US Privacy and Employee Records
The United States has no single federal privacy law covering employee data. Instead there is a patchwork: a growing set of state comprehensive privacy laws, plus specific federal rules that bite hard on exactly the kind of data a health and safety system holds — injury and medical information.
This page is not legal advice. Privacy obligations vary significantly by state and by the nature of your workforce.
The most important rule: ADA medical confidentiality
Section titled “The most important rule: ADA medical confidentiality”If you take one thing from this page, take this. Under the Americans with Disabilities Act (and its regulations at 29 CFR 1630.14), employee medical information must be kept confidential and stored separately from general personnel files.
This applies to information obtained from medical examinations and inquiries, and it is generally read broadly to cover injury and illness information about identified individuals.
Access is limited to narrow categories:
- Supervisors and managers may be told about necessary restrictions on work duties and necessary accommodations
- First aid and safety personnel may be told if the condition might require emergency treatment
- Government officials investigating ADA compliance must be given relevant information on request
The practical consequence for a health and safety system: injury records containing medical detail should not be casually visible to everyone in the organisation. Think about who can see what before you put diagnoses, treatment detail, or medical restrictions into a free-text field.
A common misconception: HIPAA usually does not apply
Section titled “A common misconception: HIPAA usually does not apply”Employers frequently assume HIPAA governs their injury records. It generally does not.
HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers who transmit health information electronically. Employment records held by an employer in its capacity as an employer are expressly excluded from HIPAA’s definition of protected health information.
Where HIPAA can become relevant is if your organisation also administers a group health plan, in which case the plan is a covered entity and must be kept separate from employment functions. And if you are a healthcare provider, HIPAA applies to your patients — but your own employees’ injury records are still employment records.
The confidentiality obligation you are actually under is the ADA’s, plus any applicable state law — not HIPAA.
OSHA 1910.1020 — access to exposure and medical records
Section titled “OSHA 1910.1020 — access to exposure and medical records”This standard gives employees, their designated representatives, and OSHA a right of access to two categories of record:
- Employee exposure records — monitoring results for toxic substances or harmful physical agents, biological monitoring, and safety data sheets
- Employee medical records — records concerning the health status of an employee, made or maintained by a physician, nurse, or other health care personnel
Retention periods
Section titled “Retention periods”| Record type | Retention |
|---|---|
| Employee exposure records | 30 years |
| Employee medical records | Duration of employment plus 30 years |
| Material safety data sheets / chemical identity records | 30 years (may be satisfied by other means) |
| First-aid records of one-time treatment for minor injuries, kept on site | Not subject to the 30-year rule |
| Health insurance claims records maintained separately | Not covered |
Employees separated for less than one year need not have their medical records kept for the full period in some cases — check the standard.
Response time
Section titled “Response time”You must provide access within 15 working days of a request. If you cannot, you must state the reason and the earliest date access will be provided.
You must also inform employees annually of the existence, location, and availability of these records, who maintains them, and their right of access.
Recordkeeping privacy — 1904.29
Section titled “Recordkeeping privacy — 1904.29”Separate from the ADA, OSHA’s recordkeeping standard has its own confidentiality rule. Certain privacy-concern cases must be logged without the employee’s name, with a separate confidential list held elsewhere. See OSHA Recordkeeping for the full list — it covers injuries to intimate body parts, sexual assault, mental illness, HIV, hepatitis, tuberculosis, and contaminated needlesticks.
You must also withhold descriptive information that could identify an employee when you release the 300 log to anyone other than a government representative or an employee exercising their access rights.
The state privacy patchwork
Section titled “The state privacy patchwork”There is no federal comprehensive privacy statute. Instead, a growing number of states have enacted their own. The most significant for employers:
California — CCPA / CPRA
Section titled “California — CCPA / CPRA”California is the outlier: its privacy law applies to employee and job applicant personal information, where most other state laws exempt it. Covered employers must provide notice at collection, honour rights of access, correction, and deletion, and handle sensitive personal information — which includes health data — with additional care.
Whether you are covered depends on thresholds around revenue and the volume of personal information handled. Check current thresholds; they have been amended more than once.
Other states
Section titled “Other states”Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and around a dozen more have comprehensive privacy laws in force or coming into force. Most exempt data processed in an employment context, which limits their impact on a health and safety system — but the roster and the exemptions change, so confirm the position in the states where you operate.
Breach notification
Section titled “Breach notification”All 50 states have data breach notification laws. Requirements, deadlines, and triggers differ. If you suffer a breach involving employee personal data, your obligations depend on where the affected people live, not where you are.
Practical guidance for SteadyOn
Section titled “Practical guidance for SteadyOn”Be deliberate about what goes in free-text fields. SteadyOn’s incident description, investigation notes, and controls fields are free text and visible to anyone with access to the record. A diagnosis, a treatment detail, or a medical restriction placed there is medical information sitting in a general-access field.
A workable convention:
- Record the facts of the event in the incident — what happened, where, when, what was being done
- Keep medical detail in an attachment with restricted circulation, or outside SteadyOn in your confidential medical file
- Record what the organisation needs to act on — a work restriction, an accommodation — without recording the underlying condition
Use roles and permissions. SteadyOn’s roles (owner, admin, member) control who can see and change records. Review who has admin access, and remember that everyone in the organisation can see incidents.
Attachments carry the same duty. A photograph of an injury, a medical certificate, or a treatment note uploaded as an attachment is medical information. The same confidentiality applies.
The audit trail is your friend here. The Log records who accessed and changed what, which is exactly what you want if a question later arises about who saw a confidential record.
How SteadyOn helps
Section titled “How SteadyOn helps”| Requirement | SteadyOn module |
|---|---|
| Restricting who can administer records | Roles and permissions (owner / admin / member) |
| A record of who changed what and when | The Log page + per-entity Log tab |
| Keeping medical documents separate from general records | Documents, with attachments held against the specific record |
| Exposure monitoring records | Documents — with the 30-year retention noted |
| Annual notification of record access rights | Actions — a recurring annual action |
| Data export on request | CSV export from any list |
| Injury records to support access requests | Incidents |
Where to go next
Section titled “Where to go next”- OSHA Recordkeeping — privacy-concern cases on the 300 log
- First Aid and Medical Services — first-aid records and their retention
- Roles and Permissions — controlling access within SteadyOn