Health plan data privacy is not a side issue anymore. It is the fine print sitting inside almost every vendor contract a plan sponsor signs, and increasingly, that fine print includes permission to train an AI model on member claims data.
Photo by Towfiqu barbhuiya on Unsplash
Insurers and their vendors have moved fast. A National Association of Insurance Commissioners survey found that 84 percent of health insurers already use AI or machine learning somewhere in their operations, and 68 percent use it specifically for prior authorization decisions. Every one of those tools was trained on data, and a growing share of that training data started as someone’s health plan claim.
That shift puts plan sponsors in an odd spot. Most benefits leaders can explain their deductible structure and their stop loss attachment point without blinking. Far fewer can say with confidence what their third party administrator, pharmacy benefit manager, or wellness vendor is doing with member claims data inside an AI pipeline, or whether anyone at the company ever agreed to it in writing. Health plan data privacy has quietly become a governance gap most committees have not closed.
None of this makes AI the villain of the story. Used well, AI can speed up claims turnaround and catch billing errors that a human reviewer would miss. The problem is not the technology itself. It is signing off on how that technology touches health plan data privacy without asking a single question first.
Why Health Plan Data Privacy Is Suddenly an AI Problem
For years, the privacy question was narrow: who is allowed to see a claim. Now the more urgent question is what a vendor’s AI system learned from thousands of claims, and whether that knowledge lives on inside a model that keeps working long after the service agreement ends. A trained model does not forget the way a filing cabinet can be emptied.
Regulators are not treating this lightly either. As of January 2026, HHS raised its HIPAA civil penalty tiers for inflation, with the top tier reaching $2,190,294 per violation category, per calendar year, for willful neglect that is not corrected.
Self-funded plan sponsors are not bystanders in this. A self-funded group health plan is a HIPAA covered entity in its own right, which means the same privacy and security rules that apply to a hospital system apply to the plan sitting on your company’s balance sheet. When a vendor asks for permission to use claims data beyond the task the plan hired it to do, the plan is the one holding the compliance risk, not just the vendor’s brand name.
What HIPAA Actually Permits When AI Is in the Mix
HIPAA does not have a special carve out for artificial intelligence. It has the same framework it has always had. Covered entities and business associates may use protected health information for treatment, payment, and healthcare operations, and anything that falls outside those categories generally needs authorization from the member or a valid de-identification step first.
A Business Associate Agreement Is Not a Blanket Yes
A signed BAA is table stakes, not a finish line. It defines what a vendor may do with protected health information, and training a general-purpose AI model is a distinct use case from processing a claim for payment.
If the agreement does not specifically name model training, evaluation, and support as permitted uses, a vendor that trains on your plan’s data anyway is operating outside the deal you actually signed, regardless of what its sales team implied during onboarding. Get the scope wrong here and health plan data privacy stops being a policy statement and starts being a liability.
De-identification Is the Real Bar for Training Data
HIPAA offers two paths to strip data of its protected status. The Safe Harbor method removes eighteen specific categories of identifiers, from names and addresses down to device numbers and biometric data. Expert Determination is the other route, where a qualified statistician certifies in writing that the risk of re-identifying an individual from the remaining data is very small.
Under the Privacy Rule’s minimum necessary standard, a covered entity or business associate should use de-identified information for an activity like AI training whenever that is feasible. Once data genuinely meets one of these two standards, HIPAA no longer applies to it at all, which is exactly why vendors lean so heavily on the word “de-identified” in their sales materials.
Minimum Necessary Still Applies to Every AI Feature
The minimum necessary standard does not disappear because the word “AI” appears in a statement of work. A vendor’s chatbot that answers benefit questions does not need five years of a member’s full claims history to do its job, and a model trained broadly across an entire book of claims for convenience, rather than scoped tightly to a defined administrative task, is very likely asking for more data than the task requires. Scope creep like this is where health plan data privacy quietly erodes.
Photo by Vitaly Gariev on Unsplash
The Regulatory Net Around Health Plan Data Privacy Is Tightening
Regulators are not waiting for a major breach to catch up with AI. In January 2025, the Department of Health and Human Services proposed the first major update to the HIPAA Security Rule in two decades, and the proposal explicitly states that electronic protected health information used in AI training data, prediction models, and algorithm data maintained by a regulated entity is protected by HIPAA. That is a direct answer to the argument some vendors have made that AI training somehow sits outside the rule.
State regulators are moving in parallel. At least 25 states have issued guidance based on a 2023 model bulletin from the National Association of Insurance Commissioners covering how existing insurance law applies to AI, including its use in claims administration, fraud detection, and underwriting. None of this makes health plan data privacy simpler. It makes it a moving target that plan sponsors need to track at both the federal and state level, not just at the moment a vendor contract gets signed.
This Is Also a Fiduciary Duty Question, Not Just a Compliance One
Here is the part many plan sponsors miss. A perfectly HIPAA-compliant arrangement can still be an ERISA problem, because HIPAA compliance and prudent fiduciary judgment are two different tests. Only one of them measures whether the decision was actually made with the plan participants’ best interest in mind, and it is the one that carries personal liability for the people sitting on your benefits committee.
ERISA’s duty of prudence requires fiduciaries to act with the care, skill, and diligence that a prudent person familiar with these matters would use. That duty does not stop at picking a carrier once every few years. It extends to negotiating vendor contract terms, monitoring how those vendors actually perform, and revisiting the relationship when circumstances change.
Attorneys who track this area of employee benefits law have been direct about the implication. Fiduciaries who delegate claims processing to an opaque AI system, without asking how that system uses plan data, are taking on real litigation exposure, not a theoretical one. Health plan data privacy, in other words, is now a fiduciary line item.
The vendor-monitoring theory behind this is not new. It is the same theory playing out in Lewandowski v. Johnson & Johnson, where plan participants argued the company’s benefits committee failed to prudently negotiate and monitor its pharmacy benefit manager’s contract terms. That case centers on drug pricing, not AI, but the underlying principle transfers directly: a fiduciary who signs a vendor agreement without scrutinizing its terms, and never revisits it, is exposed either way.
Five Questions to Ask Before Signing an AI Vendor Contract on Health Plan Data Privacy
Legal and benefits advisors who focus on this issue keep landing on the same short list of questions plan sponsors should be able to answer before a signature goes on any vendor agreement that touches health plan data privacy. None of these require a technical background, only a willingness to ask and to insist on a written answer.
Photo by Campaign Creators on Unsplash
What This Looks Like in Practice
Picture a mid-size employer heading into its annual TPA renewal, the kind of health plan data privacy decision that rarely gets a second look. The contract renewal packet lands with a routine cover email, and buried on page eleven is an updated “service enhancement” clause granting the TPA rights to use claims data to improve its AI-driven utilization review tools, for this plan and others. Nobody flags it, because nobody on the committee was looking for it.
A fiduciary-first review catches that clause before signing, not after a complaint arrives. The committee asks the TPA to name the permitted AI uses inside the BAA, confirm which de-identification method applies, and strike the language allowing the plan’s data to train models for other book-of-business clients.
The renewal still closes on time. Nothing about the process slows the plan down or turns into a standoff with the TPA. The difference is that health plan data privacy and the fiduciary paper trail both improve at the same time, with a written record the committee can point to if anyone ever asks how the decision was made.
Build a Fiduciary-First AI Vendor Review Into Your Renewal Cycle
Ethos Benefits helps employers put real structure around fiduciary decisions, including how vendors handle health plan data privacy. Our Fiduciary Framework gives your benefits committee a documented process for exactly this kind of review.
Let’s TalkFrequently Asked Questions
Yes, if that data is protected health information. Training an AI model is not automatically treatment, payment, or healthcare operations, so using identifiable claims data at scale for training generally requires either member authorization or a valid de-identification step first. This is one of the clearest health plan data privacy risks in a typical vendor relationship.
Once data genuinely meets the Safe Harbor or Expert Determination standard, it is no longer considered protected health information and HIPAA no longer applies to it. The catch is that de-identification has to be done correctly and documented, not simply assumed, and a weak process here is a common source of health plan data privacy problems.
ERISA’s duty of prudence covers how fiduciaries select and monitor the vendors who service the plan, and that duty does not pause for AI. If a vendor’s AI practices affect how claims data is used or how claims decisions are made, reviewing those practices, and the health plan data privacy terms behind them, falls squarely inside a fiduciary’s existing job.
At minimum, the agreement should name AI training and evaluation as a permitted use if it applies, specify the de-identification method used, restrict the vendor from training models for other clients on your plan’s data, and address what happens to the data and any resulting model when the contract ends. It should also spell out audit rights, so the committee can verify these terms rather than take them on faith.
This article is provided for general informational purposes and does not constitute legal advice. Health plan sponsors should consult qualified ERISA counsel and a HIPAA privacy professional before making decisions about vendor contracts, health plan data privacy, or fiduciary process.