No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Compliance

Do OSHA and HIPAA Rules Stand at Odds?

by Peter McGrath
October 20, 2015
in Compliance
Do OSHA and HIPAA Rules Stand at Odds?

The Occupational Safety and Health Administration (OSHA) Act[1] requires most employers with 10 or more full-time employees to keep a yearly log of all work-related injuries and illnesses[2].  OSHA prefers that employers subject to the law use its Form 300 to record the required information.  The OSHA Form 300 is an actual, fillable form for employers to record all reportable injuries and illnesses that occur in the workplace, with spaces to report where and when the incidents occur, the nature of the case, the name and job title of the employee injured or made sick and the number of days away from work or on restricted or light duty, if any.

OSHA requires employers to record all new cases of work-related fatalities, injuries and illnesses if they involve death, days away from work, restricted work or transfer to another job, medical treatment beyond first aid, loss of consciousness or of significant injury or illness diagnosed by a physician or other licensed health care professional.  Each recordable injury or illness must be recorded on the 300 log and OSHA Form 301 Incident Report within seven calendar days after the employer receives notice the injury or illness occurred.  The OSHA 300 log requires employers to check one of six boxes to categorize the illness or injury:  injury, skin disorder, respiratory condition, poisoning, hearing loss or “other.”  Employees, former employees and employee representatives are authorized to review the OSHA 300 logs.

There are certain cases in which an injury or illness must be handled as a privacy case and kept confidential.  Employees are prohibited from entering an employee’s name on the OSHA 300 log in the following cases:

  1. The injury or illness occurred to an intimate body part or their reproductive system
  2. Sexual assault
  3. Mental illnesses
  4. HIV infection, hepatitis or tuberculosis
  5. Needle-stick injuries and cuts from sharp objects that are contaminated with another person’s blood

In privacy concern cases, a separate confidential list of employee names must be kept.  Employers also have the right to use discretion describing the sensitive nature of the injury where the worker’s identity would be known. Employers must post a copy of an annual summary of OSHA 300 logs in each establishment in a conspicuous place or places where notices to employees are customarily posted.  (The summaries do not include employee names.)

Employers have expressed concern to OSHA that employers must remove all of the names from the OSHA 300 log before providing access in order to comply with privacy requirements contained in the Health Insurance Portability and Accountability Act. (HIPAA).[3]

HIPAA essentially defines and limits the circumstances in which an individual’s protected heath information may be used or disclosed by covered entities.  Covered entities generally include health plans, health care providers and health care clearinghouses (or any business associate of any of those entities).  A covered entity may not use or disclose protected health information except either (1) as the HIPAA permits or requires or (2) as the individual who is the subject of the information (or the individual’s personal representative) authorizes in writing.

A covered entity must disclose protected health information in only two situations: (1) to individuals (or their personal representatives) specifically when they request access to, or an accounting of disclosures of, their protected health information and (2) to the Department of Health and Human Services when it is undertaking a compliance investigation or review or enforcement action.

The AFL-CIO several years ago asked OSHA to clarify the effect of the HIPAA policy protection rules upon the OSHA recordkeeping requirements contained in the log 300 rules.  OSHA has indicated that it does not believe that HIPAA provides a basis for employers to remove employee’s names from the log before providing access to the log to an employee, former employee or employee representative as authorized by the OSHA rules.  Even if HIPAA privacy protection is implicated by the employer’s disclosure of the OSHA log, HIPAA and its implementing regulations expressly permit the disclosure of protected health information to the extent required by law.

Health care providers have become remarkably sensitive to HIPAA privacy concerns and remarkably protective of patient health care information.  OSHA requires employers to collect, make available and, to some extent, even publish health care information regarding injuries or illnesses caused or occurring in the workplace.  While OSHA is almost certainly correct that OSHA-authorized disclosure of information might otherwise be protected under HIPAA, it may be an uphill battle for employers to persuade health care providers to supply required information.  OHSA already imposes significant burdens on employers, apart from educating health care providers about the interaction between OSHA and HIPAA.  If employers are finding it impossible or even difficult to convince health care providers to supply information the employers believe they need to complete OSHA logs, employers may need to seek reconsideration of the rules by OSHA.  Employers may also need to work together through trade or industry groups to convince OSHA and health care providers of potential problems.  Congressional action to amend PSHA or HIPAA may be required to clarify the rules, but Congressional action on any issue seems a remote possibility at this time.

[1]  29 U.S.C. 650, et seq.

[2] 29 CFR 1904

[3] 42 U.S.C. § 300gg and 29 U.S.C § 1181 et seq. and 42 USC 1320d et seq.


Previous Post

Observations on the Short-Term/Long-Term Debate, Part 2

Next Post

Haskell & White Earns National Accolades

Peter McGrath

Peter McGrath

September 17 - Peter McGrath headshotA frequent lecturer and author on diverse environmental issues, Peter McGrath, a member at Moore & Van Allen, brings to his wide-ranging clients extensive counseling and litigation experience with environmental issues arising in business and real estate transactions.

Related Posts

Fox_DOJ Speeches_f

Analysis of Recent DOJ Statements

by Corporate Compliance Insights
March 23, 2023

DOJ leaders provide insight into agency's plans. Analysis of Recent Statements DOJ Shaping the Future of Corporate Criminal Enforcement What’s...

Fox_2023 ECCP Update_f

2023 Evaluation of Corporate Compliance Programs

by Corporate Compliance Insights
March 23, 2023

Keeping up with 2023 changes to DOJ guidelines. Additions, Deletions & Changes From 2020 2023 Evaluation of Corporate Compliance Programs...

encompass update

Encompass Launches pKYC Maturity Model

by Corporate Compliance Insights
March 22, 2023

KYC automation platform Encompass has unveiled a new perpetual Know Your Customer (pKYC) maturity model designed to help banks improve...

consilio onna partnership

Consilio, Onna Seek to Streamline eDiscovery for Cloud Apps

by Corporate Compliance Insights
March 22, 2023

Legal technology provider Consilio has launched a new platform, Sightline Collect, powered by data management supplier Onna. The platform is...

Next Post
Haskell & White Earns National Accolades

Haskell & White Earns National Accolades

Compliance Job Interview Q&A

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Code of Conduct Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2022 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe

© 2022 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT