Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Compliance topic

No spam. Unsubscribe anytime.

Staff flags cybersecurity and mental-health parity compliance risks

State Employee Health Commission · January 15, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The commission was warned that cybersecurity/data breaches are considered fiduciary issues and that complying with Mental Health Parity and Addiction Equity Act rules will require non-quantitative treatment limitation analyses, contractual changes and data review by plan sponsors.

Staff told the commission that cybersecurity and data breaches are a fiduciary concern for plan sponsors and that Health and Human Services has issued guidance for HIPAA-covered entities. They also said new MHPAEA rules (if finalized) would impose substantial compliance requirements, including NQTL comparative analyses and additional data and contract language obligations.

Staff recommended plan sponsors and vendors review service-provider contracts and prepare comparative analyses to identify compliance red flags. The report emphasized that achieving parity-compliance documentation and process changes would require work across plan sponsors and vendors.