier portal. Compare users and administrator roles against the plan-administration role list. Disable or investigate access for employees outside the designated functions.
  2. Check hybrid endpoint coverage. Confirm that authorized remote users have managed devices, encryption, supported endpoint protection, and MFA. Document exceptions, such as a broker portal accessed from a vendor-managed device.
  3. Identify third parties. List the broker, third-party administrator, pharmacy benefit manager, COBRA administrator, benefits platform, and IT service provider that may receive plan ePHI. Assign contract review to counsel, procurement, or privacy.
  4. Test incident routing. Confirm that the security team, privacy officer, and plan administrator know how a plan-related incident is escalated. A central ticket queue such as ServiceNow can be appropriate if the workflow flags potential ePHI exposure.
  5. Record gaps without hiding them. An assessor will generally respond better to a dated remediation tracker than to unsupported assertions that every safeguard is complete.

What should you complete during Days 1–7?

During the first week, move from an amendment package to adopted documentation and repeatable evidence. The priority is to make the new plan-document requirement operational for the remote/hybrid workforce policy rollout.

  • Obtain formal adoption of the amendment and distribute the final version to the plan-document repository.
  • Update the remote-work policy or benefits handling procedure to state who may access plan ePHI, from which devices, and through which approved systems.
  • Review business associate agreements and other vendor agreements for security obligations that align with the sponsor’s commitment to require safeguards from agents and subcontractors.
  • Provide focused training to authorized benefits and IT support personnel on separation boundaries, secure remote handling, phishing reporting, and incident escalation.
  • Create or update a risk-analysis entry for remote access to plan ePHI, including risks from unmanaged devices, shared home workspaces, misdirected email, and excessive administrator access.
  • Collect screenshots or configuration evidence for MFA, encryption compliance, conditional access, endpoint management, and access reviews.

What have you intentionally deferred, and why is that acceptable?

A 60-minute quick-start should intentionally defer work that requires evidence gathering, technical validation, legal review, or governance approval. Deferring those items is acceptable only when you document the gap, assign an owner, set a due date, and avoid representing the control as fully mature.

Items commonly deferred include a comprehensive enterprise risk analysis, full vendor contract remediation, penetration testing, tabletop incident exercises, detailed audit-log review procedures, and redesign of legacy benefits-system roles. These activities matter, but none should delay adding the required sponsor commitments to the plan documents when the underlying safeguard requirement is currently absent.

Do not defer the determination of whether the sponsor actually receives or accesses ePHI. If the sponsor does not handle ePHI on behalf of the plan, document that conclusion with counsel or privacy leadership rather than adding generic language without understanding the operating model.

When should you upgrade from a quick-start to a mature control?

Upgrade immediately when remote access expands, a new benefits vendor is onboarded, privileged access is granted to additional IT personnel, a security incident involves plan information, or the external assessment requests implementation evidence beyond the plan language. A mature program links the plan-document requirement to risk analysis, access governance, endpoint controls, vendor oversight, incident response, training, and periodic testing.

For the auditor, maturity is demonstrated when you can trace each promise in the amendment to an owner, operating procedure, technical safeguard, and retained record. That traceability is more persuasive than a lengthy policy library because it shows that the group health plan’s ePHI safeguards operate in practice.

Next step: Schedule a 30-minute evidence review with benefits, privacy, IT security, and plan counsel to convert your 60-minute amendment package into an externally assessable control file.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.