Answer: A health plan with fewer than 50 participants that is administered by the sponsoring employer is excluded from the definition of a “group health plan” under HIPAA's administrative simplification provisions, which include the privacy and security requirements.