Resources/HIPAA Requirements For Hr Software

Summary

This guide breaks down exactly what HIPAA requires from HR software, who is covered, and the practical steps you need to take to stay compliant. This is where HR software features become especially important. HIPAA’s Security Rule requires specific technical controls:


HIPAA Requirements for HR Software: What Every Employer Needs to Know

Managing employee health information is one of the most sensitive responsibilities an HR department handles. Whether you’re processing benefits enrollments, managing leave requests, or storing medical certifications, your HR software must meet strict HIPAA requirements. Failing to comply can result in civil penalties ranging from $100 to $50,000 per violation — and that’s before factoring in reputational damage.

This guide breaks down exactly what HIPAA requires from HR software, who is covered, and the practical steps you need to take to stay compliant.


Who Does HIPAA Actually Cover in an HR Context?

HIPAA (the Health Insurance Portability and Accountability Act) applies to covered entities and their business associates. For HR departments, this creates some important distinctions.

When HR Departments Become Covered Entities

Most employers are not covered entities under HIPAA simply because they employ people. However, your organization does fall under HIPAA obligations when it:

  • Sponsors a self-funded group health plan
  • Administers employee health benefits directly
  • Handles Protected Health Information (PHI) on behalf of a health plan

In these cases, the HR department acts as the plan administrator and must comply with HIPAA’s Privacy and Security Rules when handling PHI.

The Business Associate Relationship

If your HR software vendor accesses, stores, or transmits PHI on your behalf, they become a Business Associate (BA). This is critical. Any HR software that touches employee health data must have a signed Business Associate Agreement (BAA) in place before you share a single record.

Without a BAA, both you and your vendor are exposed to significant liability.


What Counts as Protected Health Information in HR Software?

Not all employee health data is automatically PHI. Understanding the distinction helps you configure your HR software appropriately.

PHI in an HR context typically includes:

  • Medical certifications submitted for FMLA leave requests
  • Disability documentation from healthcare providers
  • Health plan enrollment data tied to individually identifiable information
  • Workers’ compensation medical records (in some states)
  • Accommodation requests that include clinical diagnoses

What is generally NOT PHI under HIPAA:

  • Employment records held by the employer in their capacity as an employer (not as a health plan)
  • General wellness program participation data (unless tied to health plan eligibility)
  • Basic demographic information without health context

The line can be blurry. When in doubt, treat the data as PHI and apply appropriate protections.


Core HIPAA Requirements Your HR Software Must Meet

1. Administrative Safeguards

Administrative safeguards are the policies and procedures that govern how your team handles PHI. Your HR software must support these requirements by enabling:

  • Role-based access controls so only authorized personnel can view health records
  • Audit logs that track who accessed PHI and when
  • User authentication to verify the identity of anyone accessing the system
  • Workforce training documentation to prove employees have been trained on HIPAA policies

Your software should also support a designated Privacy Officer role — someone responsible for overseeing HIPAA compliance within the HR function.

2. Physical Safeguards

Even cloud-based HR software has physical safeguard requirements. These apply to the data centers and devices used to access PHI:

  • Servers storing PHI must be in physically secure facilities
  • Workstations accessing PHI should be in restricted areas or use screen locks
  • Mobile device management (MDM) policies should cover any phones or tablets used to access HR software
  • Media disposal procedures must be documented for any hardware that stored PHI

Ask your HR software vendor for their SOC 2 Type II report or equivalent documentation proving physical security at their data centers.

3. Technical Safeguards

This is where HR software features become especially important. HIPAA’s Security Rule requires specific technical controls:

  • Encryption at rest and in transit for all PHI (AES-256 is the current standard)
  • Automatic session timeouts to prevent unauthorized access on unattended devices
  • Multi-factor authentication (MFA) for system access
  • Data integrity controls to detect unauthorized alteration of PHI
  • Transmission security using TLS 1.2 or higher for all data transfers

When evaluating HR software vendors, request a security questionnaire and verify these controls are in place — not just promised.

4. The Business Associate Agreement (BAA)

This document is non-negotiable. A valid BAA must specify:

  • The permitted uses and disclosures of PHI by the vendor
  • The vendor’s obligation to implement appropriate safeguards
  • Requirements to report breaches within 60 days of discovery
  • Provisions for returning or destroying PHI upon contract termination
  • Subcontractor obligations (your vendor’s vendors must also comply)

Many major HR platforms — including Workday, ADP, and BambooHR — offer BAAs, but you must request and execute them explicitly. They are rarely included automatically.


FMLA, ADA, and the Intersection with HIPAA

HR software often manages leave and accommodation workflows where HIPAA intersects with other federal laws.

FMLA Leave Management

When employees submit medical certifications for FMLA leave, those documents contain PHI. Your HR software must:

  • Store medical certifications separately from general personnel files
  • Restrict access to HR personnel with a legitimate need to know
  • Never share certification details with direct managers beyond the approved leave dates

ADA Accommodation Requests

Medical documentation submitted for ADA accommodations is similarly sensitive. HR software should maintain these records in a confidential medical file — separate from the employee’s standard HR record — as required by both HIPAA and the ADA.


Common HIPAA Compliance Mistakes in HR Software

Even well-intentioned HR teams make these errors:

  • Storing PHI in general HR files rather than designated medical record sections
  • Skipping the BAA with software vendors because “it’s just HR data”
  • Sharing medical details in email without encryption, even internally
  • Failing to audit access logs quarterly to detect unauthorized viewing
  • Not training HR staff on what constitutes PHI and how to handle it
  • Using personal email or unsecured file-sharing to exchange medical certifications

Each of these mistakes represents a potential HIPAA violation, even without a data breach occurring.


Steps to Evaluate Your HR Software for HIPAA Compliance

Use this checklist when assessing your current or prospective HR software:

  • [ ] Does the vendor offer and sign a Business Associate Agreement?
  • [ ] Is PHI encrypted at rest and in transit?
  • [ ] Are there role-based access controls for health-related records?
  • [ ] Does the system maintain audit logs with timestamps?
  • [ ] Is MFA available and enforced for HR system access?
  • [ ] Can medical records be stored separately from general personnel files?
  • [ ] Does the vendor have documented breach notification procedures?
  • [ ] Has the vendor completed a third-party security assessment (SOC 2, ISO 27001)?

If a vendor cannot answer “yes” to all of these questions, that’s a red flag worth investigating before you sign a contract.


FAQ: HIPAA Requirements for HR Software

Does HIPAA apply to all HR departments?

Not automatically. HIPAA applies to HR departments when they handle PHI as part of administering a self-funded health plan or acting as a plan sponsor. General employment records are not covered by HIPAA, but may be protected by other laws like the ADA.

What happens if our HR software vendor has a data breach?

If your vendor experiences a breach involving PHI and you have a valid BAA in place, they are required to notify you within 60 days. You may then be required to notify affected individuals and the Department of Health and Human Services (HHS). Without a BAA, your organization bears greater liability for the breach.

Can we use standard cloud storage like Google Drive or Dropbox for medical records?

Generally, no — not without a signed BAA with the provider and proper encryption controls. Standard consumer-grade cloud storage does not meet HIPAA’s technical safeguard requirements out of the box. Enterprise versions of these platforms may qualify with a BAA in place.

Do we need separate software for HIPAA-covered health data?

Not necessarily. Many comprehensive HR platforms have HIPAA-compliant modules or configurations. The key is ensuring the vendor signs a BAA and that you configure the system to segregate PHI appropriately.

How often should we review our HR software’s HIPAA compliance?

At minimum, annually. You should also conduct a review whenever you change HR software vendors, add new integrations, modify your health plan structure, or experience a security incident.


Get Compliant Faster with Ready-to-Use Templates

Understanding HIPAA requirements is only half the battle — you also need the right documentation in place. Our professionally drafted HIPAA compliance template library gives HR teams everything they need to get compliant quickly, including:

  • Business Associate Agreement templates ready for vendor negotiations
  • HIPAA Privacy Policy tailored for HR departments
  • Employee Training Acknowledgment Forms
  • Medical Records Segregation Policy
  • Breach Notification Procedures
  • FMLA/ADA Confidentiality Checklists

Stop starting from scratch. Our templates are written by compliance experts, regularly updated to reflect current HHS guidance, and formatted for immediate use.

[Browse the HIPAA HR Compliance Template Bundle →]

Save hours of legal drafting time and give your organization the documentation foundation it needs to handle employee health information with confidence.

Next step after reading this guide
Open the HIPAA Documentation Kit

Best for teams building a HIPAA documentation and readiness baseline.

Recommended documentation for HIPAA Requirements For Hr Software
HIPAA Documentation Kit

HIPAA Security + Privacy Rule documentation with audit-readiness artifacts

View template →
Need documents now?
Get editable kits instead of starting from a blank page.
Browse Documentation Kits →
Need an execution path?
See how the readiness workflow turns a purchase into review and evidence work.
See How It Works →
Need more guidance first?
Keep exploring framework guides before choosing your starting kit.
Explore More Guides →
We use analytics cookies to understand traffic and improve the site.Learn more.