“Doesn’t that violate HIPAA?” This is a question we hear regularly from employers, businesses and individuals who are concerned that asking someone for their COVID-19 vaccination status could raise issues under the Health Insurance Portability and Accountability Act (“HIPAA”) Privacy Rule. The answer is no – it is not a problem to ask and it is not a problem to require disclosure of COVID-19 vaccinated status. This is fairly clear on the face of the regulations themselves. While vaccination information is classified as health information that is generally covered by the HIPAA Privacy Rule, HIPAA generally only provides protections with respect to disclosures by covered entities (such as health care providers and health plans) and their business associates. HIPAA therefore does not apply to most employers, and does not apply when an individual employee discloses to their employer information about the employee’s own health status, including COVID-19 vaccination status.
The Department of Health and Human Services (“HHS”) has recently provided further reassurance regarding the inapplicability of HIPAA with respect to certain information about vaccination status in the form of lengthy FAQs posted to their website on September 30, 2021.