← Back to blog

Does HIPAA Apply to Your Workplace Wellness Program?

August 26, 2026
Does HIPAA Apply to Your Workplace Wellness Program?

BLUF: HIPAA applies to workplace wellness programs only when they operate as part of a group health plan or when a covered entity or business associate holds the program data. Otherwise, other federal laws, mainly the ADA, GINA, and FTC rules, govern what you can and cannot do with employee health information.

If your program is tied to your group health plan (biometric screenings that adjust premiums, health risk assessments linked to plan incentives), treat every data point as protected health information (PHI). If it's a standalone perk (a stipend for a gym membership, a company-wide step challenge with no plan tie), HIPAA doesn't apply, but you're not off the hook. The Department of Labor and HHS jointly regulate incentive limits for plan-based programs, while HHS/OCR sets the coverage test itself.

  • If plan-linked: lock down employer access to identifiable data immediately.
  • If standalone: audit your vendor's data-sharing practices for FTC exposure.
  • Either way: document which category your program falls into today, in writing.

A population health partner like Hadaco builds compliance into program design from day one, rather than retrofitting it after a complaint lands.

Key Takeaways

Compliant wellness programs succeed by correctly classifying HIPAA coverage upfront, capping incentives within regulatory limits, and auditing every vendor for both PHI handling and third-party data sharing.

PointDetails
Classify before you designDetermine group health plan status first; every other compliance decision flows from that answer.
Cap incentives correctlyUse 30% of employee-only coverage cost as the standard ceiling, 50% for tobacco programs.
Certify plan-sponsor separationAmend plan documents and certify PHI access controls before any data transfer occurs.
Audit vendors regardless of HIPAA statusScan for tracking pixels and require BAAs wherever PHI could be generated.
Hadaco integrates compliance into designPrograms layer onto existing plans with quarterly reporting and no upfront fees.

Table of Contents

How to Decide: Group Health Plan vs. Employer-Run Program

The entire HIPAA question hinges on one structural fact: is your wellness program part of your group health plan, or is it a separate perk you run directly?

HIPAA's Privacy and Security Rules bind "covered entities" (health plans, clearinghouses, and most providers) and their "business associates" (vendors who touch PHI on the plan's behalf). A group health plan is a covered entity. When your wellness program is woven into that plan, meaning participation changes premiums, deductibles, or plan contributions, the data collected becomes PHI, and HIPAA governs it directly.

When the program runs outside the plan (employer pays for it directly, no premium or contribution impact), HIPAA typically doesn't reach it, even though the subject matter looks identical on paper.

Covered examples: biometric screening results that feed into a premium surcharge; health risk assessments tied to a plan-based reward. Not covered examples: a standalone step-count challenge with a gift card prize; a gym membership reimbursement paid straight from payroll, with no connection to plan design.

Run this quick diagnostic with your benefits counsel:

  1. Does the incentive or penalty change what an employee pays for group health coverage?
  2. Does the plan document reference the wellness program at all?
  3. Who administers the program, the health plan's third-party administrator or a separate HR vendor?
  4. Does the data flow into the plan's claims or enrollment systems?
  5. Would an employee lose or gain plan benefits based on participation?

Pro Tip: If you answer "yes" to even one of the first two questions, assume HIPAA applies and route the decision through your plan's privacy officer, not just HR.

The Five Requirements for Health-Contingent Programs and Reward Caps

Health-contingent wellness programs, ones that require employees to hit a health target or complete an activity to earn a reward, face the strictest rules. The Departments of Labor, Health and Human Services, and Treasury built five specific requirements into the final regulations governing these programs:

  • Annual qualification opportunity: employees must be able to qualify for the reward at least once a year.
  • Reasonable design: the program must have a legitimate shot at improving health, not just penalize people.
  • Full reward availability: everyone must be able to earn the full reward, including through a reasonable alternative.
  • Reasonable alternative standard: anyone who can't meet the standard due to a medical condition gets another way to qualify.
  • Disclosure: plan materials must clearly explain the alternative standard's availability.

The reward cap is generally limited to a significant portion of the total cost of employee-only coverage for most health-contingent programs, with a higher limit allowed when a tobacco-prevention component is involved. If dependents participate, the cap calculates against the cost of whatever coverage tier they're enrolled in, not just the employee-only rate, so a family plan with spousal wellness incentives, needs its own math.

Participatory programs (health fairs, gym reimbursements with no health target) skip these five requirements entirely, since there's no outcome or activity gate. Activity-only programs (walk a certain number of steps) and outcome-based programs (hit a specific cholesterol number) both trigger the full requirement list, with outcome-based designs facing the closest EEOC scrutiny.

Employer Access, Certifications, and Safeguards for PHI

If your wellness program is plan-linked, receiving PHI as the employer isn't automatically off-limits, but it comes with real paperwork. HHS guidance requires the plan document to be amended to describe how PHI will be used, and the plan sponsor must certify that it has put safeguards in place before the plan hands over data.

That certification isn't a formality. It has to describe a genuine separation between employees who administer the plan (who may see PHI) and everyone else in HR or management (who should not).

  • Amend the plan document to name permitted uses of PHI and certify the separation before any data transfer happens.
  • Restrict ePHI to specific systems with access logs, encryption at rest and in transit, and role-based permissions.
  • Build a breach-notification protocol that meets HIPAA's timelines the moment a vendor or internal system is compromised.
  • Require a signed Business Associate Agreement (BAA) from any vendor that creates, receives, or transmits PHI on the plan's behalf.

Pro Tip: Ask every wellness vendor for their BAA template before signing anything else. If they can't produce one, that's your answer about whether they've handled PHI before.

Where ADA, GINA, and FTC Enforcement Come In

Even when HIPAA doesn't apply, you're not operating in a vacuum. The EEOC enforces the ADA's requirement that medical inquiries in wellness programs stay voluntary, with reasonable accommodations for employees who can't participate in a standard way, and physician verification available when a medical condition prevents someone from meeting a health standard.

GINA adds a separate rule: employers cannot collect genetic information, including family medical history, as a condition of earning a reward or participating at all.

Meanwhile, the FTC has been busy. Wellness apps and platforms operating outside HIPAA's reach have faced enforcement for quietly sharing sensitive health inputs with ad networks and analytics trackers through pixels embedded on their sign-up and check-in pages.

  • Audit every vendor's website and app for tracking pixels and third-party SDKs before you sign a contract following detailed guidance in the HIPAA Compliant Website Workflow.
  • Confirm the vendor's privacy policy matches what actually happens to the data, not just what the marketing page claims.

Your Compliance Checklist, Step by Step

Turning all of this into practice comes down to five moves, in order.

  1. Classify the program. Run the diagnostic above, document the answer, and file it with your plan records.
  2. Calculate and adopt. If plan-linked, calculate your reward cap, build in a reasonable alternative standard, and update plan documents and sponsor certifications accordingly.
  3. Contract your vendors. Require a BAA wherever PHI is involved, scan for tracking pixels and third-party SDKs regardless of HIPAA status, and insist on encryption and access controls in writing.
  4. Communicate clearly. Draft plan notices that spell out the reasonable alternative standard using model language from EBSA guidance, and make sure your incentive communications don't imply participation is mandatory.
  5. Monitor continuously. Set up quarterly reporting, a breach-notification trigger list, and a clear escalation path to legal counsel the moment something looks off.

Pro Tip: Put a calendar reminder on step five. Compliance gaps rarely show up during the annual audit, they show up in the six months between audits when nobody's watching the vendor relationship.

How Hadaco Builds HIPAA Awareness Into Program Design

Hadaco integrates with your existing benefit plans instead of replacing them, which keeps the compliance boundaries you already have in place intact rather than forcing a redesign. Programs address chronic disease management, preventive care, and engagement with structured data governance from the start, not bolted on after a legal review flags a problem.

For programs that touch PHI, Hadaco operates with the separation and access controls OCR guidance calls for. For programs outside HIPAA's reach, the same discipline applies to third-party sharing and vendor accountability, closing the gap that has drawn FTC attention elsewhere in the industry.

  • No upfront fees, with performance tied to measurable outcomes.
  • Companies typically see average savings per employee in year one, though exact amounts vary by organization.
  • Quarterly reporting gives HR and legal a documented paper trail, not just a year-end summary.
PointDetails
Plan-linked programs carry PHI riskTreat biometric or plan-tied wellness data as PHI and restrict employer access accordingly.
Reward caps are calculated, not guessedUse 30% of employee-only coverage cost (50% for tobacco programs) as your ceiling.
Hadaco integrates without disruptionPrograms layer onto existing plans, averaging $451 in year-one savings per employee.

Group Health Plan Wellness vs. Standalone Employer Programs

The line between a HIPAA-covered wellness program and a separate employer initiative often gets blurred in practice, even though the legal test is fairly clean on paper.

A program qualifies as part of your group health plan when it's referenced in plan documents, when participation affects premium contributions or plan design, or when the plan's third-party administrator handles enrollment and data. Once any of those conditions apply, the program inherits the plan's HIPAA obligations wholesale, including notice requirements, PHI handling rules, and business associate agreements for any vendor involved.

A separate employer program looks different structurally. It's funded directly by the employer, administered independently of the health plan, and typically pays out rewards through payroll or gift cards rather than premium adjustments. A company offering a $50 monthly stipend for a fitness app subscription, paid regardless of what health plan an employee is enrolled in (or whether they're enrolled at all), sits outside HIPAA's scope.

The tricky middle ground shows up when employers try to have it both ways: a program marketed as "independent" but administered through the same vendor that runs the health plan's disease management services, with data quietly flowing between the two systems. Regulators and plaintiffs' attorneys look at actual data flows and administrative overlap, not just how a program is labeled in an employee handbook. If your standalone program shares a vendor, a database, or a reporting dashboard with your group health plan, get counsel to confirm the separation is real, not just cosmetic, before you tell employees it's "not a HIPAA program."

Group Health Plan Wellness vs. Standalone Employer Programs — overview diagram

Incentive Limits and Penalty Structures Employers Need to Know

The mechanics of what you can offer and what you can withhold have specific rules attached, and they've shifted enough over the past decade that older internal policies are worth a second look.

For health-contingent programs tied to a group health plan, the reward or penalty generally cannot exceed 30% of the total cost of employee-only coverage, calculated using both employer and employee contributions combined, not just what the employee pays out of pocket. Tobacco-related programs get the higher 50% ceiling, which is why so many employers structure a separate tobacco surcharge rather than folding it into a general wellness reward.

Penalties work the same way incentives do, mathematically. A surcharge for tobacco use functions as a reward for tobacco cessation viewed from the other direction, and it has to stay within the same 50% cap. Employers sometimes miscalculate this by applying the cap to the wrong coverage tier, using family coverage costs when an employee is actually enrolled in employee-only coverage, which inflates the allowable reward beyond what regulations permit.

Participatory programs, ones that don't require hitting a health outcome, technically face no dollar cap under the wellness regulations themselves. That said, the ADA's voluntariness standard still applies if any medical information is collected, which functionally limits how large an incentive can get before the EEOC considers participation coerced rather than voluntary. There's no bright-line dollar figure from EEOC on this specific point, so conservative employers keep participatory incentives modest and document the voluntary nature of enrollment in plan materials.

Handling Biometric Data the Right Way

Biometric screenings, blood pressure, cholesterol, glucose, body mass index, generate some of the most sensitive data a wellness program touches, and how you handle it depends entirely on whether the screening is plan-linked.

When biometric results feed into a plan-based incentive, that data is PHI, full stop. It needs the same encryption, access restrictions, and business associate agreements as any other protected health information moving through your group health plan. The vendor conducting the screening should never hand raw results to HR or management; results should route only to the plan's designated administrators, consistent with the data wall model OCR recommends.

Biometric screening tools on wellness table

When biometric screening happens outside a plan context (a health fair with no premium tie-in, for instance), HIPAA doesn't govern it, but GINA still does if family history questions sneak into the intake form, and ADA voluntariness rules still apply if participation affects any employment-related benefit.

Practically, this means every employer running biometric screenings should know, in writing, exactly where those results go after collection. If you can't answer that question in one sentence, your vendor contract needs revision. Health risk assessments that pair with biometric data deserve the same scrutiny, since combining the two data sets often reveals more about an individual than either does alone, raising the privacy stakes even for programs that technically sit outside HIPAA.

Employee notification isn't optional paperwork, it's the mechanism that makes your reasonable alternative standard legally meaningful. If employees don't know an alternative exists, offering one on paper does little good.

For plan-linked programs, the notice needs to appear in plan materials, typically the summary plan description or open enrollment communications, and it must describe the reasonable alternative standard in plain language, not buried in a footnote referencing a phone number to call. EBSA's model language gives employers a starting template rather than requiring them to draft disclosure language from scratch.

Consent for standalone programs looks different, since HIPAA's authorization requirements don't apply. Instead, the practical standard is informed, voluntary opt-in: employees should see, before enrolling, what data gets collected, who receives it, and whether it's shared with anyone outside the program vendor. This is exactly where the FTC's recent enforcement actions bite hardest, companies that collected health data under vague consent language and then shared it with advertisers have faced real penalties.

Build your notice around three questions employees should be able to answer after reading it: What information will you collect? Who will see it? What happens if I don't participate? A notice that leaves any of those three unanswered isn't doing its job, regardless of whether HIPAA technically requires it.

Common HIPAA Mistakes in Wellness Programs

Most wellness program compliance failures trace back to a handful of repeated mistakes, and they're almost always avoidable with better process, not better lawyers.

The most common one: employers assume a program is automatically HIPAA-covered simply because it collects health information, then apply HIPAA-style rules unevenly or, worse, assume the opposite and skip privacy protections entirely because "it's just a wellness perk." Both assumptions skip the actual structural test.

A second frequent error involves the plan-sponsor certification. Employers receive PHI for plan administration purposes without ever amending the plan document or formally certifying the required separation between plan administrators and general management, a step OCR guidance treats as mandatory, not optional.

Third, vendor contracts frequently omit a Business Associate Agreement when one is legally required, because the wellness vendor is treated as a general service provider rather than as an entity handling PHI on the plan's behalf.

Fourth, and increasingly common as more programs go digital: nobody audits the vendor's website or app for tracking pixels, and sensitive health inputs end up flowing to ad networks without anyone at the company realizing it until an FTC complaint or state AG inquiry arrives. Recent settlements involving companies like Hims & Hers over health-data sharing practices show regulators are actively pursuing these cases, not just issuing warnings.

The EEOC's wellness program rulemaking has had a bumpy history, and that history matters for how employers should think about risk today. Earlier incentive limit rules tied to ADA and GINA were vacated by a federal court, leaving employers for several years without clear numerical guidance on what "voluntary" means in dollar terms for programs that ask disability-related questions.

The EEOC has since worked to realign its guidance with the Departments' HIPAA-based incentive limits, but the core enforcement priority hasn't changed: voluntariness remains the central test, and programs that make participation feel mandatory, through excessive penalties, opaque consequences for opting out, or pressure from managers, invite scrutiny regardless of the exact incentive dollar amount.

Litigation trends over the past several years point toward plaintiffs' attorneys pairing ADA and GINA claims with state privacy law claims when wellness data ends up shared inappropriately, rather than filing single-statute cases. This layered approach means an employer defending a wellness program complaint increasingly has to satisfy multiple legal frameworks simultaneously, not just demonstrate ADA compliance in isolation.

For HR and legal teams, the practical takeaway is that documentation matters more than it used to. Programs that can show evidence-based design rationale, a genuinely voluntary structure, and a clean data-handling record fare far better in front of the EEOC and in litigation than programs that simply point to a vendor's marketing claims about compliance.

What Actually Matters Here, and What Doesn't

Most compliance guides treat HIPAA and wellness programs as a single tangled topic, when they're really two separate risk categories wearing the same name. That confusion is the single biggest reason employers over-invest in HIPAA paperwork for programs that don't need it, while under-investing in ADA, GINA, and FTC protections for programs that do.

The conventional advice, "get a BAA and you're covered," misses that most wellness privacy failures over the past few years happened at companies operating entirely outside HIPAA's reach. The Hims & Hers and similar cases didn't involve HIPAA violations at all. They involved ordinary consumer data practices that regulators decided were deceptive.

If you take one thing from this guide, make it this: classify your program correctly first, because that single decision determines which entire body of law applies. Skip that step and you'll either over-engineer compliance for a standalone perk or, worse, leave a plan-linked program exposed. Programs built with evidence-based design and honest data governance from the start, rather than retrofitted after a complaint, hold up far better under both regulatory and legal scrutiny.

— Gene

Get a Compliance-First Population Health Program Without the Guesswork

Building a wellness program that respects HIPAA boundaries, satisfies ADA and GINA, and still moves the needle on employee health takes more than a checklist, it takes a partner who bakes compliance into the program architecture from day one. Hadaco does exactly that: population health programs that integrate with your current benefit plans, backed by evidence-based interventions for chronic disease, preventive care, and mental health, with no disruption to what's already working.

Hadaco

Every engagement runs with no upfront fees, transparent cost projections through Hadaco's savings estimator, and quarterly reporting so your legal and HR teams have a documented record, not just a year-end promise. Employers typically see $451 in average savings per employee in year one, alongside measurable gains in engagement and retention. If you're ready to see what a compliance-aware population health program could save your organization, request a consultation with Hadaco and get your savings estimate today.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources