Buying Guide

Must-Have Features in Occupational Health Software for OSHA and Immunization Compliance

carefoundryESC Team · Occupational Health & Compliance · Jan 26, 2026 · 8 min read

Last reviewed Jan 26, 2026

If you run an employee health program at a hospital, clinic, or long-term-care facility, you are carrying two burdens at once: you hold protected health information (PHI) for every worker, and you answer to a stack of federal recordkeeping rules that carry real financial penalties. The occupational health software features you buy either lighten both loads or quietly add risk to them.

The trap in most vendor demos is that everything looks compliant. The way to cut through it is to stop asking "does this have OSHA reporting?" and start asking "which regulation, which form, which deadline, which retention period?" Below is the occ health software checklist I use, with each capability tied to the rule it exists to satisfy. Bring these questions to your next demo.

OSHA recordkeeping and reporting: the non-negotiables

Start here, because this is where auditors start. These are the OSHA reporting software features that separate a real system from a form printer.

The 300, 300A, and 301 forms, generated and maintained. Under OSHA's injury and illness recordkeeping standard, you must keep the OSHA 300 Log, the 300A annual summary, and the 301 Incident Report. All three (plus the privacy case list, if you keep one) have to be retained for five years following the end of the calendar year they cover (29 CFR 1904.33). Any tool can print a form. The differentiator is whether it enforces that retention window instead of letting old logs age out of a report view.

In-period updating of the 300 Log. This one trips people up. During that five-year storage period, you are required to go back and update stored 300 Logs when you discover a newly recordable case or when a case's classification changes — say, a restricted-duty case that later becomes a lost-time case (29 CFR 1904.33(b)). The 300A summary and 301 reports don't have to be updated, but the Log does. Ask the vendor to show you how a reclassified case flows back into an already-closed year. If the only answer is "you'd edit it manually," that's a gap.

Electronic submission to the ITA — with the size logic built in. The annual deadline to submit injury and illness data through OSHA's Injury Tracking Application is March 2 for the prior year's data, and the ITA accepts three channels: manual web entry, CSV upload, and API (OSHA ITA). Supporting all three is good. Knowing who submits what is better. Establishments with 250+ employees in covered industries, and 20–249 employees in Appendix A industries, submit 300A data; establishments with 100 or more employees in Appendix B industries must additionally submit case-level data from the 300 and 301 (OSHA ITA). Software that reflects those thresholds saves you from either over- or under-reporting.

Severe-event deadline alerting. A work-related fatality has to be reported to OSHA within 8 hours; an in-patient hospitalization, amputation, or loss of an eye within 24 hours, by phone (1-800-321-OSHA) or the online reporting app (29 CFR 1904.39). Those clocks start ticking at 2 a.m. on a holiday weekend as easily as at 9 a.m. on a Tuesday. A system that fires an alert the moment a qualifying event is logged is worth more than one that simply records it.

One value-add worth asking about: automated incidence-rate calculation for the 300A. The rate depends on hours worked, and hand-calculating analytical rates like DART and TCIR across establishments is where errors creep in. The 300A itself doesn't require you to compute those rates, but if the software does the arithmetic from actual hours worked, you get cleaner numbers for internal benchmarking and BLS surveys.

Immunization and exposure features

This is the half of the job that regulators scrutinize hardest in healthcare, and it's where thin immunization tracking software shows its seams.

Hepatitis B vaccine tracking under the Bloodborne Pathogens standard. For employees with occupational exposure, the Hep B vaccine must be made available at no cost within 10 working days of initial assignment (unless the worker is already immune, declines, or has a contraindication) (29 CFR 1910.1030(f)(2)(i)). Your software needs to track the offer date against the assignment date — not just whether the shot was given — and it needs to capture declinations with the signed statement.

A real Sharps Injury Log. The Bloodborne Pathogens standard requires a sharps injury log recording each percutaneous injury from a contaminated sharp, including the device type and brand, the department or work area, and an explanation of how the incident occurred (29 CFR 1910.1030(h)(5)). A generic incident field won't cut it; you want those specific data points as structured fields, feeding a post-exposure follow-up workflow.

Respirator scheduling with recurrence. The Respiratory Protection standard requires a medical evaluation before an employee is fit tested or required to use a respirator, and fit testing before initial use, whenever the facepiece changes, and at least annually thereafter (29 CFR 1910.134(e) and (f)). "At least annually" is a recurrence rule. Look for automatic re-scheduling and due/overdue queues, not a spreadsheet reminder you set yourself.

For the broader healthcare-personnel vaccine picture — seasonal influenza, MMR, varicella, Tdap, COVID-19 — you want the ability to track recommended vaccines and immunity documentation per person. Those recommendations come from CDC/ACIP rather than OSHA, and CDC revises them, so confirm the current wording directly at cdc.gov before you hard-wire a policy into your program.

Data retention: a 30-year architecture, not a 30-day one

This deserves its own line on the checklist because it's a design decision, not a setting. OSHA's access-to-records standard requires employee medical records to be preserved for the duration of employment plus 30 years, and employee exposure records for at least 30 years (29 CFR 1910.1020). Bloodborne Pathogens medical records — Hep B status, post-exposure evaluations — follow the same duration-plus-30-years rule (29 CFR 1910.1030(h)(1)(iv)). Ask the vendor point-blank: what is your retention floor, and does anything auto-purge? A tool built to tidy up after a year is the wrong tool.

Security features, mapped to the HIPAA Security Rule

Occupational health records are PHI, so your security requirements aren't preferences — they trace to the HIPAA Security Rule's technical safeguards (45 CFR 164.312). At minimum, require: access control with unique user identification, automatic logoff, a mechanism to encrypt and decrypt ePHI, audit controls that record and let you examine system activity involving ePHI, and transmission security.

Two of those — automatic logoff and the encrypt/decrypt mechanism — are technically classified as addressable implementation specifications rather than flat requirements, meaning a covered entity assesses whether each is reasonable and appropriate and documents the decision. In practice, for a health-records system there is no defensible reason to skip either, so treat them as required in your compliance software requirements. Audit controls are the one buyers overlook and regulators ask about — you want to answer "who viewed this employee's SSN, and when" without heroics. Because HHS has been updating the Security Rule, verify the current "addressable" versus "required" designations at the eCFR before you finalize a checklist.

Vendor note: carefoundryESC concentrates its design effort here — PII encrypted at rest, unique logins, audit logging, automatic logoff — precisely because these map one-to-one to §164.312. Whatever you buy, insist on the same mapping.

What non-compliance actually costs

The stakes aren't abstract. Effective January 15, 2026, OSHA's maximum civil penalties are $16,550 per serious or other-than-serious violation, $165,514 per willful or repeated violation, and $16,550 per day beyond the abatement date for failure-to-abate (OSHA Penalties). Those are federal maximums; State Plan states set their own structures, so check yours. Against numbers like that, the recordkeeping features above earn their keep the first time they catch a misclassified case before an inspector does.

FAQ

Which features are truly non-negotiable? The 300/300A/301 forms with enforced 5-year retention and in-period updating, ITA electronic submission, and the HIPAA §164.312 technical safeguards. Everything else is important; these are disqualifying if missing.

What OSHA reporting should the software automate? Form generation, incidence-rate math from actual hours, ITA submission across all three channels, and deadline alerting for the 8-hour/24-hour severe-event clocks.

What immunization and exposure features matter most? Hep B offer-versus-assignment date tracking with declination capture, a structured Sharps Injury Log, respirator medical-evaluation and fit-test recurrence, and per-person tracking of recommended HCP vaccines and immunity documentation.

How long must records be kept? Injury logs for five years; medical records for duration of employment plus 30 years; exposure records for at least 30 years. Confirm your software never auto-purges within those windows.


Compliance rules change. Verify every requirement above against current OSHA and CDC guidance at osha.gov and cdc.gov, and consult counsel before acting.

Want to see how carefoundryESC maps to each citation on this checklist? Bring these questions to a demo and hold every vendor — us included — to the same standard.

See carefoundryESC in action

Generate OSHA 300/300A/301 reports, track immunizations, and manage employee health from one HIPAA-aligned system.

Request a demo →
← Back to the blog