HR News | Employer's Guardian

Protected Health Information (PHI): What Employers Need to Know

Written by Admin | Aug 18, 2026, 3:39:05 PM

Protected health information is the term HIPAA uses for individually identifiable health data held by covered entities — health plans, providers, and their business associates. For employers the term is the source of two opposite and equally expensive confusions: assuming HIPAA covers all health information they touch, and assuming that where HIPAA does not apply, nothing does.

Neither is true, and the boundary between them determines how different records must be handled.

Where HIPAA actually reaches an employer

HIPAA governs the employer's group health plan, not the employer as such. Data flowing within plan administration — claims information, enrollment records held by the plan, anything received from the insurer about members — is PHI, and the rules around it are strict: it may be used for plan administration only, and a firewall must separate it from employment decisions.

That firewall is the operational core. The person who sees claims data while administering the plan must not carry what they saw into hiring, promotion, or termination decisions — and the plan documents are supposed to name who may access PHI and certify the separation. In a small HR team where one person wears both hats, the firewall is a discipline rather than an org chart, which makes it harder, not optional.

What HIPAA does not cover - and what covers it instead

The medical information employers hold in their employment capacity is generally outside HIPAA: doctors' notes for absences, leave certifications, accommodation records, workers' compensation files, drug test results, injury reports.

The mistake is concluding this data is therefore unprotected. It is governed by a different stack: disability law's separate-file and confidentiality requirements, state medical privacy statutes — California's among the strongest, with its own consent requirements for obtaining and disclosing medical information — workers' compensation confidentiality rules, and general breach notification statutes, which include medical information among their trigger categories.

The practical handling standard ends up similar on both sides of the line: stored separately from personnel files, access restricted to named administrators, supervisors told restrictions and dates but never diagnoses. What differs is the legal machinery behind it, which matters when something goes wrong.

The flows worth mapping

An employer that has never traced where health data moves usually finds surprises. The common flows:

  • From the carrier — claims experience reports for plan management, which arrive as PHI and must stay inside the plan-administration boundary. Large-claim detail circulated to executives deciding on renewal is a recurring firewall breach nobody intended.
  • Through wellness programs — biometric screenings and health assessments, whose HIPAA status depends on how the program is structured, and which deserve the strict treatment either way
  • Through leave management — certifications held by the employer or its leave vendor, employment-side records under the disability-law rules
  • Into absence tracking — where recording reasons rather than leave types quietly converts a scheduling tool into a medical record
  • To and from vendors — the benefits administrator and leave platform, whose contracts should reflect the applicable regime: business associate agreements where HIPAA applies, service-provider and confidentiality terms where it does not

Why the distinction pays to get right

Misclassifying in either direction has costs. Treating employment-side records as HIPAA-governed leads to compliance theater aimed at the wrong statute while the actual obligations — the separate file, the state-law consent rules — go unmet. Treating plan-side data casually walks into the regime with federal enforcement behind it.

And both kinds of records share one downstream exposure: exposure of medical information triggers breach notification obligations in most states, and knowledge of an employee's condition in the wrong head creates discrimination-claim inference regardless of which statute governed the paper.

The working rules

  • Plan data stays in plan administration; name who may touch it and keep the firewall real
  • Employment-side medical records live in separate files with restricted access
  • Supervisors receive restrictions and dates, never conditions
  • Absence systems record categories, not reasons
  • Vendor contracts match the applicable regime — and get reviewed when programs change
  • All of it is encrypted at rest and included in breach response planning

Employer's Guardian helps employers structure medical file handling, leave documentation, and the boundaries between plan and employment records through leave-of-absence management.

This article provides general educational information, not legal advice. Health information obligations vary by program structure and jurisdiction. Consult qualified counsel regarding your specific arrangements.