OSHA Compliance

OSHA Privacy Concern Cases Under 1904.29: How Healthcare Employers Protect Employee Identities

carefoundryESC Team · Occupational Health & Compliance · Nov 5, 2025 · 7 min read

Last reviewed Nov 5, 2025

A nurse on your med-surg floor catches a needlestick during a blood draw. You record it, as you should. But when you go to enter her name on the OSHA 300 Log, stop — that record is an OSHA privacy case, one of a handful where the rule tells you not to write the name at all. This trips up a lot of otherwise diligent recordkeepers, especially in hospitals and long-term care where sharps injuries and bloodborne-pathogen exposures are routine.

Here's how the privacy-concern-case rules in 29 CFR 1904.29 actually work, and the small operational habits that keep you compliant without exposing anyone.

What qualifies as a privacy concern case?

There are exactly six categories, and the list is closed. Under 1904.29(b)(7), a privacy concern case is any of these:

  1. An injury or illness to an intimate body part or the reproductive system.
  2. An injury or illness resulting from a sexual assault.
  3. Mental illnesses.
  4. HIV infection, hepatitis, or tuberculosis.
  5. Needlestick injuries and cuts from sharp objects contaminated with another person's blood or other potentially infectious material (OPIM).
  6. Other illnesses, but only if the employee voluntarily requests that their name be left off the log.

1904.29(b)(8) is explicit that this is the complete list — no other injury or illness qualifies. So a broken wrist, a back strain, a slip on a wet floor? Those get the employee's name, full stop, even when the employee would rather stay anonymous.

The distinction that matters most in a clinical setting: categories 1 through 5 are automatic. You don't wait for a request, and you don't have discretion. If it's a contaminated needlestick or a confirmed HIV, hepatitis, or TB case, it becomes a privacy concern case the moment it's recordable. Category 6 — "other illnesses" — is the only one that hinges on the employee choosing to opt out.

That answers a question we hear constantly: an HIV or hepatitis exposure becomes a privacy case automatically. The employee never has to ask.

When do I leave a name off the 300 Log?

For any of the six cases, you don't just skip the name — you replace it. Under 1904.29(b)(6), you enter the words "privacy case" in the space normally used for the employee's name. Leaving it blank reads as an incomplete record; the words "privacy case" show a reviewer you made a deliberate call.

Everything else on that line stays. Job title, date, department, the classification columns, days away or on restriction — all of it still goes on the log. The injury still shows up in your numbers; only the name is shielded.

What is a privacy case list?

If you strip names off the log, you still need a way to know who's who — for updating cases, responding to a compliance officer, or managing follow-up. That's the privacy case list.

1904.29(b)(6) requires you to keep a separate, confidential list matching each privacy case number to the employee's name, so you can update the case and give the information to the government if asked. Practically, this is a locked spreadsheet or a restricted record — something that lives well away from the posted log.

Retention runs on the same clock as the rest of your recordkeeping. Under 1904.33, you keep the 300 Log, the privacy case list (if you have one), the 300A summary, and the 301 incident reports for five years following the end of the calendar year each record covers. When you purge the log at five years, purge the matching privacy list on the same schedule — never earlier.

When a name isn't enough to protect someone

Sometimes removing the name doesn't do the job. On a 12-person unit, "reproductive system injury, day surgery, March 14" narrows things down fast. 1904.29(b)(9) gives you room here: if you reasonably believe the person could still be identified, you may use discretion in describing the injury or illness on the 300 and 301 forms. Enter enough to identify the cause and the general severity, while leaving out the intimate or private details.

You can go a step further in unusual cases. Per OSHA FAQ 29-3, you may also leave the job title, date, or location off the log when that's what it takes to protect identity — though OSHA expects this to be rare. Reach for it only when a genuine re-identification risk exists.

Who can see the names — and who can't

Authorized employees and their representatives are entitled to the log. What changes for a privacy case is only the name column.

When you share the 300 Log or the forms with people not authorized to see names, 1904.29(b)(10) requires you to remove or hide employees' names and other personally identifying information. There are narrow exceptions — auditors and consultants, workers' compensation insurers, and public-health or law-enforcement authorities — but redaction is the default posture.

HIPAA does not get you out of recording

A common misread in healthcare: "We're a covered entity, so HIPAA lets us skip this on the log." It doesn't. OSHA's August 2, 2004 standard interpretation is clear that HIPAA does not exempt you from recording a case on the 300 Log, that employees and their representatives must have access to the complete log, and that disclosure is permitted to the extent required by law. Protection comes from the privacy-case mechanism in 1904.29; HIPAA has no bearing on what lands on the log.

Pair this with 1904.8: work-related contaminated needlesticks and sharps cuts must be recorded, and your sharps injury log must be maintained in a way that protects the injured employee's confidentiality. So a contaminated sharps injury triggers both obligations at once — record it under 1904.8 and enter it as a privacy case under 1904.29.

What's at stake if you get it wrong

Recordkeeping and posting failures carry real penalties. As of 2025, OSHA's maximums run to $16,550 per serious or other-than-serious violation and $165,514 per willful or repeated violation, with failure-to-abate assessed at $16,550 per day; check OSHA's penalties page for the figures in effect when you file. And don't forget the calendar: 1904.32 requires you to post the 300A summary no later than February 1 and keep it up through April 30.

FAQ

Do I need the employee's permission to make a needlestick a privacy case? No. Contaminated needlesticks and sharps cuts fall under category 5 of 1904.29(b)(7) and are automatic. Only "other illnesses" (category 6) depend on an employee request.

Can an employee ask to keep a sprained ankle off the log? No. A sprained ankle isn't on the six-item list, and 1904.29(b)(8) makes that list exhaustive. The name goes on.

How long do I keep the privacy case list? Five years after the end of the calendar year the records cover, matching the rest of your OSHA records under 1904.33.


If you're managing this by hand across several facilities, the pieces that go wrong are usually the boring ones: a name that slipped onto the log, a privacy list that lived in the same file as the posted summary, a case purged a year early. carefoundryESC handles OSHA privacy-case tracking in line with these requirements — flagging the automatic categories and keeping the confidential case list separate from the log you print.

This article is regulatory background, not legal advice. State-plan states may impose requirements at least as stringent as federal OSHA, so confirm any state-specific rules, and consult a qualified safety or compliance professional for your program.

See carefoundryESC in action

Generate OSHA 300/300A/301 reports, track immunizations, and manage employee health from one HIPAA-aligned system.

Request a demo →
← Back to the blog