All articles
Compliance & Regulations

HIPAA Employer Access to Health Claims: HR Guide

WHIA Team 9 min read
HIPAA Employer Access to Health Claims: HR Guide

Can an HR department see an employee's health claims? The answer depends on the type of information, the role the employer performs for the health plan, and the safeguards in the plan documents. HIPAA does not give an employer a general right to inspect an employee's diagnoses, treatments, or claim history. It can allow limited access for defined plan administration work.

Talk with a Washington Health Insurance Agency advisor about your health plan questions.

What does HIPAA say about employer access to health claims?

HIPAA employer access to claims is limited, role-based access. A group health plan is generally the covered entity, not the employer that sponsors it. The plan may share certain information with the plan sponsor for plan administration when the required plan-document, certification, separation, and use restrictions are in place. That is different from giving HR open access to individual medical records.

The U.S. Department of Health and Human Services explains that an employer is not generally a HIPAA covered entity merely because it sponsors a group health plan. The group health plan is treated as a separate legal entity. The plan remains responsible for following the Privacy Rule when it shares protected health information with the employer or plan sponsor. See the HHS guidance on employers that sponsor group health plans.

That distinction answers a common HR question: the fact that a company pays premiums, selects a carrier, or employs the benefits administrator does not by itself authorize the company to review every claim. Access must match a permitted purpose and the plan's documented controls.

Which health information may an employer receive?

Employers may receive enrollment information and certain summary health information in situations allowed by HIPAA. They may also receive protected health information when the plan sponsor performs defined plan administration functions and the plan documents and certifications impose the required safeguards. The information should be limited to what the role requires, not whatever data a vendor can technically export.

Information or requestWhat may be allowedImportant boundary
Enrollment or disenrollment statusConfirmation that an individual participates in, enrolls in, or leaves the group health planDo not treat enrollment status as permission to inspect medical details
Summary health informationClaims history, claims expenses, or types of claims experience summarized and stripped of most individual identifiersUse it for purposes such as obtaining premium bids or changing the group health plan, as allowed
Plan administration PHILimited information needed for functions the plan sponsor performs for the planRequires plan-document restrictions, certification, separation, and access limited to authorized personnel
An employee's diagnosis or treatment historyNot a routine HR benefit of sponsoring a planDo not request or use it for employment decisions or unrelated benefit plans

The governing regulation, 45 CFR 164.504(f), describes the conditions for disclosures to a plan sponsor. It requires permitted uses to be established in the plan documents. It also requires the plan sponsor to certify that it will protect the information and will not use it for employment-related actions or decisions.

What is the difference between plan administration and employment use?

Plan administration concerns operating the health plan for covered people. Employment use concerns making decisions about a person's job or treating the person differently because of health information. HIPAA permits a narrow plan-administration lane, but the regulation specifically bars disclosure to a plan sponsor for employment-related actions or decisions or for another benefit plan of the sponsor.

Examples of plan administration work can include helping resolve an eligibility or enrollment issue, coordinating a plan change, reviewing allowed plan-level reports, or working with a carrier or third-party administrator on an operational problem. The exact scope depends on the plan documents, the employer's role, and the information involved.

Examples of employment use include using a diagnosis to decide who receives a promotion, using claim details in a performance review, asking a supervisor to investigate an employee's treatment, or using one benefit plan's health information to make decisions about another benefit. Those uses are outside the narrow purpose for which plan information may be shared.

HIPAA is not the only law that can matter. The Americans with Disabilities Act, the Genetic Information Nondiscrimination Act, ERISA, the Affordable Care Act, state privacy rules, and workplace policies may create additional duties. HR leaders should send fact-specific questions to qualified benefits or employment counsel instead of assuming that a HIPAA answer resolves every issue.

Need a clearer benefits administration process? Book a conversation with Washington Health Insurance Agency.

Can HR see claims data for a renewal or plan review?

HR and business leaders can often use aggregated or summary claims information to evaluate plan performance, compare renewal proposals, and identify broad cost drivers. That does not require viewing an employee's name, diagnosis, provider note, or individual claim line. A report that helps answer a plan-level question is safer and more useful than a data export that exposes private details without a defined purpose.

For example, a plan-level report might show total paid claims, pharmacy spending, utilization categories, or changes over time. A benefits team may use those patterns to ask whether network design, employee education, or plan funding deserves a closer review. It should not use a pattern to identify the person behind an expensive claim or speculate about a person's health.

Washington Health Insurance Agency's guide to health plan claims data for employers covers how aggregated reporting can inform renewal decisions. That topic is different from this privacy question. The operational test is simple: review the plan's permitted purpose, request the least information needed, and keep the report at a group level whenever individual detail is not necessary.

Benefits advisor explaining privacy boundaries to an HR professional
Good claims reporting helps HR ask plan-level questions without turning an employee's medical history into an HR file.

How do fully insured and self-funded plans differ?

The employer's funding arrangement can affect which organizations handle claims information, but it does not create a blanket right to see individual claims. In a fully insured arrangement, the carrier generally performs most claims operations. In a self-funded arrangement, the employer may work with a third-party administrator and may perform more plan administration, subject to the same privacy boundaries.

HHS notes that a fully insured group health plan that receives no protected health information beyond summary health information and enrollment or disenrollment information may have fewer Privacy Rule administrative responsibilities. The rule still applies to the health plan's disclosures and does not turn individual claims into ordinary HR data. Read the HHS guidance on fully insured group health plans for the specific exception.

Self-funded plans deserve extra care because the employer may have a larger role in plan operations and may receive reports from a third-party administrator. A larger operational role means the employer should define who may access what, document the permitted functions, train those people, and check that reports do not disclose more than needed. It does not mean every HR employee should receive claim-level data.

Employers evaluating self-funding can also review Washington Health Insurance Agency's self-funded health insurance guide. Funding strategy and privacy governance should be reviewed together, especially when an employer is changing administrators, adding reporting tools, or bringing a function in-house.

What should HR do before requesting health claims information?

Before asking a carrier, third-party administrator, or broker for claims information, HR should identify the business question and document why the answer is needed. A request that starts with a defined plan-administration purpose is easier to limit, approve, and audit than a request for every available report.

  1. Define the purpose: State whether the request supports enrollment, a plan amendment, premium bids, renewal analysis, or another documented administration function.
  2. Start with aggregate reporting: Ask first for group-level or summary information. Do not request names or claim details if a trend report answers the question.
  3. Check the plan documents: Confirm what the plan sponsor is allowed to receive and whether a certification or amendment is required.
  4. Limit the audience: Identify the employees or classes of employees who need access. Keep the data separate from ordinary personnel files and restrict access to those duties.
  5. Set handling rules: Use approved systems, retention limits, access logging, secure transfer, and a process for reporting an incident or mistaken disclosure.
  6. Ask counsel when facts are close: Get advice before requesting identifiable information, combining claims data with employment data, or using information for a purpose not clearly addressed in the plan documents.

These steps are practical controls, not a substitute for a legal determination. A written process also helps an employer explain to employees why a report exists, who can see it, and how the company separates benefit administration from employment decisions.

What can an employer ask an employee directly?

An employer may ask an employee for health information in some workplace situations, such as leave administration, workers' compensation, wellness programs, or health insurance. That does not mean the employer can obtain the same information directly from the employee's doctor or health plan. HHS explains that a provider generally cannot disclose information to the employer without the individual's authorization unless another legal exception applies.

HR should use the correct process for the situation. A leave or accommodation request may follow a separate employer procedure. A plan enrollment issue may require eligibility information. A claims question should usually go to the carrier or administrator through the plan's approved channel, not to a manager and not to an informal shared inbox.

Keep employment records and plan records conceptually separate. HHS explains that HIPAA generally does not protect an employer's employment records, even when they contain health-related information. Other federal and state laws may still restrict how those records are collected, stored, or used.

Frequently asked questions about HIPAA and employer claims access

Can an employer see an employee's individual health claims?

Not as a general matter. An employer may receive limited information for permitted plan administration functions when the required safeguards are in place. Summary or aggregate reporting is usually more appropriate for renewal analysis than identifiable claim details. Employers should not use protected health information for employment decisions.

Is an employer a HIPAA covered entity because it offers health insurance?

Usually, no. HHS explains that the group health plan is generally the covered entity and is treated as separate from the employer or plan sponsor. The plan's disclosures to the sponsor remain subject to HIPAA conditions. Other laws can still regulate the employer's handling of workplace health information.

Can HR use claims information to decide who gets promoted?

No. HIPAA's plan-sponsor rules do not permit protected health information to be disclosed for employment-related actions or decisions. A company should also review other employment and disability-discrimination laws before collecting or using health information in a workplace decision.

What claims data can an employer use for renewal planning?

Employers can often use summary or aggregate information about claims expenses, utilization, pharmacy spending, and broad plan trends for permitted plan purposes. The report should not identify individual employees when identification is unnecessary. Confirm the allowed data with the plan administrator and benefits counsel.

Does self-funding let an employer see all employee claims?

No. Self-funding may give an employer more responsibility for plan administration, but access remains limited by the plan documents, HIPAA conditions, and the purpose of the request. Employers should use a third-party administrator or other approved process and limit access to authorized personnel.

Have a benefits privacy question? Book a no-pressure conversation with Washington Health Insurance Agency.

Sources and legal disclaimer

This article is educational information for HR and business leaders. It is not legal, tax, medical, or compliance advice, and it does not create an attorney-client relationship. Rules can depend on the plan, funding arrangement, contracts, facts, and other applicable laws. For a specific situation, consult qualified benefits or employment counsel and the plan's administrator.

Keep reading

More from the desk.

From Reading to Talking

Insight is useful. A conversation is better.

Reading about the options is a fine start — but the real value comes from applying them to your plan. Book a thirty-minute conversation and we'll diagnose before we prescribe, with your numbers in front of us.

Book a conversation
Washington employers · 10–200 employees