What HIPAA Means for Employers
Employers who handle employee health information must follow the Health Insurance Portability and Accountability Act (HIPAA). While HIPAA primarily regulates covered entities—health plans, health care providers, and their business associates—many workplace situations fall under its privacy and security rules. In the first 100 words, we answer: employers may receive limited health data for benefits administration, workplace safety, or accommodations, but must protect it, limit use, and provide employees with privacy rights.
- What HIPAA Means for Employers
- Key Definitions
- When Employers Are Directly Covered
- Common Employer Interactions with PHI
- Benefits Administration
- Workplace Injuries and Workers' Compensation
- Family and Medical Leave (FMLA) & ADA Accommodations
- Employer Obligations Under HIPAA
- Practical Steps for Compliance
- Frequently Asked Questions
- Can an employer request my entire medical record?
- Do I have a right to see my own health information held by my employer?
- What happens if a breach occurs?
- Comparison: Employer vs. Non‑Employer HIPAA Responsibilities
- Bottom Line
More from this site
Keep reading the latest coverage
Key Definitions
Understanding HIPAA starts with a few core terms:
- Covered Entity: A health plan, health care provider, or health care clearinghouse that electronically transmits PHI.
- Business Associate: A third‑party that performs services for a covered entity involving PHI (e.g., payroll processors, EHR vendors).
- Protected Health Information (PHI): Any individually identifiable health information held or transmitted by a covered entity or business associate.
When Employers Are Directly Covered
Most private‑sector employers are not covered entities, but they become covered when they:
- Offer a group health plan that includes electronic transmission of medical records.
- Act as a health care provider (e.g., on‑site clinic) that transmits PHI electronically.
In those cases, the employer must implement HIPAA's privacy, security, and breach‑notification rules just like a hospital or insurer.
Common Employer Interactions with PHI
Benefits Administration
When employees enroll in health insurance, the employer's HR or payroll system often receives enrollment forms, claims data, and eligibility confirmations. This information is considered PHI, so the employer must:
- Limit access to only those who need it for benefits processing.
- Use secure transmission (encryption, TLS) and storage.
- Provide a Notice of Privacy Practices if the employer itself is a covered entity.
Workplace Injuries and Workers' Compensation
Employers must collect medical information to process workers' compensation claims. HIPAA permits this limited disclosure, but the employer must:
- Obtain the employee's written authorization before sharing more detailed medical records.
- Retain the data only as long as necessary for the claim.
Family and Medical Leave (FMLA) & ADA Accommodations
Under the Family and Medical Leave Act and the Americans with Disabilities Act, employers may request medical certification to approve leave or accommodations. HIPAA restricts the scope of that request:
- Only information directly relevant to the leave or accommodation need be collected.
- Employers cannot request full medical histories or unrelated diagnoses.
Employer Obligations Under HIPAA
Whether the employer is a covered entity or a business associate, the following obligations apply:
- Privacy Rule: Limit uses and disclosures of PHI, provide a notice of privacy practices, and honor employee rights to access and amend their records.
- Security Rule: Implement administrative, physical, and technical safeguards (e.g., access controls, encryption, audit logs).
- Breach Notification Rule: Notify affected individuals, the Secretary of Health and Human Services, and sometimes the media within 60 days of a breach.
Practical Steps for Compliance
Employers can adopt a checklist to stay HIPAA‑compliant:
Frequently Asked Questions
Can an employer request my entire medical record?
No. Under HIPAA and related statutes, an employer may only request information directly related to a legitimate business need (e.g., confirming a disability for accommodation). Full records require a signed authorization.
Do I have a right to see my own health information held by my employer?
If the employer is a covered entity or business associate, you have the same access rights as you would with a health plan—typically a written request and a reasonable fee for copying.
What happens if a breach occurs?
The employer must notify affected employees promptly, report to HHS within 60 days, and may face civil penalties up to $50,000 per violation (adjusted for inflation). State laws may impose additional fines.
Comparison: Employer vs. Non‑Employer HIPAA Responsibilities
| Aspect | Employer (Covered Entity/BA) | Non‑Employer (No HIPAA Scope) |
|---|---|---|
| Access to PHI | Limited to job‑related purposes; must document need | Generally none; can only receive de‑identified data |
| Required Policies | Privacy & security policies, breach plan | Only standard data‑privacy policies |
| Training | HIPAA‑specific training for staff handling PHI | General privacy training |
Bottom Line
HIPAA does reach employers, but only when they handle protected health information as part of a health plan, on‑site clinic, or through a business‑associate relationship. Understanding the scope of permissible data collection, implementing robust safeguards, and maintaining clear policies are essential to avoid costly violations and to protect employee privacy.