Skip to main content
  • Foundation
  • Executive network
  • CEO Circle
  • SHRM Business
  • Linkage Logo
  • Store
  • Sign In
  • Account
    • My Account
    • Logout
    • Global
    • India
    • MENA
SHRM
About
Book a Speaker
Join Today
Renew
Rejoin Now
Renew
  • Membership
  • Certification
    Certification

    Smiling asian student studying in library with laptop books doing online research for coursework, making notes for essay homework assignment, online education e-learning concept
    Get Certified!

    Be recognized as an HR leader with your SHRM-CP or SHRM-SCP credential.

    • How to Get Certified

      Demonstrate your ability to apply HR principles to real-life situations. No other HR certification compares.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Details and Fees
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me
      • Certification FAQs
    • Prepare for the Exam

      Give yourself the best chance to pass your SHRM certification exam.

      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      • Study Aids & Add-ons
    • Recertification

      Recertify your SHRM Credentials before your end date!

      • Specialty Credentials
      • Qualifications
  • Topics & Tools
    Topics & Tools

    Stay up to date with workplace news and leverage our vast library of resources to streamline day-to-day HR tasks.

    The white house in washington, dc.
    Executive Order Impact Zone

    Do not abandon, but evaluate and evolve. It is about legal, equal opportunity for all.

    • News & Trends

      Follow breaking news and emerging workplace trends.

      Legal & Compliance

      Stay informed on workplace legal updates and their impacts.

      From the Workplace

      Explore diverse perspectives from your peers on today's workplaces.

      Flagships

      Get curated collections of podcasts, videos, articles, and more produced by SHRM.

    • HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
      SEE ALL
      SHRM Research
    • Tools & Samples

      Access member resources and tools to streamline HR tasks.

      • Forms & Checklists
      • How-To Guides
      • Interactive Tools
      • Job Descriptions
      • Policies
      • Toolkits
      SEE ALL
      Ask an Advisor
  • Events & Education
    Events & Education

    SHRM25 in San Diego, June 29 - July 2, 2025
    Join us for SHRM25 in San Diego

    Register for the World’s Largest HR Conference being held on June 29 - July 2, 2025

    • Events
      • SHRM25
      • The AI+HI Project 2025
      • INCLUSION 2025
      • Talent 2026
      • Linkage Institute 2025
      SEE ALL
      Webinars
    • Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

      Specialty Credentials

      Demonstrate targeted competence and enhance credibility among peers and employers.

      Qualifications

      Gain a deeper understanding and develop critical skills.

    • Team Training & Development

      Customized training programs unique to your organization’s needs.

  • Business Solutions
  • Advocacy
    Advocacy

    Make your voice heard on public policy issues impacting the workplace.

    Advocacy
    SHRM's President & CEO testifies to Congress on "The State of American Education"
    • Policy Areas
      • Workforce Development
      • Workplace Inclusion
      • Workplace Flexibility & Leave
      • Workplace Governance
      • Workplace Health Care
      • Workplace Immigration
      State Affairs

      SHRM advances policy solutions in state legislatures nationwide.

      Global Policy

      SHRM is the go-to for global HR leaders and businesses on workplace matters.

    • Advocacy Team (A-Team)

      SHRM’s A-Team is a key member benefit, giving you the tools, insights, and opportunities to shape workplace policy and drive real impact.

      Take Action

      Urge lawmakers to support policies that create lasting, positive change.

      Advocacy & Legislative Resources

      Access SHRM’s curated policy materials and content.

    • SHRM-Led Coalitions
      • Generation Cares
      • The Section 127 Coalition
      • Learn More & Partner with SHRM Government Affairs
  • Community
    Community

    Woman raising hand in group
    Find a SHRM Chapter

    Easily find a local professional or student chapter in your area.

    • Chapters

      Find local connections from over 607 chapters and state councils and create your personalized HR network.

      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      SHRM Northern California

      Join SHRM members in the greater San Francisco Bay area for local events and networking.

    • Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      • Membership Advisory Council
      • Regional Councils
    • Volunteers

      Learn about volunteer opportunities with SHRM.

      • Volunteer Leader Resource Center
Close
  • Membership
  • Certification
    back
    Certification
    Smiling asian student studying in library with laptop books doing online research for coursework, making notes for essay homework assignment, online education e-learning concept
    Get Certified!

    Be recognized as an HR leader with your SHRM-CP or SHRM-SCP credential.

    • How to Get Certified

      Demonstrate your ability to apply HR principles to real-life situations. No other HR certification compares.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Details and Fees
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me
      • Certification FAQs
    • Prepare for the Exam

      Give yourself the best chance to pass your SHRM certification exam.

      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      • Study Aids & Add-ons
    • Recertification

      Recertify your SHRM Credentials before your end date!

      • Specialty Credentials
      • Qualifications
  • Topics & Tools
    back
    Topics & Tools

    Stay up to date with workplace news and leverage our vast library of resources to streamline day-to-day HR tasks.

    The white house in washington, dc.
    Executive Order Impact Zone

    Do not abandon, but evaluate and evolve. It is about legal, equal opportunity for all.

    • News & Trends

      Follow breaking news and emerging workplace trends.

      Legal & Compliance

      Stay informed on workplace legal updates and their impacts.

      From the Workplace

      Explore diverse perspectives from your peers on today's workplaces.

      Flagships

      Get curated collections of podcasts, videos, articles, and more produced by SHRM.

    • HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
      SEE ALL
      SHRM Research
    • Tools & Samples

      Access member resources and tools to streamline HR tasks.

      • Forms & Checklists
      • How-To Guides
      • Interactive Tools
      • Job Descriptions
      • Policies
      • Toolkits
      SEE ALL
      Ask an Advisor
  • Events & Education
    back
    Events & Education
    SHRM25 in San Diego, June 29 - July 2, 2025
    Join us for SHRM25 in San Diego

    Register for the World’s Largest HR Conference being held on June 29 - July 2, 2025

    • Events
      • SHRM25
      • The AI+HI Project 2025
      • INCLUSION 2025
      • Talent 2026
      • Linkage Institute 2025
      SEE ALL
      Webinars
    • Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

      Specialty Credentials

      Demonstrate targeted competence and enhance credibility among peers and employers.

      Qualifications

      Gain a deeper understanding and develop critical skills.

    • Team Training & Development

      Customized training programs unique to your organization’s needs.

  • Business Solutions
  • Advocacy
    back
    Advocacy

    Make your voice heard on public policy issues impacting the workplace.

    Advocacy
    SHRM's President & CEO testifies to Congress on "The State of American Education"
    • Policy Areas
      • Workforce Development
      • Workplace Inclusion
      • Workplace Flexibility & Leave
      • Workplace Governance
      • Workplace Health Care
      • Workplace Immigration
      State Affairs

      SHRM advances policy solutions in state legislatures nationwide.

      Global Policy

      SHRM is the go-to for global HR leaders and businesses on workplace matters.

    • Advocacy Team (A-Team)

      SHRM’s A-Team is a key member benefit, giving you the tools, insights, and opportunities to shape workplace policy and drive real impact.

      Take Action

      Urge lawmakers to support policies that create lasting, positive change.

      Advocacy & Legislative Resources

      Access SHRM’s curated policy materials and content.

    • SHRM-Led Coalitions
      • Generation Cares
      • The Section 127 Coalition
      • Learn More & Partner with SHRM Government Affairs
  • Community
    back
    Community
    Woman raising hand in group
    Find a SHRM Chapter

    Easily find a local professional or student chapter in your area.

    • Chapters

      Find local connections from over 607 chapters and state councils and create your personalized HR network.

      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      SHRM Northern California

      Join SHRM members in the greater San Francisco Bay area for local events and networking.

    • Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      • Membership Advisory Council
      • Regional Councils
    • Volunteers

      Learn about volunteer opportunities with SHRM.

      • Volunteer Leader Resource Center
Join Today
Renew
Rejoin Now
Renew
  • Store
    • Global
    • India
    • MENA
  • About
  • Book a Speaker
  • Foundation
  • Executive network
  • CEO Circle
  • SHRM Business
  • Linkage Logo
SHRM
Sign In
  • Account
    • My Account
    • Logout
Close

  1. Topics & Tools
  2. Employment Law & Compliance
  3. What to Do When Employee Medical Data Is Compromised
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

What to Do When Employee Medical Data Is Compromised

November 17, 2016 | Kwabena A. Appenteng

A stethoscope sits on top of a laptop computer.


Given recent headlines, it would be easy to believe that for a "data breach" to occur a hacker must be involved. While this may be the most commonly reported type of data breach, employers are exposed to the risk of many other forms of data breaches each day.

Take, for example, the employee who leaves on an empty train seat an unencrypted company laptop containing the confidential medical records of 100 patients of the physician's office where the employee works. Or the employee who accidentally e-mails an unencrypted spreadsheet listing the names and medical conditions of 75 employees enrolled in the company's wellness program to the wrong e-mail address—not his supervisor john.smith@acme.com but an unknown john.smith@aol.com.

These are also data breaches. What's more, because both involve entities subject to the Health Insurance Portability and Accountability Act (HIPAA), employers must comply with HIPAA's breach notification rule which, among other things, requires each employee impacted by the breach to be notified within a specified time frame.

Up until August of this year, the incidents described above may not have led to an investigation by the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR), the federal agency that enforces HIPAA, because each breach involved less than 500 people. That changed on Aug. 18, 2016, when OCR announced that it will now investigate data breaches of all sizes.

If the threat of an investigation into a company's data security practices is not enough to cause concern, this must also be considered: HIPAA permits a state's attorney general to investigate and bring civil actions against entities that violate HIPAA's breach notification rule. Therefore, an employer that suffers a data breach could now be investigated by either a state's attorney general's office or OCR.

So, is your company required to comply with HIPAA's breach notification rule? And, if so, what do you need to do if you suffer a security incident to comply with the rule? And what if you are not covered by HIPAA but still retain medical information? Read on.

Are You Required to Comply with HIPAA?

If an employer sponsors an employee group health plan, the plan is required to comply with HIPAA.

One of the biggest misconceptions about HIPAA is that it applies only to health care providers, such as doctors or hospitals. This is not true. In addition to health care providers and health care clearinghouses, HIPAA applies to health plans, such as the group health plans offered by many employers and even the flexible spending accounts that many employers provide, if certain elements are met. Many employers are under the false impression that they do not have to comply with HIPAA and HIPAA's breach notification rule.

With that said, an important distinction must be made: if an employer does have a HIPAA-qualifying health plan, only the plan is subject to HIPAA, not the employer's entire business. So, for example, if a retail company sponsors a group health plan that pays the cost of its employees' medical care, the company itself—or "plan sponsor"—is not a HIPAA-covered entity, but the group health plan is.

[SHRM members-only Q&A: Medical Privacy: What are the HIPAA privacy notice requirements for employers that sponsor a group health plan?]

Cloud Storage Service

If an employer stores health information using a cloud storage service, the cloud storage provider must comply with HIPAA and must have a HIPAA-qualified contract with the employer that governs how employees' health information will be used and safeguarded.

On Oct. 6, 2016, HHS released guidance for cloud service providers (CSPs) that store electronic health information for HIPAA-covered entities—for example, a group health plan that electronically stores employees' health information using Google cloud storage.

According to HHS's guidance, even if a CSP is unable to open or access health information it is storing because the health information is encrypted and the CSP does not have the decryption key (or password), the CSP is a "business associate" and therefore must comply with HIPAA.

A business associate is an entity that creates, receives, maintains or transmits health information on behalf of a covered entity for the purpose of claims processing or administration, data analysis, benefit management or billing. An entity that receives health information from a HIPAA-covered entity, and provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial services is also a business associate.

HIPAA requires that a business associate that suffers a breach to notify the covered entity and provide the name of each individual whose health information has been compromised as a result of the breach.

However, because HIPAA also requires that HIPAA-covered entities and business associates to enter into business associate contracts, a HIPAA-covered entity can contractually expand the obligations that a business associate must comply with in the event of a breach. So, for example, a group health plan can require that if the claims processor it works with suffers a breach, the processor must not only notify the group health plan of the breach, but also must notify each employee affected by the breach and pay the cost of credit-monitoring services for each employee.

Have You Actually Suffered a Breach?

To trigger HIPAA's breach notification rule, an entity must suffer a breach of "unsecured" health information.

HIPAA does not limit the definition of a breach to security incidents involving electronically stored records; a security incident involving paper records can also constitute a breach. However, in order for HIPAA's breach notification rule to be triggered, an entity must suffer an unauthorized disclosure of health information "that is not rendered unusable, unreadable or indecipherable to unauthorized persons," referred to as "unsecured" health information.

Electronic health information that is encrypted, and health information in paper form that has been shredded, are two examples of "secured" health information.

There are three situations that HIPAA specifically excludes from the definition of a breach:

  • An employee who works for a HIPAA-covered entity or business associate unintentionally obtains health information in good faith, and does not use or disclose the health information. For example, a doctor mistakenly receives a FedEx package containing medical information about an individual who is not a patient and immediately shreds the documents.
  • An employee who works for a HIPAA-covered entity or business associate and has access to health information inadvertently discloses health information to another employee and the receiving employee does not share the information with anyone. For example, an employee of Acme, a company's third-party benefits administrator, sends an e-mail containing medical information about a health plan participant to a colleague who does not do any work with that particular health plan. The Acme employee who inadvertently receives the information deletes the e-mail.
  • A HIPAA-covered entity or business associate discloses health information to a person who is not authorized to receive it but has a good-faith belief that the receiving party will not be able to retain the information. For example, a doctor sends an e-mail containing health information to the wrong e-mail address, but the e-mail bounces back due to the address being wrong.

Even if an entity does not fall within these exemptions, it may still be exempt from complying with HIPAA's breach notification rule in the event of a breach of unsecured health information if it can show a low probability that the health information has been compromised.

What Should You Do to Comply?

If you are a HIPAA-covered entity, you have suffered a breach and the breach involves unsecured health information, you must comply with HIPAA's breach notification rule.

In the event of a breach, the rule requires a HIPAA-covered entity to:

  • Send a notice to each individual whose unsecured health information has been, or is reasonably believed to have been, disclosed as a result of the breach "without unreasonable delay" and in no case later than 60 days after the breach is discovered. (Substitute notice is permitted under certain circumstances.)
  • Send the notice by first-class mail, unless the individual to be notified has agreed to e-mail notification.
  • Include within the notice: a brief description of the breach; a description of the types of information involved in the breach; the steps individuals should take to protect themselves from harm; a brief description of the steps the entity is taking to investigate the breach, mitigate the harm and prevent further breaches; and a toll-free telephone number, e-mail address, website or postal address for individuals to use to contact your company to ask questions.
  • No later than within 60 days of the end of the calendar year in which the breach was discovered, notify HHS by submitting a breach report on its website.

If the breach involves more than 500 residents of a state or locality, the entity must:

  • Without unreasonable delay, and in no case later than 60 days after the breach is discovered, notify "prominent media outlets."
  • No later than 60 calendar days from the discovery of the breach, notify HHS by submitting a breach report on its website.

What About Entities that Are Not Covered by HIPAA?

Non-HIPAA covered entities that suffer a breach must ensure they are in compliance with state breach notification laws and the Federal Trade Commission's (FTC's) health breach notification rule.

Employers that are not covered by HIPAA are not immune from reporting obligations in the event of a security incident involving health information. Numerous states require notification within a specified time frame if residents' medical or health information is compromised as a result of a security incident. These states include Arkansas, California, Florida, Illinois, Missouri, Montana, North Dakota, Oregon, Rhode Island, Texas and Virginia.

Entities that maintain "personal health records" are required to comply with the FTC's health breach notification rule in the event of a breach. The prevalence of wearable technology has led to more entities retaining "personal health records": these are defined as an electronic record of health information that reasonably identifies an individual, that can be drawn from multiple sources, and that is managed, shared and controlled by the individual or primarily for the individual.

For example, a website that enables users to input information about their weight, blood pressure and other general health information might be considered a personal health record. The FTC's rule closely tracks the requirements of HIPAA's data breach notification rule. HIPAA-covered entities and business associates are exempt from compliance with the FTC's rule.

Takeaways for Employers

Employers might want to consider taking the following steps:

  • Establish a security incident response team that is trained on how to comply with HIPAA's breach notification rule and develop an incident response plan.
  • Review—and if necessary, enhance—administrative, physical and technical safeguards for health information to both reduce the risk of a security breach and ensure compliance with HIPAA.
  • Develop templates for notice letters.
  • Conduct simulations to test the effectiveness of the incident response plan.

Kwabena A. Appenteng is an attorney with Littler in Chicago.

Was this article useful? SHRM offers thousands of tools, templates and other exclusive member benefits, including compliance updates, sample policies, HR expert advice, education discounts, a growing online member community and much more. Join/Renew Now and let SHRM help you work smarter.

 

Employment Law & Compliance
Leadership & Navigation
Risk Management
Technology
Workplace Security

Artificial Intelligence in the Workplace

​An organization run by AI is not a futuristic concept. Such technology is already a part of many workplaces and will continue to shape the labor market and HR. Here's how employers and employees can successfully manage generative AI and other AI-powered systems.



Related Content

Kelly Dobbs Bunting speaks onstage at SHRM24
(opens in a new tab)
News
Why AI+HI Is Essential to Compliance

HR must always include human intelligence and oversight of AI in decision-making in hiring and firing, a legal expert said at SHRM24. She added that HR can ensure compliance by meeting the strictest AI standards, which will be in Colorado’s upcoming AI law.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

Workplace Compliance Newsletter

Summaries of legal decisions, legislative news and regulatory news, delivered Friday afternoons.

Success title

Success caption

Manage Subscriptions
  • About SHRM
  • Careers at SHRM
  • Press Room
  • Contact SHRM India
  • Book a SHRM Executive Speaker
  • Advertise with Us
  • Copyright & Permissions
  • Post a Job
  • Find an HR Job
Contact Us

SHRM India Corporate Information
Email: shrmindia@shrm.org
Phone: (1)800.103.2198
WhatsApp: +919810503727

Follow Us
  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube
  • SHRM Newsletters
  • Ask An Advisor

© 2025 SHRM. All Rights Reserved

SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer


  1. Privacy Policy

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Member Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member?
Free Article
Limit Reached

Get unlimited access to articles and member-exclusive resources.

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member?
Free Article
Exclusive Executive-Level Content

This content is for the SHRM Executive Network and Executive Content Subscription members only.

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member?
Free Article
Exclusive Executive-Level Content

This content is for the SHRM Executive Network and Executive Content Subscription members only.

You've reached the limit of 1 free article this month. Join and enjoy unlimited access to SHRM Executive Network Content.

Already a member?
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member?

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now