Skip to content Skip to footer

Table of contents

Health insurance portability and privacy

Medical information employers can access

The Americans with Disabilities Act (ADA) governs employer access to and use of medical information. These restrictions are described in Disabilities and genetic information.

Privacy rule

The Health Insurance Portability and Accountability Act (HIPAA) privacy rule and security rule protects the use and disclosure of protected health information (PHI) by covered entities and business associates, except as authorized by the individual or as permitted or required by the privacy rule. The rule imposes different requirements on healthcare providers, group health plans and employers. Therefore, depending on whether the organization is handling health information in its capacity as a group health plan as opposed to its role as an employer or even healthcare provider, the requirements may change. Initially, there are six key must-knows:

  1. What is PHI?

  2. Who’s a covered entity?

  3. Who’s a business associate?

  4. What’s “use or disclosure?”

  5. How do I get authorization or identify a regulatory exception?

  6. What use/disclosure is permitted by the HIPAA privacy rule?



Please call us at (312) 960-9400 if this is an error or if you have any questions.