HIPAA, PHI and PII


What about HIPAA? 

HIPAA requires health care providers and their subcontractors to protect the privacy and security of personally identifiable health information created or collected by or on behalf of the health care provider.  SlateSafety is not a health care provider nor does SlateSafety provide any services to or for health care providers.  None of SlateSafety's products are a health care device and is not intended to be used by health care providers in the diagnosis or treatment of medical conditions.  As a result, we are not required to comply with HIPAA.  SlateSafety does, however, recognize that our clients entrust us with their personally identifiable information collected through our wearable.  Our use and disclosure of that personally identifiable information is governed applicable state and federal privacy laws and our Privacy Policy, which is available at https://slatesafety.com/privacy-policy.  We maintain commercially reasonable administrative, physical and technical safeguards to protect the security and integrity of your personal data.  For more information, please see the Terms of Service available at https://slatesafety.com/terms-of-service.


“OSHA medical and injury records are not governed by HIPAA because HIPAA explicitly excludes employment records maintained by an employer in its capacity as an employer. While HIPAA applies only to healthcare providers, health plans, and clearinghouses, workplace safety logs and medical files fall under Occupational Safety and Health Administration (OSHA) regulations.” Source: Recording Injuries and Illnesses of Temporary Workers versus HIPAA Requirements | Occupational Safet…


What about PHI? 

Protected health information (PHI) is any information in the medical record or designated record set that can be used to identify an individual and that was created, used, or disclosed in the course of providing a health care service such as diagnosis or treatment. We are not a health care provider nor do we provide any services to or for health care providers.  Our wearable is not a health care device and is not intended to be used by healthcare providers in the diagnosis or treatment of medical conditions.  As a result, none of the data is considered PHI. 


What about PII? 

Personally identifiable information (PII) data is usually broken into two parts, Sensitive and Non-Sensitive:

  1. Sensitive PII is sensitive information that directly identifies an individual and could cause significant harm if leaked or stolen. Examples of this are unique identification numbers such as driver's license numbers, passport numbers, biometric identification data such as fingerprints, retinal scans, financial information such as bank accounts or medical records. 
  2. Non-sensitive PII is personal data that, in isolation, would not cause significant harm to a person if leaked or stolen. Examples of this are a person's full name, mother's maiden name, telephone number, IP address, Place of birth, date of birth, mailing address, employment information, email address, race, ethnicity or religion. 

In the SlateSafety system, we do not store any Sensitive PII data but do have the option to include Non-sensitive PII, which would be only a person's full name and email address. 


Articles about HIPAA, PHI and PII? 

Here is a recent article from the Synergist, which independently validates our stance on the above topics - https://synergist.aiha.org/202412-industrial-hygiene-data-privacy. Please note: it requires an AIHA account to view.

Still need help? Contact Us Contact Us