Does HIPAA Apply to Employers? Common Misconceptions
Quick Answer
HIPAA does not directly apply to most private employers. However, employers that provide health insurance, maintain health records, or act as business associates of covered entities may have HIPAA obligations. Small employers typically fall under ERISA regulations instead.
Myth vs. Reality
❌ Myth: All employers must follow HIPAA rules
Many employees believe their employer's handling of health information is regulated by HIPAA just like healthcare providers.
✓ Reality: HIPAA covers specific employer roles only
HIPAA applies to "covered entities" and their business associates. Most private employers are neither. However, if an employer provides its own health insurance (a self-funded plan), acts as a health plan, or contracts with health information exchanges, they may become subject to HIPAA.
❌ Myth: Employers can freely access and share employee medical records
Some employers believe they have unlimited access to health information submitted for benefits or accommodations.
✓ Reality: Employers must maintain medical record privacy
Under the ADA and state privacy laws, employers must keep medical information confidential and separate from personnel files. Even if not directly bound by HIPAA, employers are subject to other privacy regulations and must protect sensitive health data.
❌ Myth: HIPAA penalties don't apply to businesses
Employers sometimes assume HIPAA violations only concern healthcare organizations.
✓ Reality: Employers can face HIPAA penalties
If an employer qualifies as a covered entity or business associate, HIPAA violations can result in fines ranging from $100 to $50,000 per violation, with annual maximums reaching millions. Additionally, state privacy laws and data breach notification laws apply to most employers.
Understanding HIPAA and Employer Obligations
The confusion around HIPAA and employers stems from the fact that HIPAA only applies to healthcare providers, health plans, and healthcare clearinghouses. Most private employers fall outside this definition. Instead, employer obligations regarding health information are governed by:
- ERISA: Controls how employer-sponsored health plans operate and requires privacy protections
- ADA: Requires confidentiality of medical information used in reasonable accommodations
- State Privacy Laws: California CCPA, Colorado CPA, and others regulate personal information including health data
- FCRA: Governs medical information in background checks
- Data Breach Laws: Require notification if employee health data is breached
When Employers Become HIPAA Covered Entities
An employer might have HIPAA obligations if it:
- Operates a self-funded health insurance plan (processes claims internally)
- Offers a health savings account or flexible spending account
- Acts as a clearinghouse or business associate for healthcare transactions
- Provides occupational health services with electronic health records
Employer Best Practices
Even if not legally required, employers should:
- Store medical records in separate, locked files
- Limit access to HR personnel only
- Provide privacy notices to employees about data handling
- Implement data security measures for electronic health information
- Train employees on privacy compliance
Frequently Asked Questions
Q: If my employer uses a third-party health insurance company, is HIPAA involved?
A: The health insurance company is HIPAA-covered, and your employer becomes responsible as a data processor. Your employer may have contractual HIPAA obligations regarding health plan information, but differs from being a directly regulated entity.
Q: Can I sue my employer for a HIPAA violation?
A: Only if your employer qualifies as a HIPAA-covered entity or business associate. Otherwise, you may pursue claims under state privacy laws, the ADA, or contract law. Contact an employment attorney to assess your situation.
Q: Does my employer need a Business Associate Agreement (BAA)?
A: Only if your employer qualifies as a business associate. If your employer is not involved in handling protected health information on behalf of a covered entity, a BAA is not required.
Q: What should I do if my employer mishandles my health information?
A: Document the incident and contact your HR department. If unresolved, consult an employment lawyer, file a complaint with your state's attorney general, or report to the EEOC if disability-related. If HIPAA applies, you can file a complaint with HHS.
Concerned About Your Organization's Health Data Security?
Get a comprehensive security risk analysis to identify HIPAA and privacy law vulnerabilities.
Get Your Risk Analysis →