HR's Guide to HIPAA Compliance

Notice: No webinar is currently available in this series.

This webinar is not currently available, new dates coming soon.

Frequently Asked Questions

HIPAA—the Health Insurance Portability and Accountability Act—governs how protected health information (PHI) is collected, stored, and shared. For HR professionals, HIPAA compliance is relevant in several specific contexts. HR handles sensitive health data in connection with employer-sponsored group health plans, making the organization a 'plan sponsor' subject to HIPAA's privacy rules. HR also receives medical information during FMLA requests, workers' compensation claims, ADA accommodation processes, and return-to-work medical clearances. While HIPAA doesn't directly regulate general employment files, HR must maintain strict confidentiality of all health-related employee information and store medical records separately from personnel files as required by the ADA. Understanding HIPAA's scope—what it covers, who it applies to, and where HR's obligations begin and end—is the first step toward compliant practices that protect both employees and the organization from significant legal and regulatory exposure.
HR professionals regularly receive medical information through multiple channels, and proper handling is critical for HIPAA and ADA compliance. Medical documentation—such as doctor's notes, FMLA certifications, disability accommodation requests, and drug test results—must be stored in confidential medical files that are physically and electronically separate from regular personnel files. Access should be strictly limited to those with a legitimate need to know: HR managers, direct supervisors only when necessary for work restrictions, and benefits administrators. Verbal disclosures must be made in private settings to prevent unauthorized exposure. When sharing health information with third parties—insurance carriers, EAP providers, or occupational health vendors—data sharing agreements must be in place. HR should document when health information is shared, with whom, and under what authorization. Regular training for HR staff on medical information handling reduces the risk of inadvertent disclosures that expose the organization to significant legal liability.
Common HIPAA-related violations in HR settings include improper disclosure of employee medical information, failure to store medical records separately from personnel files, sharing health details with supervisors beyond what is operationally necessary, and inadequate security for electronic medical records. Discussing an employee's medical condition in a common area or via unsecured email constitutes a disclosure violation. Allowing managers unrestricted access to full medical files when only work restriction information is needed is also a frequent error. Prevention starts with documented policies: a clear medical information handling policy, secure storage protocols, and mandatory staff training at hire and annually thereafter. HR should conduct periodic audits of who has accessed medical records and for what purpose. When health plan administration is in-house, additional HIPAA administrative safeguard requirements apply. Proactive compliance reduces the risk of OCR investigations, significant penalties, and reputational harm from perceived employee privacy violations.
HIPAA, FMLA, and ADA frequently intersect in HR, and navigating their interplay requires understanding each law's distinct requirements. FMLA requires employees to provide medical certification supporting a serious health condition, but HIPAA governs how HR handles that medical information—it must be kept confidential and stored separately from personnel records. ADA requires HR to engage in an interactive process to determine reasonable accommodations, which may involve medical documentation. While ADA doesn't prohibit this documentation, HIPAA governs its protection. All three laws reflect the principle of minimum necessary information—HR should only collect and access health information needed for the specific employment purpose at hand. Supervisors may be informed of work restrictions without learning the underlying diagnosis. HR professionals who understand these overlapping frameworks can design processes that satisfy all three laws simultaneously—protecting employees' medical privacy while meeting the organization's operational and legal obligations.
HIPAA training in the HR context should be role-specific and practical. HR staff who handle medical files, benefits administration, or leave management need comprehensive training on privacy rules, safeguard requirements, and breach reporting obligations. Managers and supervisors need targeted instruction on what they can and cannot ask about employee health conditions, how to handle voluntary medical disclosures appropriately, and when to involve HR rather than acting independently. Training should use realistic scenarios: what to do when an employee discloses a serious illness, how to communicate about medical leave without sharing diagnosis details, and how to document accommodation discussions without capturing unnecessary medical information. Annual refresher training keeps staff current on regulatory updates. Organizations with group health plans should also train plan administrators on HIPAA Privacy Rule requirements specific to health plan sponsors. Documented training records demonstrate due diligence in compliance audits and help establish good-faith defense in any enforcement proceedings.