Protected health information is the term HIPAA uses for individually identifiable health data held by covered entities — health plans, providers, and their business associates. For employers the term is the source of two opposite and equally expensive confusions: assuming HIPAA covers all health information they touch, and assuming that where HIPAA does not apply, nothing does.
Neither is true, and the boundary between them determines how different records must be handled.
HIPAA governs the employer's group health plan, not the employer as such. Data flowing within plan administration — claims information, enrollment records held by the plan, anything received from the insurer about members — is PHI, and the rules around it are strict: it may be used for plan administration only, and a firewall must separate it from employment decisions.
That firewall is the operational core. The person who sees claims data while administering the plan must not carry what they saw into hiring, promotion, or termination decisions — and the plan documents are supposed to name who may access PHI and certify the separation. In a small HR team where one person wears both hats, the firewall is a discipline rather than an org chart, which makes it harder, not optional.
The medical information employers hold in their employment capacity is generally outside HIPAA: doctors' notes for absences, leave certifications, accommodation records, workers' compensation files, drug test results, injury reports.
The mistake is concluding this data is therefore unprotected. It is governed by a different stack: disability law's separate-file and confidentiality requirements, state medical privacy statutes — California's among the strongest, with its own consent requirements for obtaining and disclosing medical information — workers' compensation confidentiality rules, and general breach notification statutes, which include medical information among their trigger categories.
The practical handling standard ends up similar on both sides of the line: stored separately from personnel files, access restricted to named administrators, supervisors told restrictions and dates but never diagnoses. What differs is the legal machinery behind it, which matters when something goes wrong.
An employer that has never traced where health data moves usually finds surprises. The common flows:
Misclassifying in either direction has costs. Treating employment-side records as HIPAA-governed leads to compliance theater aimed at the wrong statute while the actual obligations — the separate file, the state-law consent rules — go unmet. Treating plan-side data casually walks into the regime with federal enforcement behind it.
And both kinds of records share one downstream exposure: exposure of medical information triggers breach notification obligations in most states, and knowledge of an employee's condition in the wrong head creates discrimination-claim inference regardless of which statute governed the paper.
Employer's Guardian helps employers structure medical file handling, leave documentation, and the boundaries between plan and employment records through leave-of-absence management.
This article provides general educational information, not legal advice. Health information obligations vary by program structure and jurisdiction. Consult qualified counsel regarding your specific arrangements.