Is employee health information in HR files protected health information?

Usually not. HIPAA's definition of protected health information excludes employment records a covered entity holds in its role as employer, and most employers are not covered entities at all. Employee health details in HR files are still protected by disability, leave and state privacy laws, so companies keep them out of any data license.

The short answer

Employee health information in an HR file is usually not PHI. HIPAA protects health information held by covered entities (health plans, health care clearinghouses and providers that conduct standard transactions electronically) and their business associates. The Privacy Rule's definition of protected health information also carves out employment records that a covered entity holds in its role as employer. A manufacturer, software company or logistics business keeping a doctor's note in a personnel file is not handling PHI.

Two qualifications matter. The group health plan an employer sponsors is itself a covered entity, so claims and enrollment data held by or for the plan can be PHI. And not PHI does not mean unprotected: other federal and state laws restrict how employers collect, store and share medical information. The definition sits in HIPAA's general definitions at 45 CFR 160.103. This page links no primary text for it, so read the current regulation with counsel rather than relying on a summary.

Where does employee health information sit, and which rules apply?

RecordUsual homeHIPAA status in the employer's handsOther rules to check
Doctor's note for sick leaveHR file or leave systemEmployment record, not PHIDisability and leave laws; state sick-leave rules
Medical certification for family or medical leaveLeave management systemEmployment recordFederal leave rules on confidential, separate files
Post-offer or fitness-for-duty exam resultsSeparate medical fileEmployment recordFederal disability law confidentiality
Accommodation requests and supporting documentsHR case systemEmployment recordFederal disability law; state law
Group health plan claims and enrollment dataInsurer, third-party administrator or plan filesCan be PHI held by the planHIPAA; plan sponsor access is limited
Workers' compensation claim fileInsurer and HRGenerally outside HIPAA in the employer's handsState workers' compensation law
Wellness program resultsWellness vendorDepends on whether the program is part of the group health planHIPAA if plan-based; genetic information rules

Healthcare employers are the tricky case. When a hospital treats one of its own nurses, the treatment record is PHI held by the hospital as a provider; the same nurse's leave certification in the HR file is an employment record. The two live in different systems for a reason, and HR generally needs the employee's authorization to use the clinical record for employment purposes.

Which other laws protect employee health information?

  • Federal disability law. Medical information an employer obtains through exams or inquiries must be kept confidential and stored apart from the general personnel file, with narrow exceptions such as telling supervisors about necessary accommodations.
  • Genetic information rules. Federal law restricts employers from requesting or using genetic information, including family medical history, and requires confidentiality for what they do hold.
  • Family and medical leave rules. Medical certifications and related records are kept as confidential medical records in separate files.
  • California privacy law. The California Consumer Privacy Act gives consumers, a group that now includes a covered business's California workforce, rights that include limiting the use of sensitive personal information, and health information falls in that category. California also has a medical-information confidentiality statute with provisions aimed at employers.
  • Other states. Several states add their own medical-privacy or biometric rules for employers. Rules vary by state; check with employment counsel.

Why licenses exclude HR health information anyway

Whether or not a file is PHI, it has no place in an AI training license. AI labs and data buyers want records of how work gets done: tickets, approvals, project histories, decisions and outcomes. A personnel file's health content adds legal exposure and almost nothing to that picture. SourceX treats datasets made up mainly of PHI, with no HIPAA authorization or de-identification, as a red flag, and it settles exclusion and redaction rules with the company before any processing starts. For the separate question of training AI on PHI held by providers and plans, see HIPAA and AI training data.

The practical problem is that health details leak outside HR systems. A manager forwards a doctor's note by email, a chat thread discusses someone's surgery dates, a shared drive keeps old accommodation forms. A data map built for privacy compliance is the fastest way to find those pockets before an inventory is built.

The HR health-information sweep

Work through this list before the company completes its data inventory.

  • List every system that stores employee health information: HRIS, leave management, benefits portal, wellness vendor, occupational health.
  • Mark group health plan and third-party administrator data as PHI and out of scope.
  • Search email, chat and shared drives for doctor's notes, leave certifications and accommodation forms, and agree an exclusion or redaction rule for each pocket.
  • Check whether any part of the business is itself a covered entity or business associate, as clinics, labs, billing firms and health plans are.
  • Confirm which state laws apply to the workforce, starting with California staff and the notice they received; a California employee privacy notice template shows what that notice should cover.
  • Record each exclusion decision in the inventory so buyers can see what was left out and why.

Monitoring software can also capture health details on screen; the guide to keystroke and screen monitoring covers that separate problem.

Questions to ask your counsel

  1. Is any part of our business a covered entity or business associate, and which systems hold PHI as a result?
  2. Who can access group health plan information, and is it walled off from HR decisions?
  3. Where do exam, leave and accommodation records live, and are they separate from personnel files?
  4. Which state medical-privacy or employee-privacy laws apply to our workforce?
  5. Which exclusion and redaction rules should apply before any records are licensed?

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Next step

Partners who advise employers can test a company's fit with the company fit checker, then read how it works to see where exclusions are decided. When a company looks promising, register as a partner and make the introduction, or have the owner apply at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does HIPAA apply to a self-insured employer's health plan?

Yes, to the plan. A self-insured group health plan is a covered entity even though the employer sponsors it. The employer, acting as plan sponsor, can receive PHI from the plan only under conditions set in the plan documents, and it may not use that information for employment decisions. HR teams should keep plan administration separate from personnel work and ask benefits counsel to confirm the setup.

Can an employer ask for a doctor's note without violating HIPAA?

HIPAA does not stop an employer from asking. It governs what the health care provider may disclose, which is why providers ask the employee to authorize release or hand the note over themselves. Whether the request is appropriate is a separate question under disability, leave and state law, which limit what employers may ask and require confidential handling of the answer.

Is a hospital employee's own medical record PHI?

If the hospital treated the employee as a patient, that treatment record is PHI held by the hospital in its role as a provider, and HR generally needs the employee's authorization to use it for employment purposes. Documents the employee hands to HR, such as a leave certification, become employment records in the HR file and fall outside the PHI definition.

Can de-identified HR health data be licensed for AI training?

In practice it is left out. Even with identifiers removed, HR health information adds little to the work records AI buyers value and keeps legal risk in the dataset. Companies that license data usually exclude HR, leave, benefits and occupational health systems entirely, and agree redaction rules for any health details found in email, chat or shared drives.

Are workers' compensation files protected by HIPAA?

In the employer's hands, workers' compensation files are generally governed by state workers' compensation law rather than HIPAA, because the employer is not acting as a covered entity. Health care providers that treat the injured worker have their own HIPAA rules on what they may share for workers' compensation purposes. Rules differ by state, so check with counsel before using these files for anything beyond the claim.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment