Legal scope of HIPAA versus workers' compensation
HIPAA's privacy and security rules protect individually identifiable health information handled by covered entities—healthcare providers, health plans, and their business associates. Fully insured workers' compensation plans are insurance products sold by commercial carriers, not health‑care providers or health‑plan sponsors, so they fall outside HIPAA's definition of a covered entity. Consequently, the federal privacy safeguards that apply to medical records in a hospital or a health‑maintenance organization do not automatically extend to the claims data or medical records maintained by a workers' compensation insurer.
More from this site
Keep reading the latest coverage
Regulatory framework that does apply
Workers' compensation data are instead governed by a patchwork of state statutes, the Fair Credit Reporting Act (FCRA) for background checks, and, where applicable, the General Data Protection Regulation (GDPR) for cross‑border employees. Most states require insurers to keep claim information confidential, but the standards differ widely—some mirror HIPAA‑like protections, others rely on broader privacy principles. In addition, the Employee Retirement Income Security Act (ERISA) may impose fiduciary duties on self‑insured employers, but it does not create a federal privacy rule comparable to HIPAA for fully insured carriers.
Practical implications for employers and insurers
Because HIPAA does not apply, employers cannot cite HIPAA compliance as a shield when a claim‑related data breach occurs. They must instead rely on state‑specific breach‑notification laws and contractual obligations in their insurance policies. Insurers, meanwhile, often adopt HIPAA‑style safeguards voluntarily to reassure clients and to align with industry best practices, but those measures are not mandated by federal law.
Key differences in data handling requirements
| Aspect | HIPAA‑covered entities | Fully insured workers' comp plans |
|---|---|---|
| Applicable law | 45 CFR Part 164 (Privacy & Security Rules) | State workers' comp statutes & other federal laws (e.g., FCRA) |
| Breach notification | 45 CFR 164.404 – 60‑day notification to individuals & HHS | State‑specific breach‑notification timelines, often 30‑45 days |
| Minimum safeguards | Administrative, physical, technical safeguards defined by HIPAA | Varies by state; many insurers adopt similar safeguards voluntarily |
| Enforcement | OCR civil penalties up to $1.5 million per violation | State insurance regulators; penalties differ by jurisdiction |
When HIPAA might still be relevant
If a workers' compensation claim is processed through a health‑plan sponsor—such as an employer‑provided health insurer that also administers the claim—HIPAA could apply to the portion of the record handled by that sponsor. In those hybrid situations, the data flow must be mapped to determine which entity is the covered entity for each segment of the information.
Best‑practice checklist for compliance
- Identify the legal jurisdiction(s) governing each claim.
- Confirm whether any third‑party service provider is a HIPAA‑covered entity.
- Implement state‑required breach‑notification procedures.
- Adopt HIPAA‑style safeguards voluntarily to reduce risk.
- Document contractual privacy clauses with insurers and vendors.