💼 Employee Health Data Confidentiality Firewall Simulator
This simulation demonstrates the process of safeguarding employee medical data from unauthorized access by employers. It ensures compliance with privacy regulations and protects sensitive health information.
The Occupational Health Encounter — Where Detailed Medical Data Originates
Occupational health visits — pre-placement exams, periodic medical surveillance, return-to-work evaluations, fitness-for-duty assessments, and workers' compensation injury care — generate some of the most sensitive data an employer will ever touch. Unlike a routine personnel action, this data is subject to a distinct statutory confidentiality regime the moment it is collected.
- 42 U.S.C. §12112(d): ADA medical confidentiality clause (enacted 1990)
- 8+: Distinct data elements per encounter (diagnosis, labs, meds, notes, vitals...)
- Mandatory: Separate-file requirement (from first medical inquiry/exam)
- 15+ employees: GINA coverage threshold (Title II applies to most employers)
What happens during an occupational health visit
A single occupational health encounter can generate a surprising volume of clinical detail, most of which has no bearing on whether the employee can safely perform their job:
• History and physical: prior conditions, current symptoms, family history • Diagnostic testing: audiometry, spirometry, blood and urine labs, drug/alcohol screens, imaging • Diagnosis and treatment plan: specific medical or psychiatric diagnosis, prescribed medications, follow-up care • Functional assessment: strength, range of motion, cognitive or sensory limitations relevant to job tasks • Restriction determination: the only output that is actually needed by the employer — what the employee can and cannot safely do
All of this is captured on separate intake forms, distinct from the ordinary personnel file, because the law anticipated exactly the temptation this simulation explores: once collected, sensitive clinical data has a gravitational pull toward HR, supervisors, and management decision-making.
Legal basis for treating this data differently from ordinary employment records
The ADA (42 U.S.C. §12112(d)(3)(B), (4)(C)) requires that information obtained through employment-related medical examinations or disability-related inquiries "shall be collected and maintained on separate forms and in separate medical files, and be treated as a confidential medical record," with only narrow enumerated exceptions.
This requirement applies broadly: pre-employment medical exams (post-offer), periodic medical surveillance required by OSHA standards, fitness-for-duty exams, voluntary wellness-program medical questionnaires, and many workers' compensation records that intersect with employment.
GINA Title II (2008) layers an equivalent — and in some ways stricter — separate-file confidentiality requirement onto genetic information, defined to include family medical history. A simple "does this run in your family?" question on an intake form triggers GINA's protections.
The EEOC's 2000 Enforcement Guidance on Disability-Related Inquiries and Medical Examinations makes clear the confidentiality duty attaches the moment medical information is obtained — it does not depend on whether the employee is later found to have a disability, or whether any adverse action ever follows.
Why the data is dangerous in the wrong hands
Diagnosis and lab data routinely reveal information tied to legally protected characteristics: disability status, pregnancy, mental illness, substance-use disorder, and genetic predisposition. Each is separately protected against employment discrimination — by the ADA, GINA, Title VII, the Pregnancy Discrimination Act, and overlapping state statutes.
If that data reaches the people who make hiring, promotion, discipline, or termination decisions, it does not stay inert. Courts and the EEOC treat a decisionmaker's knowledge of a diagnosis as direct evidence relevant to discriminatory intent — converting what might have been a defensible personnel action into a case with a documented motive. The firewall exists precisely to keep clinical knowledge out of the hands of people making non-clinical decisions.
Separating Occupational Health Records from HR and Management Systems
The firewall is not a metaphor for something abstract — it is a concrete organizational, physical, and electronic separation the ADA requires employers to build between the occupational-health function and every other employment system. On one side: clinicians bound by professional confidentiality duties. On the other: HR and management, who should see none of the underlying clinical record.
- Separate file/system: Storage requirement (apart from the personnel file)
- 30 years: OSHA medical record retention (29 CFR §1910.1020, many exposure records)
- 3: ADA disclosure exceptions (supervisors, first-aid staff, gov't investigators)
- 15+ employees: GINA covered-entity threshold (Title II employment provisions)
Why "firewall" is the right mental model
Treat occupational-health records the way a network architect treats a sensitive database: a separate system, separate credentials, and a narrow, audited interface for anything that needs to cross. Occupational health staff — nurses, physicians, physician assistants — already operate under an independent professional and licensing duty of confidentiality that HR staff do not share.
In practice this means: a distinct file cabinet or a distinct access-controlled database; no shared drive with the general HRIS; and job titles alone should never grant access. "HR generalist" is not a clinical role, no matter how routine the request feels.
The three narrow ADA exceptions to confidentiality
§12112(d)(3)(B) enumerates exactly what may cross the wall, and to whom:
1. Supervisors and managers may be told about necessary restrictions on the employee's work duties, and necessary accommodations 2. First-aid and safety personnel may be told if the disability might require emergency treatment 3. Government officials investigating ADA compliance may be given relevant information upon request
Nothing else, and no one else. Critically, EEOC guidance is explicit that even within these three exceptions, only the fact of a restriction or accommodation need may be shared — never the underlying diagnosis, prognosis, or clinical rationale behind it.
A supervisor may lawfully be told "this employee cannot lift more than 10 kg for six weeks." The same supervisor may never lawfully be told why — not the diagnosis, not the surgery, not the medication causing drowsiness.
HIPAA's narrower — and often misunderstood — role in the employment context
HIPAA's Privacy Rule generally does not govern an employer's own employment records. It applies to "covered entities" — health plans, health care clearinghouses, and providers who conduct standard electronic transactions — and their business associates, not to an employer acting purely as an employer.
An occupational-health clinic that bills insurance for the visit may itself be a HIPAA covered entity, and the record it holds is protected health information while it sits there. But once a fitness-for-duty conclusion is transmitted to the employer for employment purposes, it typically becomes an employment record governed by the ADA's separate-file rule, not HIPAA's Privacy Rule. Employers who assume "our vendor is HIPAA-compliant" have covered internal HR handling are relying on the wrong statute.
What May Cross the Firewall: Conclusions, Not Clinical Detail
The gate in this simulation enforces the "minimum necessary" principle borrowed from HIPAA and applied by best practice across occupational health: translate clinical findings into a functional statement before anything crosses, and give each recipient only what their specific role requires — nothing more.
- 3: Disclosable output categories (fitness status, restrictions, accommodation)
- 45 CFR §164.502(b): Minimum-necessary standard (HIPAA rule, widely adopted by analogy)
- Functional, not diagnostic: Restriction language style ("no lifting > 10kg" not "post-op hernia repair")
- ≤ 1 sentence: Recommended disclosure length (conclusion-only communication norm)
The functional-limitation standard
Best practice — and, for supervisor notifications, the ADA's explicit statutory limit — is that the occupational-health provider translates every clinical finding into a functional-capacity statement before it leaves the vault: can or cannot perform a specific task, for how long, under what conditions.
The employer-side recipient receives only that translated statement. If the translation is done correctly, HR and supervisors could not reconstruct the diagnosis even if they wanted to — "no overhead lifting for four weeks" is consistent with dozens of unrelated conditions.
Minimum necessary and "need to know"
Minimum necessary is a per-recipient standard, not a single line drawn once for the whole company:
• A direct supervisor needs the restriction, not the diagnosis • A safety officer needs to know only whether emergency response instructions are required • HR/benefits staff coordinating an accommodation need the accommodation request and any documentation strictly necessary to substantiate and fulfill it • Payroll, IT, and general management need none of it
Each additional person who receives clinical detail beyond their specific need widens the breach surface without adding any operational value.
The interactive accommodation process without full medical disclosure
When an employee requests a reasonable accommodation, the ADA obligates the employer to engage in an interactive process to identify an effective accommodation — but the employer's right to documentation is limited to what is necessary to establish that the employee has a covered disability and needs the accommodation requested.
Employers may not use the accommodation request as a pretext to demand the complete medical file. A request for "reasonable documentation" is not a request for unrestricted access, and occupational-health staff should push back on demands that exceed it.
What may vs. may not be disclosed to the employer
| Product | Indication | Trial Design | Key Result |
|---|---|---|---|
| Fitness-for-duty (yes/no) | Disclosable | Core employment-relevant conclusion | ADA §12112(d)(3)(B) — necessary-restriction notice |
| Work restrictions (functional) | Disclosable | e.g. "no lifting > 10 kg for 6 weeks" | ADA §12112(d)(3)(B) — supervisor notification |
| Accommodation need (type only) | Disclosable, limited | What is needed, not why | ADA interactive-process obligation |
| Emergency treatment flag | Disclosable to safety staff | Whether a condition may require emergency response | ADA §12112(d)(3)(B)(ii) |
| Specific diagnosis / condition | Not disclosable | No employer need-to-know | ADA confidentiality requirement |
| Lab values / test results | Not disclosable | Raw clinical data | ADA confidentiality + minimum necessary |
| Medications prescribed | Not disclosable | Reveals condition indirectly | ADA confidentiality requirement |
| Genetic info / family history | Not disclosable | Narrow exceptions only | GINA Title II §202 |
| Mental health treatment detail | Not disclosable | Heightened sensitivity | ADA + state confidentiality statutes |
| De-identified aggregate statistics | Disclosable (aggregate only) | No individual identified | OSHA recordkeeping / population reporting |
When the Firewall Fails — Consequences of Improper Disclosure
Most confidentiality breaches are not dramatic hacks — they are a hallway comment, a forwarded email with the full clinical note attached instead of the restriction summary, or a shared drive where the occupational-health folder was never actually separated from the general HRIS. Once a diagnosis crosses, the legal exposure is immediate and does not depend on anyone acting on it.
- $300,000: ADA damages cap, 500+ employees (42 U.S.C. §1981a(b)(3))
- $50,000: ADA damages cap, 15–100 employees (smallest employer tier, same statute)
- Same caps as ADA/Title VII: GINA remedy scheme (incorporates §1981a(b)(3))
- ~20,000+/yr: ADA charges filed with EEOC (recent years) (a share involve confidentiality claims)
How breaches typically happen
The mechanisms are mundane and recurring:
• An occupational-health nurse mentions a diagnosis to a supervisor in an informal conversation, intending only to explain a restriction • HR requests — and receives — the full medical note instead of a functional-capacity summary • IT provisions a shared drive or HRIS module without separating the occupational-health folder from general personnel files • An email chain forwards the complete clinic visit note rather than a one-line restriction statement • A manager, given system access "to check on a direct report," is able to browse fields never intended for their role
None of these require malice. Nearly all of them are a control failure at exactly the point this simulation visualizes as the gate.
Legal exposure once a diagnosis crosses the wall
The ADA confidentiality provision is generally treated as violated by the disclosure itself — courts and the EEOC do not require proof that the employer additionally used the information to justify a per se claim, although some circuits require a showing of resulting harm before damages are available, creating a real circuit split employers should not rely on.
Beyond the confidentiality claim itself, once a decisionmaker has knowledge of a diagnosis, any later adverse action against that employee becomes far more litigable: the plaintiff no longer has to prove the employer knew about a disability — the improper disclosure proves it for them. Remedies can include compensatory and punitive damages (subject to the §1981a(b)(3) caps above), back pay, reinstatement, and attorney's fees.
Statutory damages caps scale with employer size: $50,000 (15–100 employees), $100,000 (101–200), $200,000 (201–500), and $300,000 (500+) under 42 U.S.C. §1981a(b)(3) — the same cap structure Title VII and GINA claims use, and it applies per complaining party, not per violation.
The enforcement and remediation pattern
EEOC investigations into occupational-health confidentiality failures typically surface a common root cause: medical information was stored or transmitted through the same systems and personnel used for ordinary HR functions, with no technical or procedural separation.
When these matters resolve — through settlement, consent decree, or conciliation — the corrective terms are strikingly consistent regardless of industry: mandatory confidentiality training for anyone with employee-facing HR duties, demonstrable separation of medical files from personnel files (physical or electronic), a defined and audited access-control policy, and in many cases an independent monitor for a period of years. The compliant system in the next stage of this simulation is, in effect, what these remediation plans require after the fact.
Building the Compliant System — Access Control, Audit Trails, and Culture
A firewall that only exists on paper fails under normal operating pressure — a rushed accommodation request, a new HR hire who doesn't know the rules, a well-meaning supervisor asking "just tell me what's wrong." A compliant program survives that pressure because the controls are technical and procedural, not merely aspirational.
- 3–4: Recommended access tiers (clinical / HR-limited / supervisor / none)
- Up to 30 years: Audit log retention (medical records) (29 CFR §1910.1020 for many exposure records)
- Annual: Recommended training cadence (ADA/GINA confidentiality refresher)
- 4: Core technical controls (separate storage, RBAC, minimum necessary, audit log)
Role-based access control (RBAC) design
A workable tier structure looks like this:
• Occupational-health clinicians: full access to the clinical record they created — governed by their own professional licensing confidentiality duties • HR/benefits staff coordinating accommodations: access to the accommodation request and supporting documentation strictly necessary to process it — not the full chart • Direct supervisors: access to the restriction statement only, delivered as a translated functional summary • Safety/first-aid personnel: access to an emergency-relevant flag only, with no diagnostic detail • IT, payroll, general management: no access by default, full stop
Access should be granted by role, expire when the role changes, and be reviewed on a fixed schedule — not accumulated indefinitely as people move through the organization.
Audit trails and technical safeguards
Every access to the occupational-health system should be logged with who accessed it, when, and which specific fields were viewed — not just that "the record" was opened. Encryption at rest and in transit is table stakes; the audit log is what turns a policy into something enforceable.
Automated alerting on anomalous access patterns catches what training alone will not: a supervisor account querying a diagnosis field, an HR account pulling records for employees outside their assigned unit, or bulk exports outside normal business hours. Periodic access reviews — not just incident-driven ones — close accounts that accumulated permissions no one remembers granting.
The audit trail is the single control most consistently required in EEOC consent decrees after a confidentiality violation — because it is the only control that lets an organization prove, after the fact, exactly who saw what and when.
Governance culture and ongoing compliance
Technical controls only work alongside a written policy every manager can point to, annual training that uses concrete examples (not just statutory citations), and a clear, non-retaliatory channel for reporting suspected breaches.
This program does not operate in isolation from other confidentiality regimes an employer juggles simultaneously: FMLA medical certifications, workers' compensation records, and GINA's genetic-information rules all carry overlapping — and sometimes divergent — confidentiality requirements. A mature program maps all of them onto the same underlying architecture demonstrated in this stage: separate storage, tiered access, minimum-necessary disclosure, and a complete audit trail.
This simulation demonstrates the process of safeguarding employee medical data from unauthorized access by employers. It ensures compliance with privacy regulations and protects sensitive health information.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install