HIPAA vs. OSHA for Employee Health Records: Which Rules Apply and When
Last reviewed Oct 24, 2025
Ask almost anyone in a hospital hallway what rule protects the fit-test results, the annual TB screens, and the post-needlestick follow-ups sitting in your occupational-health office, and you'll hear the same reflex answer: "That's HIPAA." The HIPAA vs. OSHA employee health records question rarely resolves the way people expect.
It usually isn't HIPAA. For the health files an employer keeps because it employs people, HIPAA's Privacy Rule generally does not apply. A different stack of rules does — OSHA's medical-records access standard, the ADA's confidentiality requirement, plus workers' comp and FMLA. Getting this wrong isn't harmless. It leads employers to over-withhold records an employee is legally entitled to, under-protect files the ADA says must be locked away separately, or purge things decades too early. Let's sort out who actually governs what.
What HIPAA actually covers
The HIPAA Privacy Rule reaches "covered entities" and their business associates. Covered entities are a defined, narrow set: health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions (45 CFR 160.103).
Notice what's missing: employers. An organization does not become a HIPAA covered entity simply by employing people and keeping health information about them. Your hospital is absolutely a covered entity — but for its patients, in its role as a provider. That's a different hat than the one it wears when it holds its own nurses' immunization records.
The employment-records exception
This is the distinction most people miss. HIPAA's own definition of protected health information (PHI) carves out an explicit exclusion. PHI does not include individually identifiable health information found in "employment records held by a covered entity in its role as employer" (45 CFR 160.103).
The implication is larger than it first appears. Even an organization that is a covered entity — a hospital, a clinic, a long-term-care facility — holds its own employees' occupational-health files outside the HIPAA Privacy Rule. The data can be identical in content to a patient chart. What matters is the capacity in which it's held. As HR data about your workforce, it falls under the employment-records exception; as a patient record, it wouldn't.
HHS says this plainly: the Privacy Rule does not protect employment records, even when the information in them is health-related. It protects medical or health-plan records only where the individual is a patient of the provider or a member of the health plan (HHS.gov).
Where does HIPAA re-enter? At the boundaries. If a clinic treats your employee as a patient and you request that chart, the disclosure from the clinic is a HIPAA event. If your group health plan touches the data, the plan side has HIPAA obligations. The employer-held file itself, though, is governed elsewhere.
When OSHA governs instead
For most employer-held employee medical and exposure records, the operative federal standard is OSHA's 29 CFR 1910.1020, "Access to employee exposure and medical records." It defines what these records are, who can see them, and how long you keep them.
An employee medical record is a record concerning the health status of an employee, made or maintained by a physician, nurse, or other health care personnel or technician (1910.1020(c)(6)). The definition also excludes several things people mistakenly file as medical records: health-insurance claims records maintained separately; first-aid records of one-time treatment and subsequent observation of minor injuries, made on-site by someone who is not a physician and kept separately; and records of voluntary employee-assistance programs maintained separately. If you keep those genuinely separate, they sit outside the 1910.1020 medical-record obligations.
Retention: think decades, not years
This is where facilities get burned during audits. Under 1910.1020(d)(1)(i), an employee medical record must be preserved for at least the duration of employment plus 30 years. Exposure records get their own clock: at least 30 years under 1910.1020(d)(1)(ii).
A nurse who worked 25 years and then retired means her medical record lives for another 30 years after that — roughly 55 years of custody. There is one narrow carve-out: the medical record of an employee who worked less than one year need not be retained beyond the end of employment, provided you give the record to the employee on their way out (1910.1020(d)(1)(i)). For everyone with a year or more of tenure, plan for decades. Any records-retention policy that says "purge after 7 years" will quietly destroy files OSHA requires you to keep, and there is no getting them back.
Access mechanics: 15 working days
When an employee or their designated representative asks for records, you must provide access in a reasonable time, place, and manner. If you can't do it within 15 working days, you have to state the reason for the delay and the earliest date the record will be available (1910.1020(e)(1)(i)).
The first copy is free. The employer must provide a copy at no cost, provide copying facilities at no cost, or loan the record for copying (1910.1020(e)(1)(iii)). You cannot bill an employee a per-page fee for that initial copy of their own record. For additional copies of the same record, the employer may charge reasonable, non-discriminatory administrative costs (1910.1020(e)(1)(v)) — with two exceptions: no charge for an initial request to access information that has been newly added to a record, and no charge for a collective-bargaining agent's initial request for access.
Who can actually access the file
Under 1910.1020, access runs to a defined circle:
- The employee, for their own records.
- A designated representative — any individual or organization the employee gives written authorization to exercise the right of access (1910.1020(c)(3)).
- A collective-bargaining agent, which for exposure records is treated automatically as a designated representative — no written authorization needed (1910.1020(c)(3)).
- OSHA itself, in the course of enforcement.
That's the access side. Internal sharing is governed by a different rule — the ADA.
The ADA layer: keep it confidential, keep it separate
The ADA, implemented at 29 CFR 1630.14 and enforced by the EEOC, requires that employee medical information be kept confidential and maintained in files separate from personnel records. Disclosure is limited to a short list: supervisors and managers (regarding necessary work restrictions or accommodations), first-aid and safety personnel (where a condition might require emergency treatment), and government officials investigating ADA compliance (EEOC guidance).
The practical upshot: your occ-health files do not belong in the same drawer, share drive, or HRIS record as performance reviews and disciplinary notes. A manager does not get to browse an employee's medical file to satisfy curiosity — only the specific restriction or accommodation that affects the job.
Which rule applies — a quick reference
| Who holds the record, and why | Governing rule |
|---|---|
| Employer holds it as an employer (occ-health file, fit tests, TB screens) | OSHA 1910.1020 + ADA 1630.14 confidentiality |
| Same record, viewed as PHI because the employer is a covered entity | Excluded from HIPAA — employment-records exception, 45 CFR 160.103 |
| A clinic/provider treats the employee as a patient | HIPAA applies to that provider's chart (160.103) |
| A group health plan touches the data | HIPAA applies on the plan side |
What this means for a healthcare-facility occ-health program
If you run employee health at a hospital, clinic, or long-term-care facility, build your program around the rules that actually apply:
- Treat employee occ-health data under OSHA + ADA + state law — not HIPAA. Don't let "it's HIPAA" become the reason you deny an employee their own file.
- Store it separate from HR/personnel records. That's an ADA requirement, not a nicety.
- Honor the 15-working-day access request, and provide the first copy at no cost.
- Set retention to duration-of-employment + 30 years for medical records, and 30 years for exposure records. Audit your purge scripts against this before they run, and account for the under-one-year carve-out.
- Restrict internal sharing to supervisors (restrictions/accommodations only), first-aid/safety staff, and government investigators.
State law can add stricter obligations on top of this federal floor — several states impose tighter confidentiality or longer retention on health-worker records — so treat the above as the minimum, not the ceiling. This is a summary of the rules, not legal advice; loop in your counsel or compliance officer for your specific setup.
A purpose-built occupational-health system helps here, because these obligations are structural: carefoundryESC keeps employee health records separate from HR data, encrypts them at rest, and logs every access, so answering a 15-day records request or a 30-year retention audit becomes a straightforward query.
FAQ
Are employee health records covered by HIPAA? Usually not. HIPAA's PHI definition excludes health information in employment records held by an employer (45 CFR 160.103). Even a hospital — a HIPAA covered entity for its patients — holds its own employees' occ-health files outside HIPAA.
How long must I keep employee medical records? At least the duration of employment plus 30 years for medical records, and at least 30 years for exposure records (1910.1020(d)). One narrow exception: the medical record of an employee who worked less than a year need not be kept beyond employment if you provide it to the employee at termination.
Can I charge an employee to copy their own medical record? Not for the first copy — the initial copy of the record must be provided at no cost (1910.1020(e)(1)(iii)). For additional copies of the same record you may charge reasonable, non-discriminatory administrative costs (1910.1020(e)(1)(v)), except for an initial request covering newly added information or a collective-bargaining agent's initial request.
Who can access an employee's health file besides the employee? A designated representative with written authorization, a collective-bargaining agent (automatically, for exposure records), and OSHA (1910.1020(c)(3)). Internal ADA sharing is limited to supervisors, first-aid/safety personnel, and government investigators.
Not sure whether your current filing setup would survive a records request or a retention audit? Map your employee health data to the rule that actually governs it — OSHA, ADA, and state law — before an auditor asks you to.
See carefoundryESC in action
Generate OSHA 300/300A/301 reports, track immunizations, and manage employee health from one HIPAA-aligned system.
Request a demo →