The Complete HIPAA Compliance Guide for Employee Assistance Program (EAP) Providers
HIPAA Applicability to EAPs
When HIPAA applies
HIPAA applies to an EAP when it functions as a group health plan or as a health care provider that transmits health information electronically in connection with standard transactions. Many employer-sponsored EAPs are treated as group health plans, which makes them covered entities subject to the Privacy Rule and Security Rule. If an EAP is administered by a vendor on behalf of the plan, that vendor may be a business associate; if the vendor directly provides counseling and bills electronically, it may also be a covered health care provider.
Excepted Benefits Status
Some EAPs qualify for Excepted Benefits Status if they provide no significant medical benefits, do not charge premiums or cost sharing, do not require participants to exhaust the EAP before other benefits, and are not coordinated with other group health coverage. Excepted status exempts the EAP from certain health reform mandates, but it does not remove HIPAA Privacy Rule and Security Rule obligations when the EAP is a group health plan handling PHI.
Intersection with 42 CFR Part 2
If an EAP provides substance use disorder diagnosis, treatment, or referral as part of a Part 2 program, records that identify an individual as having sought or received such services are protected by 42 CFR Part 2. These rules generally require written patient consent for most disclosures beyond limited exceptions. EAPs should segregate Part 2–protected information, apply heightened access controls, and ensure policies clearly distinguish HIPAA PHI from Part 2 records.
Employer Responsibilities and HIPAA
Plan sponsor duties
- Adopt HIPAA-compliant plan documents that restrict the employer’s use and disclosure of PHI and establish “firewalls” separating HR/benefits administration from employment functions.
- Designate a privacy official and a security official, implement policies and procedures, train workforce members with access to PHI, and maintain documentation.
- Provide a Notice of Privacy Practices (NPP) for the EAP and honor individual rights (access, amendment, accounting of disclosures, restrictions, confidential communications).
- Apply the PHI Minimum Necessary Standard to administrative requests, and use de-identified or aggregated data whenever possible.
- Perform and periodically update a security risk analysis, address identified risks, and monitor business associate performance.
ERISA Reporting Requirements
Most employer-sponsored EAPs are ERISA welfare plans. Depending on plan size and funding, the employer may need to furnish a Summary Plan Description (SPD) and file Form 5500. While an EAP with Excepted Benefits Status may have reduced health reform obligations, ERISA reporting and disclosure rules can still apply. Coordinate HIPAA, ERISA, COBRA, and state law requirements in a unified compliance calendar.
Privacy Rule Compliance for EAPs
Core Privacy Rule elements
- Permitted uses and disclosures: treatment, payment, and health care operations; public health and legal requirements; and as otherwise permitted by law. Disclosures to the employer generally require the individual’s written authorization unless a specific HIPAA provision allows it.
- Notice of Privacy Practices: explain uses/disclosures, individual rights, and how to exercise them. Provide the NPP at first service delivery and make it readily available for ongoing reference.
- Individual rights: access to records, request for amendment, accounting of disclosures, request for restrictions, and confidential communications (for example, using a personal email or mailing address).
- Authorizations: obtain a valid, specific authorization before sharing identifiable counseling information with supervisors, managers, or the broader employer.
- Psychotherapy notes: maintain separately and require an authorization for most uses/disclosures beyond limited exceptions.
PHI Minimum Necessary Standard in practice
Limit PHI to the least amount needed to accomplish the task. For operations reporting, use de-identified or aggregated data; for eligibility or billing, restrict access to narrowly defined data elements. Configure role-based access and standardized request forms to reinforce the Minimum Necessary principle.
Special considerations for 42 CFR Part 2 data
When Part 2 applies, obtain and document consent language that identifies the recipient and the scope and purpose of the disclosure. Build workflows that prevent inadvertent employer access to Part 2 records, and ensure disclosures are logged for accounting where required.
Security Rule Implementation for PHI Protection
Risk analysis and risk management
Conduct a comprehensive inventory of systems storing or transmitting PHI (EAP case management, telehealth platforms, messaging, backups). Identify threats and vulnerabilities, evaluate likelihood and impact, and implement risk-based controls. Reassess at least annually and after material changes.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Administrative safeguards
- Workforce security: background checks appropriate to roles, onboarding/offboarding checklists, and least-privilege access.
- Security awareness: periodic training, simulated phishing, and clear reporting channels for incidents.
- Contingency planning: backups, disaster recovery, and emergency mode operations with documented testing.
- Vendor governance: due diligence, Security Rule–aligned Business Associate Agreements, and ongoing monitoring.
Physical safeguards
- Secure facilities and work areas, device locking, screen privacy, and media disposal procedures.
- Controls for remote and hybrid work, including secure storage and transport of paper records.
Technical safeguards
- Encryption in transit and at rest for ePHI; multi-factor authentication; strong password and session controls.
- Role-based access, automatic logoff, and device management (MDM) for laptops and mobile devices.
- Audit logs for EAP systems, with routine review to detect anomalous access.
- Secure telehealth and messaging tools with BAAs and documented configuration baselines.
Executing Business Associate Agreements
Who is a business associate for an EAP?
Vendors that create, receive, maintain, or transmit PHI on the EAP’s behalf—such as call centers, telehealth platforms, case management software providers, cloud hosting, data analytics, and document destruction services—are business associates. The employer as plan sponsor is not a business associate but must be bound by plan document provisions limiting PHI use for plan administration.
Essential BAA provisions
- Permitted and required uses/disclosures aligned with the EAP’s purposes and the PHI Minimum Necessary Standard.
- Safeguards meeting the Security Rule, breach notification obligations with defined timelines, and incident cooperation.
- Subcontractor flow-down: require BAs to obtain written assurances from any subcontractors handling PHI.
- Access, amendment, and accounting support; return or destruction of PHI at termination where feasible.
- Right to audit and remediation steps for material noncompliance, including termination rights.
Managing Employer Access to PHI
What employers may receive without an authorization
- Enrollment and disenrollment information to administer eligibility.
- Summary health information for obtaining premium bids or modifying the plan, and de-identified or aggregated utilization reports for program evaluation.
- Disclosures required by law (for example, workers’ compensation) limited to the Minimum Necessary amount permitted.
What requires the employee’s written authorization
Identifiable clinical details, counselor notes, diagnoses, session content, or performance-related information for supervisors generally require a valid, written authorization. Train staff to route any manager or HR requests through standardized authorization workflows and to document all disclosures.
Governance and controls
- Plan sponsor “firewalls” that restrict PHI to a designated benefits team and bar access for employment decisions.
- Automated role-based access, disclosure logs, and periodic audits to verify that employer access stays within approved boundaries.
- Standardized reports that default to de-identified or aggregated data sets.
Confidentiality and Privacy Protections in EAPs
Building trust with participants
At intake, clearly explain confidentiality, the Privacy Rule, and—when applicable—42 CFR Part 2. Describe situations where disclosure may occur (for example, serious and imminent threats or legal requirements), and how the EAP protects participant privacy in all other cases.
Program design practices
- Keep clinical records separate from HR files; maintain secure EAP systems with strict access controls.
- Use discreet communication channels that respect confidential communications requests (personal email or mailing address).
- Deliver only aggregated or de-identified utilization summaries to employers and avoid small cell sizes that risk re-identification.
- Embed privacy-by-design into telehealth, texting, and mobile apps, including consent prompts and clear user notices.
Conclusion
For EAP providers, rigorous adherence to the Privacy Rule, Security Rule, and Business Associate Agreements—applied through the PHI Minimum Necessary Standard—protects participants and reduces organizational risk. Confirm HIPAA applicability, align employer plan sponsor obligations, manage access with de-identified reporting, and implement layered safeguards that honor both HIPAA and 42 CFR Part 2 where applicable.
FAQs
When does HIPAA apply to an Employee Assistance Program?
HIPAA applies when the EAP operates as a group health plan or as a health care provider that conducts standard electronic transactions. Many employer-sponsored EAPs are covered entities, and vendors that handle PHI for them are business associates subject to HIPAA through Business Associate Agreements.
What are the employer's responsibilities under HIPAA for EAPs?
The employer as plan sponsor must amend plan documents to restrict PHI use to plan administration, establish access “firewalls,” designate privacy and security officials, train staff, issue an NPP, honor individual rights, and oversee vendors. ERISA Reporting Requirements (such as SPDs and, in some cases, Form 5500) may also apply.
How must EAPs manage PHI under the Security Rule?
EAPs must perform a risk analysis and implement administrative, physical, and technical safeguards: role-based access, encryption, MFA, audit logging, secure telehealth platforms, vendor governance, contingency planning, and ongoing training—continually refined through a documented risk management process.
What consent is required to share employee information with an employer?
Identifiable clinical information typically requires the employee’s written authorization before disclosure to the employer. Without authorization, the employer may receive only enrollment/disenrollment data, summary health information for plan functions, or de-identified/aggregated reports, subject to the PHI Minimum Necessary Standard and any stricter protections under 42 CFR Part 2.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.