Marquee Background
Marquee Background

Offit Kurman Blogs

Labor and Employment

That’s a violation of HIPAA! But is it…

August 26, 2021

By Sarah M. Sawyer

It has certainly been an eventful summer from the reopening of businesses and office spaces, talk of a fall “comeback” with many employers hoping to return the majority of their workforce to working in person or operating in a hybrid model, and the elimination of mask mandates to the reinstatement of mask mandates, a delta surge, increased vaccine mandates, and approval of the Pfizer vaccine. As we have learned over the last 18 months, there is never a dull moment when it comes to the COVD-19 pandemic.

Over the last month, I have seen a sharp increase in companies mandating vaccination in the workplace and organizations requiring proof of immunization or a negative COVID-19 test to attend meetings or events. With these increases in mandatory policies, I have also been fielding many questions regarding HIPAA compliance. Namely, what do we need to do to comply with HIPAA when requesting and obtaining medical information, such as vaccination status?

Well, I am here to set the record straight-HIPAA probably doesn’t apply to your business.

The Health Insurance Portability and Accountability Act of 1996, better known by its acronym, “HIPAA,” is a federal law that created national standards to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge. Since this law covers patients, it only applies to healthcare providers, health plans, healthcare clearinghouses (“Covered Entities”), and business associates acting on behalf of these Covered Entities. HIPAA does not cover businesses that are not in healthcare or acting on behalf of healthcare entities.

While HIPAA does not cover most businesses who call me with questions regarding HIPAA compliance, that does not mean they are not responsible for keeping medical information confidential and keeping it secure and out of the wrong hands. When it comes to protecting confidential medical information, other federal, state, and local laws likely apply. For example, when it comes to employees, under the Americans with Disabilities Act (ADA), employers are required to keep all employee medical information confidential and keep it in a confidential medical file separate from the employee’s personnel file. There are also laws, such as the Family Education Rights and Privacy Act (FERPA), that protect the medical information of elementary, secondary, and post-secondary students.

While asking whether HIPAA applies is not technically relevant to most companies or organizations, the question has become a colloquial way of asking what they should do with confidential information to stay out of trouble, which is a thoughtful and necessary question. Ultimately, when obtaining or storing personal medical information of employees, clients, or event attendees, companies and organizations need to check federal, state, and local regulations to ensure compliance.

Resources

Related People

Related Services

  • Posts
  • About
  • Subscribe

Firm Highlights

  • Blog Posts
    Law, Love, and Life's Battles: Facing Breast Cancer
    What happens to a marriage and a family when a breast cancer diagnosis changes everything? In this episode of Love Ends, Law Begins, hosts Fara Rodriguez and Stephanie Lehman have a deeply personal conversation about breast cancer, marriage, family, and the challenges that can come with a serious illness. This episode is especially meaningful for Fara, who shares her own recent breast cancer diagnosis and journey. She opens up about discovering a lump, receiving her diagnosis, undergoing a double mastectomy and subsequent treatments, and navigating the emotional impact of cancer while continuing to work and care for her family. Fara and Stephanie discuss how a cancer diagnosis can affect a marriage in unexpected ways—from changing family roles and creating new caregiving responsibilities to putting pressure on finances, health insurance, and household responsibilities. They explore how illness can either bring couples closer together or create additional challenges, particularly when one spouse becomes the primary caregiver or when the family is dealing with fear and uncertainty. The conversation also addresses the unique challenges of parenting during an illness, including how to talk to children about a cancer diagnosis and how divorced parents may need to adjust parenting schedules and responsibilities when one parent becomes sick. From navigating medical expenses and insurance coverage to balancing work, parenting, caregiving, and intimacy, Fara and Stephanie offer a candid look at the ways illness can reshape relationships and family dynamics. In recognition of Breast Cancer Awareness Month, this episode provides an honest and personal conversation about facing cancer while navigating marriage, family, and the many practical challenges that come with a serious diagnosis. In this episode, you'll hear about: • Fara's personal breast cancer diagnosis and journey • How a cancer diagnosis can affect a marriage • The challenges of becoming a caregiver to your spouse • How illness can bring couples closer together—or create new challenges • Talking to children about a parent's cancer diagnosis • How divorced parents can navigate parenting responsibilities when one parent becomes ill • The financial impact of illness and the loss of household income • Health insurance and medical coverage considerations • How medical expenses can create additional financial strain • The importance of support from family, friends, and caregivers • Balancing work, parenting, treatment, and recovery • How illness can affect intimacy and marital dynamics • The importance of supporting children through a parent's illness • Why communication and cooperation matter during a health crisis • Breast Cancer Awareness Month and the importance of mammograms
  • Events
    AIA Tri-State Conference
    Princeton will serve as the backdrop for three days of connection, learning, and design leadership. From keynotes to tours to the Tri-State Design Awards, this year’s conference is designed to go far beyond education sessions. Kick off the week with pre-conference intensives and individual state component Design Award celebrations, followed by three days of education, inspiration, networking, and design excellence at the 2026 AIA Tri-State Conference—featuring pre-conference intensives, three keynote speakers, 25 education sessions, curated tours, an expo, spec academies, and the AIA Tri-State Design Awards—bringing together architects and design professionals from New Jersey, New York, and Pennsylvania to connect, learn, and celebrate the best of the profession. G2. Designing Secure Practices: Cybersecurity, Data Privacy, Contractual Provisions, and Insurance Risks for Architects (4:00 PM - 5:30 PM) Architects and design professionals increasingly rely on cloud platforms, BIM software, and digital tools to manage sensitive data, creating cybersecurity and privacy risks. A single incident can trigger liability claims, regulatory obligations, reputational harm, and insurance challenges. Yet many firms underestimate how contracts, insurance, and internal practices intersect during a breach. This program offers legal and insurance perspectives on cyber risk in architecture, examining liability exposure, risky contract provisions, and mitigation strategies. A cyber insurance expert will explain policy responses, coverage gaps, coordination with professional liability, and best practices for aligning insurance with contractual risk and protecting firms from evolving cyber threats. Learning Objectives: Identify key cybersecurity and data privacy risks faced by architecture firms and explain how these risks can impact professional liability and project outcomes. Analyze common contractual provisions to determine which clauses may increase exposure to cyber incidents and propose strategies to mitigate these risks. Evaluate the scope and limitations of cyber insurance policies, including coordination with professional liability coverage, to determine how a policy would respond in a breach scenario. Develop actionable risk management strategies by integrating legal, contractual, and insurance considerations to protect sensitive client and project data.