Is employee health information in HR files protected health information?
Usually not. HIPAA's definition of protected health information excludes employment records a covered entity holds in its role as employer, and most employers are not covered entities at all. Employee health details in HR files are still protected by disability, leave and state privacy laws, so companies keep them out of any data license.
The short answer
Employee health information in an HR file is usually not PHI. HIPAA protects health information held by covered entities (health plans, health care clearinghouses and providers that conduct standard transactions electronically) and their business associates. The Privacy Rule's definition of protected health information also carves out employment records that a covered entity holds in its role as employer. A manufacturer, software company or logistics business keeping a doctor's note in a personnel file is not handling PHI.
Two qualifications matter. The group health plan an employer sponsors is itself a covered entity, so claims and enrollment data held by or for the plan can be PHI. And not PHI does not mean unprotected: other federal and state laws restrict how employers collect, store and share medical information. The definition sits in HIPAA's general definitions at 45 CFR 160.103. This page links no primary text for it, so read the current regulation with counsel rather than relying on a summary.
Where does employee health information sit, and which rules apply?
| Record | Usual home | HIPAA status in the employer's hands | Other rules to check |
|---|---|---|---|
| Doctor's note for sick leave | HR file or leave system | Employment record, not PHI | Disability and leave laws; state sick-leave rules |
| Medical certification for family or medical leave | Leave management system | Employment record | Federal leave rules on confidential, separate files |
| Post-offer or fitness-for-duty exam results | Separate medical file | Employment record | Federal disability law confidentiality |
| Accommodation requests and supporting documents | HR case system | Employment record | Federal disability law; state law |
| Group health plan claims and enrollment data | Insurer, third-party administrator or plan files | Can be PHI held by the plan | HIPAA; plan sponsor access is limited |
| Workers' compensation claim file | Insurer and HR | Generally outside HIPAA in the employer's hands | State workers' compensation law |
| Wellness program results | Wellness vendor | Depends on whether the program is part of the group health plan | HIPAA if plan-based; genetic information rules |
Healthcare employers are the tricky case. When a hospital treats one of its own nurses, the treatment record is PHI held by the hospital as a provider; the same nurse's leave certification in the HR file is an employment record. The two live in different systems for a reason, and HR generally needs the employee's authorization to use the clinical record for employment purposes.
Which other laws protect employee health information?
- Federal disability law. Medical information an employer obtains through exams or inquiries must be kept confidential and stored apart from the general personnel file, with narrow exceptions such as telling supervisors about necessary accommodations.
- Genetic information rules. Federal law restricts employers from requesting or using genetic information, including family medical history, and requires confidentiality for what they do hold.
- Family and medical leave rules. Medical certifications and related records are kept as confidential medical records in separate files.
- California privacy law. The California Consumer Privacy Act gives consumers, a group that now includes a covered business's California workforce, rights that include limiting the use of sensitive personal information, and health information falls in that category. California also has a medical-information confidentiality statute with provisions aimed at employers.
- Other states. Several states add their own medical-privacy or biometric rules for employers. Rules vary by state; check with employment counsel.
Why licenses exclude HR health information anyway
Whether or not a file is PHI, it has no place in an AI training license. AI labs and data buyers want records of how work gets done: tickets, approvals, project histories, decisions and outcomes. A personnel file's health content adds legal exposure and almost nothing to that picture. SourceX treats datasets made up mainly of PHI, with no HIPAA authorization or de-identification, as a red flag, and it settles exclusion and redaction rules with the company before any processing starts. For the separate question of training AI on PHI held by providers and plans, see HIPAA and AI training data.
The practical problem is that health details leak outside HR systems. A manager forwards a doctor's note by email, a chat thread discusses someone's surgery dates, a shared drive keeps old accommodation forms. A data map built for privacy compliance is the fastest way to find those pockets before an inventory is built.
The HR health-information sweep
Work through this list before the company completes its data inventory.
- List every system that stores employee health information: HRIS, leave management, benefits portal, wellness vendor, occupational health.
- Mark group health plan and third-party administrator data as PHI and out of scope.
- Search email, chat and shared drives for doctor's notes, leave certifications and accommodation forms, and agree an exclusion or redaction rule for each pocket.
- Check whether any part of the business is itself a covered entity or business associate, as clinics, labs, billing firms and health plans are.
- Confirm which state laws apply to the workforce, starting with California staff and the notice they received; a California employee privacy notice template shows what that notice should cover.
- Record each exclusion decision in the inventory so buyers can see what was left out and why.
Monitoring software can also capture health details on screen; the guide to keystroke and screen monitoring covers that separate problem.
Questions to ask your counsel
- Is any part of our business a covered entity or business associate, and which systems hold PHI as a result?
- Who can access group health plan information, and is it walled off from HR decisions?
- Where do exam, leave and accommodation records live, and are they separate from personnel files?
- Which state medical-privacy or employee-privacy laws apply to our workforce?
- Which exclusion and redaction rules should apply before any records are licensed?
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Next step
Partners who advise employers can test a company's fit with the company fit checker, then read how it works to see where exclusions are decided. When a company looks promising, register as a partner and make the introduction, or have the owner apply at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does HIPAA apply to a self-insured employer's health plan?
Yes, to the plan. A self-insured group health plan is a covered entity even though the employer sponsors it. The employer, acting as plan sponsor, can receive PHI from the plan only under conditions set in the plan documents, and it may not use that information for employment decisions. HR teams should keep plan administration separate from personnel work and ask benefits counsel to confirm the setup.
Can an employer ask for a doctor's note without violating HIPAA?
HIPAA does not stop an employer from asking. It governs what the health care provider may disclose, which is why providers ask the employee to authorize release or hand the note over themselves. Whether the request is appropriate is a separate question under disability, leave and state law, which limit what employers may ask and require confidential handling of the answer.
Is a hospital employee's own medical record PHI?
If the hospital treated the employee as a patient, that treatment record is PHI held by the hospital in its role as a provider, and HR generally needs the employee's authorization to use it for employment purposes. Documents the employee hands to HR, such as a leave certification, become employment records in the HR file and fall outside the PHI definition.
Can de-identified HR health data be licensed for AI training?
In practice it is left out. Even with identifiers removed, HR health information adds little to the work records AI buyers value and keeps legal risk in the dataset. Companies that license data usually exclude HR, leave, benefits and occupational health systems entirely, and agree redaction rules for any health details found in email, chat or shared drives.
Are workers' compensation files protected by HIPAA?
In the employer's hands, workers' compensation files are generally governed by state workers' compensation law rather than HIPAA, because the employer is not acting as a covered entity. Health care providers that treat the injured worker have their own HIPAA rules on what they may share for workers' compensation purposes. Rules differ by state, so check with counsel before using these files for anything beyond the claim.
Related pages
- HIPAA and AI training data: what the rules allow and what stays out of a license
- Data mapping for privacy compliance that doubles as data licensing prep
- Employee privacy notice template for California employers, clause by clause
- Is employee keystroke and screen monitoring legal, and can captures be licensed?
- Check Company Fit for Data Licensing
- How SourceX US company data referrals work
Free resources
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment