Skip to content

US Privacy and Employee Records

The United States has no single federal privacy law covering employee data. Instead there is a patchwork: a growing set of state comprehensive privacy laws, plus specific federal rules that bite hard on exactly the kind of data a health and safety system holds — injury and medical information.

This page is not legal advice. Privacy obligations vary significantly by state and by the nature of your workforce.


The most important rule: ADA medical confidentiality

Section titled “The most important rule: ADA medical confidentiality”

If you take one thing from this page, take this. Under the Americans with Disabilities Act (and its regulations at 29 CFR 1630.14), employee medical information must be kept confidential and stored separately from general personnel files.

This applies to information obtained from medical examinations and inquiries, and it is generally read broadly to cover injury and illness information about identified individuals.

Access is limited to narrow categories:

  • Supervisors and managers may be told about necessary restrictions on work duties and necessary accommodations
  • First aid and safety personnel may be told if the condition might require emergency treatment
  • Government officials investigating ADA compliance must be given relevant information on request

The practical consequence for a health and safety system: injury records containing medical detail should not be casually visible to everyone in the organisation. Think about who can see what before you put diagnoses, treatment detail, or medical restrictions into a free-text field.


A common misconception: HIPAA usually does not apply

Section titled “A common misconception: HIPAA usually does not apply”

Employers frequently assume HIPAA governs their injury records. It generally does not.

HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers who transmit health information electronically. Employment records held by an employer in its capacity as an employer are expressly excluded from HIPAA’s definition of protected health information.

Where HIPAA can become relevant is if your organisation also administers a group health plan, in which case the plan is a covered entity and must be kept separate from employment functions. And if you are a healthcare provider, HIPAA applies to your patients — but your own employees’ injury records are still employment records.

The confidentiality obligation you are actually under is the ADA’s, plus any applicable state law — not HIPAA.


OSHA 1910.1020 — access to exposure and medical records

Section titled “OSHA 1910.1020 — access to exposure and medical records”

This standard gives employees, their designated representatives, and OSHA a right of access to two categories of record:

  • Employee exposure records — monitoring results for toxic substances or harmful physical agents, biological monitoring, and safety data sheets
  • Employee medical records — records concerning the health status of an employee, made or maintained by a physician, nurse, or other health care personnel
Record typeRetention
Employee exposure records30 years
Employee medical recordsDuration of employment plus 30 years
Material safety data sheets / chemical identity records30 years (may be satisfied by other means)
First-aid records of one-time treatment for minor injuries, kept on siteNot subject to the 30-year rule
Health insurance claims records maintained separatelyNot covered

Employees separated for less than one year need not have their medical records kept for the full period in some cases — check the standard.

You must provide access within 15 working days of a request. If you cannot, you must state the reason and the earliest date access will be provided.

You must also inform employees annually of the existence, location, and availability of these records, who maintains them, and their right of access.


Separate from the ADA, OSHA’s recordkeeping standard has its own confidentiality rule. Certain privacy-concern cases must be logged without the employee’s name, with a separate confidential list held elsewhere. See OSHA Recordkeeping for the full list — it covers injuries to intimate body parts, sexual assault, mental illness, HIV, hepatitis, tuberculosis, and contaminated needlesticks.

You must also withhold descriptive information that could identify an employee when you release the 300 log to anyone other than a government representative or an employee exercising their access rights.


There is no federal comprehensive privacy statute. Instead, a growing number of states have enacted their own. The most significant for employers:

California is the outlier: its privacy law applies to employee and job applicant personal information, where most other state laws exempt it. Covered employers must provide notice at collection, honour rights of access, correction, and deletion, and handle sensitive personal information — which includes health data — with additional care.

Whether you are covered depends on thresholds around revenue and the volume of personal information handled. Check current thresholds; they have been amended more than once.

Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and around a dozen more have comprehensive privacy laws in force or coming into force. Most exempt data processed in an employment context, which limits their impact on a health and safety system — but the roster and the exemptions change, so confirm the position in the states where you operate.

All 50 states have data breach notification laws. Requirements, deadlines, and triggers differ. If you suffer a breach involving employee personal data, your obligations depend on where the affected people live, not where you are.


Be deliberate about what goes in free-text fields. SteadyOn’s incident description, investigation notes, and controls fields are free text and visible to anyone with access to the record. A diagnosis, a treatment detail, or a medical restriction placed there is medical information sitting in a general-access field.

A workable convention:

  • Record the facts of the event in the incident — what happened, where, when, what was being done
  • Keep medical detail in an attachment with restricted circulation, or outside SteadyOn in your confidential medical file
  • Record what the organisation needs to act on — a work restriction, an accommodation — without recording the underlying condition

Use roles and permissions. SteadyOn’s roles (owner, admin, member) control who can see and change records. Review who has admin access, and remember that everyone in the organisation can see incidents.

Attachments carry the same duty. A photograph of an injury, a medical certificate, or a treatment note uploaded as an attachment is medical information. The same confidentiality applies.

The audit trail is your friend here. The Log records who accessed and changed what, which is exactly what you want if a question later arises about who saw a confidential record.


RequirementSteadyOn module
Restricting who can administer recordsRoles and permissions (owner / admin / member)
A record of who changed what and whenThe Log page + per-entity Log tab
Keeping medical documents separate from general recordsDocuments, with attachments held against the specific record
Exposure monitoring recordsDocuments — with the 30-year retention noted
Annual notification of record access rightsActions — a recurring annual action
Data export on requestCSV export from any list
Injury records to support access requestsIncidents