Data Security

Data Security Checklist for Employee Health Records: Protecting PHI End to End

carefoundryESC Team · Occupational Health & Compliance · May 15, 2025 · 8 min read

Last reviewed May 15, 2025

The immunization records, TB screens, respirator clearances, and incident reports your program collects are electronic protected health information (ePHI) whenever your program handles them on behalf of — or as part of — a HIPAA covered entity or business associate. (Some employer-held occupational-health records fall under HIPAA's employment-records exclusion and sit outside the Security Rule entirely; OSHA still governs them, so don't assume "not HIPAA" means "unregulated.") This employee health data security checklist walks the HIPAA Security Rule (45 CFR Part 164, Subpart C) spec by spec, then flags where OSHA's records-access standard adds duties HIPAA never mentions. Two rulebooks, one file cabinet.

If you've been putting off a self-audit because it feels enormous, here's the reassuring part: the regulation is already structured as a checklist. Good PHI security best practices come from reading it that way — spec by spec — rather than from a separate framework you have to invent.

What you're actually protecting

The Security Rule opens with four general requirements at 45 CFR 164.306(a). You must (1) ensure the confidentiality, integrity, and availability of all ePHI you create, receive, maintain, or transmit — the CIA triad; (2) protect against reasonably anticipated threats and hazards; (3) protect against reasonably anticipated impermissible uses and disclosures; and (4) ensure your workforce actually complies.

That third point matters for occ-health specifically. The classic breach in our world isn't a hacker — it's a supervisor asking the nurse "so what's actually wrong with him?" and getting an answer. Availability matters too: if your only copy of an exposure record lives on one laptop, a dead hard drive is a compliance failure, not just an IT headache.

The rule also builds in flexibility. Under 164.306(b), controls scale to your entity's size, complexity, and risk. A three-nurse clinic isn't held to the same infrastructure as a 2,000-bed system — but both have to do the analysis and document their reasoning.

"Addressable" does not mean optional

This is the single most misread word in HIPAA security, so read it twice. Under 164.306(d), every implementation spec is labeled either Required or Addressable. Required means do it, full stop. Addressable means you assess whether it's reasonable and appropriate, then either implement it, implement an equivalent alternative, or document in writing why it isn't reasonable and appropriate for you.

Skipping an addressable spec with no documented rationale is a finding waiting to happen. If you decide not to encrypt something, the decision and the reasoning have to exist on paper. "We didn't get to it" is not a defense.

Administrative safeguards checklist (§164.308)

The administrative safeguards are where most programs are actually weakest, because they're policy work, not technology.

Physical safeguards checklist (§164.310)

The physical safeguards are the ones auditors can see with their own eyes:

Technical safeguards checklist (§164.312)

This is the layer people picture when they hear "data security." The technical safeguards break into a clean trilogy: who can get in, prove who they are, and record what they did.

Access control and least privilege

The Access Control standard at 164.312(a) has four specs: Unique User Identification (Required) — no shared "frontdesk" login, ever; Emergency Access Procedure (Required) — a documented way in when the primary path fails; Automatic Logoff (Addressable); and Encryption/Decryption (Addressable).

Least privilege is enforced on the administrative side too, through Information Access Management in 164.308(a)(4) — Access Authorization and Access Establishment and Modification. In practice this means role-based access: a scheduler sees appointments, not lab results; a manager sees restrictions, not diagnoses. Review those roles when people change jobs, not once a year.

Prove who they are, record what they did

Person or Entity Authentication (164.312(d)) verifies the user is who they claim. Audit Controls (164.312(b)) require mechanisms that record and examine activity in systems holding ePHI. Logs you never read are just disk usage — the Information System Activity Review spec exists because someone has to look. Integrity protections and Transmission Security (Integrity Controls and Encryption, both Addressable) round out the set.

Protecting employee health information end to end means the technical spine and the human process both hold: encrypting PII at rest and writing an audit entry on every change covers the machine side, but the access-review and log-review work around it is still yours to own.

Don't forget the business associates

Your billing service, your document-shredding vendor, your cloud host — anyone who touches ePHI on your behalf needs a Business Associate Contract under 164.308(b). No BAA, no data. Inventory who has access before you're asked to.

Breach readiness and the 60-day clock

When unsecured PHI is breached, 164.404(b) requires you to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. That clock starts when the breach is discovered, not when it's confirmed or convenient. Have the notification template and the decision tree written now, while nothing's on fire.

The OSHA overlap most HIPAA checklists miss

Here's what a pure-HIPAA audit won't catch. Under 29 CFR 1910.1020, employee medical records must be kept for the duration of employment plus 30 years, and exposure records for at least 30 years. Your five-year retention policy is fine for HIPAA and badly out of compliance with OSHA.

The same standard gives employees or their designated representatives access to their records within 15 working days. And in a narrow case — a diagnosis of terminal illness or a psychiatric condition — 1910.1020(e)(2)(ii)(D) lets you restrict direct employee access while still releasing the record to a designated representative with written consent. That's a rare edge case worth flagging in your access policy so it doesn't get handled ad hoc.

How to audit your own posture

Two activities anchor everything. The Risk Analysis (164.308(a)(1)(ii)(A), Required) inventories where ePHI lives and what threatens it. The periodic Evaluation (164.308(a)(8)) re-checks that your controls still hold.

Run the audit spec by spec: walk 164.308, then 164.310, then 164.312, and for each implementation spec write down "implemented / alternative implemented / not reasonable because ___." Pull a month of audit logs and actually review them. Restore a backup and confirm it works. Document the date and who did it. That paper trail is what turns "we take security seriously" into something you can prove.

What's changing (as of mid-2025)

As of mid-2025, the biggest pending change is a proposal, not a rule. On January 6, 2025, HHS/OCR published a Notice of Proposed Rulemaking to strengthen the Security Rule; the comment period closed March 7, 2025. As proposed, it would remove the Required/Addressable distinction — making every spec required — mandate encryption of ePHI, require multi-factor authentication, and require technology asset inventories and network maps.

This is a proposed rule, not current law. The Addressable/Required framework above still governs unless and until a final rule takes effect. Building to the proposal's higher bar now — encrypt everything, turn on MFA, keep an asset inventory — means you meet today's rule and won't be scrambling if it is finalized. Confirm the final-rule status before you rely on any of it.

FAQ

Does "addressable" mean I can skip it? No. You must implement it, implement an equivalent alternative, or document why it isn't reasonable and appropriate (45 CFR 164.306(d)). Silence is a finding.

How long do I really have to keep employee health records? For HIPAA, follow your retention policy; for occupational medical records, OSHA requires duration of employment plus 30 years, and exposure records 30 years (29 CFR 1910.1020). Follow the longer duty.

How fast do I have to notify people after a breach? No later than 60 calendar days after discovery (45 CFR 164.404(b)), and without unreasonable delay before that.


Start with the Risk Analysis — it's Required, it's the foundation, and it tells you which of the boxes above actually matter for your program. If your current system can't produce a per-record audit trail or encrypt PII at rest, fix that before your next Evaluation. This article is general guidance, not legal advice; confirm current rule status and check with counsel for your facility.

See carefoundryESC in action

Generate OSHA 300/300A/301 reports, track immunizations, and manage employee health from one HIPAA-aligned system.

Request a demo →
← Back to the blog