The University of Alabama at Birmingham

Human Resources

May my employer contact my health care provider about my serious health condition?

The regulations clarify that contact between an employer and an employee’s health care provider must comply with the Health Insurance Portability and Accountability Act (HIPAA) privacy regulations. Under the regulations, employers may contact an employee’s health care provider for authentication or clarification of the medical certification by using a health care provider, a human resource professional, a leave administrator, or a management official. In order to address employee privacy concerns, the regulations make it clear that in no case may the employee’s direct supervisor contact the employee’s health care provider. In order for an employee’s HIPAA-covered health care provider to provide an employer with individually-identifiable health information, the employee will need to provide the health care provider with a written authorization allowing the health care provider to disclose such information to the employer. Employers may not ask the health care provider for additional information beyond that contained in the medical certification form. 


By Francesca Collins | Modified on: Tue, 10 Nov, 2020 at 2:13 PM
The information in this article has been verified as up-to-date on the date of publication. All information is for general purposes only and not intended to address the specific circumstances of any particular individual. For specific questions or support, contact us at humanresources@uab.edu.

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.