Skip to main content

OCR Issues Guidance on HIPAA, COVID-19 Vaccinations, and the Workplace

Today, the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) issued guidance to help the public understand when the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule applies to disclosures and requests for information about whether a person has received a COVID-19 vaccine.

In the guidance, OCR reminds the public that the HIPAA Privacy Rule does not apply to employers or employment records. The HIPAA Privacy Rule only applies to HIPAA covered entities (health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions), and, in some cases, to their business associates.  The HIPAA Privacy Rule applies to most EMS providers but only as it relates to it’s patient’s Protect Health Information (PHI).

Today’s guidance addresses common workplace scenarios and answers questions about whether and how the HIPAA Privacy Rule applies. The Privacy Rule does not apply when an individual:

  • Is asked about their vaccination status by a school, employer, store, restaurant, entertainment venue, or another individual.
  • Asks another individual, their doctor, or a service provider whether they are vaccinated.
  • Asks a company, such as a home health agency, whether its workforce members are vaccinated.

Generally, the Privacy Rule does not regulate what information can be requested from employees as part of the terms and conditions of employment that an employer may impose on its workforce

The Privacy Rule does not prohibit a covered entity or business associate from requiring or requesting each workforce member to:

  • Provide documentation of their COVID-19 or flu vaccination to their current or prospective employer.
  • Sign a HIPAA authorization for a covered health care provider to disclose the workforce member’s COVID-19 or other vaccination record to their employer.
  • Wear a mask–while in the employer’s facility, on the employer’s property, or in the normal course of performing their duties at another location.
  • Disclose whether they have received a COVID-19 vaccine in response to queries from current or prospective patients.

OCR stated that they are issuing this guidance to help consumers, businesses, and health care entities understand when HIPAA applies to disclosures about COVID-19 vaccination status and to ensure that they have the information they need to make informed decisions about protecting themselves and others from COVID-19.

More details about the latest guidance on HIPAA, COVID-19 Vaccinations, and the Workplace may be found at https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-covid-19-vaccination-workplace/index.html.  If you have questions regarding what information you may or may not share relative to COVID-19 vaccinations, please contact the AAA for assistance.

 

COVID-19 coronavirus, Department of Health and Human Services (HHS), HIPAA, Office of Civil Rights (OCR)

Stay In Touch!

By signing up, you agree to the AAA Privacy Policy & Terms of Use