Employers often receive employee medical information when processing accommodation requests, administering leave or determining eligibility for disability benefits. Because this information is highly sensitive, employers must understand when it can be collected and how it must be protected.
Several federal laws establish confidentiality requirements, including the Americans with Disabilities Act (ADA), Family and Medical Leave Act (FMLA), Genetic Information Nondiscrimination Act (GINA) and, in limited situations, Health Insurance Portability and Accountability Act (HIPAA). While HIPAA is commonly associated with medical privacy, it generally applies to employer-sponsored health plans rather than employment records.
To help protect employee medical information, employers should:
- Keep medical records separate from personnel files.
- Limit access to authorized employees.
- Secure both paper and electronic records.
- Train staff on confidentiality requirements.
- Respond promptly to any suspected privacy breach.
Employers should also be aware that state and local laws may impose additional confidentiality requirements. When multiple laws apply, following the strictest standard can help reduce compliance risks.
If you have questions about employee medical information confidentiality or other workplace compliance issues, contact The MBA’s HR & Legal Services team at hr@mbausa.org or 814-833-3200.
This article was originally written for Business Magazine and can be read here.