The HHS determined that the Health Insurance and Accountability Act does not prevent businesses and health care providers from asking about vaccination status.
The Health Insurance Portability and Accountability Act (HIPAA) does not prohibit any businesses and individuals, including HIPAA-covered entities such as certain health care providers, from asking if someone is vaccinated against COVID-19, according to the U.S. Department of Health and Human Services’ Office for Civil Rights.
The Office for Civil rights issued guidance on September 30 to inform the public about when the HIPAA Privacy Rule applies to disclosures and requests for information about the COVID-19 vaccine.
According to the guidance, the Privacy Rule only applies to HIPAA-covered entities, including health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions, and in some cases, their business associates.
It regulates how and when they are permitted to use and disclose protected health information, including vaccination status, but not their ability to request that information from patients and visitors.
The Privacy Rule does not apply to employers and employment records, including records held by covered entities in their capacity as employers.
It also does not prohibit an employer from requiring employees to disclose whether they are vaccinated against COVID-19, provide documentation of their vaccination and sign a HIPAA authorization for a health care provider to disclose their vaccination record to the employer.
However, the guidance points out that other federal and state laws, such as federal anti-discrimination laws, do address terms and conditions of employment.
These laws may require that employee vaccination information be kept confidential but don’t prevent an employer from requiring all employees entering the workplace to be vaccinated against COVID-19 and provide documentation or other confirmation that they have met this requirement.
According to the guidance, the rule is still subject to reasonable accommodation provisions and other equal employment opportunity considerations.
In general, HIPAA does not permit health care providers to disclose a patient’s vaccination status to employers or other parties except with the individual’s authorization or as otherwise permitted or required by the Privacy Rule.
“We are issuing this guidance to help consumers, businesses, and health care entities understand when HIPAA applies to disclosures about COVID-19 vaccination status and to ensure that they have the information they need to make informed decisions about protecting themselves and others from COVID-19,” said Lisa Pino, director of the Office for Civil Rights.