Skip to content
View in the app

A better way to browse. Learn more.

BariatricPal

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Join BariatricPal free

  • Ask your own questions
  • Reply and follow topics
  • Message other members
  • No cost, no spam

I told my boss and now I'm upset!

I finally told my nosey boss that i was having a 'procedure' done on Monday and now the whole office knows. I only mentioned it to her. I am so embarassed because people are coming up to me asking what am I getting done?!! Another asked how long would i be out. None of your damn business. Isn't some sort of HIPAA violation. Can I sue my employer??? Do I have a case?

I should also mention that i never stated that i am having surgery only a 'procedure' but my out of office notice filled out by the surgeons office has Surgical specialist on it..

  • Replies 45
  • Views 3k
  • Created
  • Last Reply

Featured Replies

HIPAA does not apply to employers, unless you work at a hospital or other covered healthcare-related entity and are also a patient there. I completely understand your need for privacy. I'm sure your boss and coworkers needed to know something--eg, that you would be out on medical leave. I would leave it at that...they really don't need to know anything else. If someone pries more, either change the subject or use the old Dear Abbey retort of: "Why do you ask?" Most people don't have a good response.

HIPAA does not apply to employers' date=' unless you work at a hospital or other covered healthcare-related entity and are also a patient there. I completely understand your need for privacy. I'm sure your boss and coworkers needed to know something--eg, that you would be out on medical leave. I would leave it at that...they really don't need to know anything else. If someone pries more, either change the subject or use the old Dear Abbey retort of: "Why do you ask?" Most people don't have a good response.[/quote']

That's not true. I work at FedEx and our hr representative even went over hippa and employees. Hippa is covered by any business that offers healthcare.

That's not true. I work at FedEx and our hr representative even went over hippa and employees. Hippa is covered by any business that offers healthcare.

Fyre, see link above. Your HR rep is misinformed, or did not communicate the info very well. I thought this was the case as well at one time, and I asked an attorney friend about it who specializes in HIPAA and other healthcare regulatory issues. I was actually shocked when he told me--but I trust his expertise, and then I double-checked it on the HHS Web site and it's correct (see link above). There is of course the whole other issue of HR respecting your privacy and being professional, but that's different than a HIPAA violation.

Lol I doubt a multimillion dollar company is wrong if you look more into that web site it says:

Health Plans. Individual and group plans that provide or pay the cost of medical care are covered entities.4 Health plans include health, dental, vision, and prescription drug insurers, health maintenance organizations (“HMOs”), Medicare, Medicaid, Medicare+Choice and Medicare supplement insurers, and long-term care insurers (excluding nursing home fixed-indemnity policies). Health plans also include employer-sponsored group health plans, government and church-sponsored health plans, and multi-employer health plans. There are exceptions—a group health plan with less than 50 participants that is administered solely by the employer that established and maintains the plan is not a covered entity. Two types of government-funded programs are not health plans: (1) those whose principal purpose is not providing or paying the cost of health care, such as the food stamps program; and (2) those programs whose principal activity is directly providing health care, such as a community health center,5 or the making of grants to fund the direct provision of health care. Certain types of insurance entities are also not health plans, including entities providing only workers’ compensation, automobile insurance, and property and casualty insurance. If an insurance entity has separable lines of business, one of which is a health plan, the HIPAA regulations apply to the entity with respect to the health plan line of business.

It says it in the first line.

Fyre, check out this test to see if a company is a covered HIPAA entity. Fed Ex would not qualify. This is from the Centers for Medicare & Medicaid Services which helps administer HIPAA:

http://www.cms.gov/Regulations-and-Guidance/HIPAA-Administrative-Simplification/HIPAAGenInfo/AreYouaCoveredEntity.html

Are You a Covered Entity?

The Administrative Simplification standards adopted by Health and Human Services (HHS) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) apply to any entity that is

  • a health care provider that conducts certain transactions in electronic form (called here a "covered health care provider").
  • a health care clearinghouse.
  • a health plan.

An entity that is one or more of these types of entities is referred to as a "covered entity" in the Administrative Simplification regulations.

Doesn't look like the link shows where an employer or business is a covered entity.

Even that chart says we're covered unless you or i are reading it wrong. It says a health plan which we have is covered so I'm not understanding where your saying its not?

Lol I doubt a multimillion dollar company is wrong if you look more into that web site it says:

Health Plans. Individual and group plans that provide or pay the cost of medical care are covered entities.4 Health plans include health, dental, vision, and prescription drug insurers, health maintenance organizations (“HMOs”), Medicare, Medicaid, Medicare+Choice and Medicare supplement insurers, and long-term care insurers (excluding nursing home fixed-indemnity policies). Health plans also include employer-sponsored group health plans, government and church-sponsored health plans, and multi-employer health plans. There are exceptions—a group health plan with less than 50 participants that is administered solely by the employer that established and maintains the plan is not a covered entity. Two types of government-funded programs are not health plans: (1) those whose principal purpose is not providing or paying the cost of health care, such as the food stamps program; and (2) those programs whose principal activity is directly providing health care, such as a community health center,5 or the making of grants to fund the direct provision of health care. Certain types of insurance entities are also not health plans, including entities providing only workers’ compensation, automobile insurance, and property and casualty insurance. If an insurance entity has separable lines of business, one of which is a health plan, the HIPAA regulations apply to the entity with respect to the health plan line of business.

It says it in the first line.

You're misunderstanding. Fed Ex may have an employer-sponsored health plan as many large companies do, but legally they cannot administer the plan themselves. They contract with a company to do that, and that entity is the one that is subject to HIPAA regulations. I have worked in the medical communications field for 20 years and have been covering these issues for physicians and health plans for over a decade--so this is based on professional experience in this area as well as the clarification from my attorney friend who specializes in this area. I'm not trying to get into an argument about it, I just want people to have the correct information, because if someone did want to submit a complaint, it wouldn't do any good to file a HIPAA complaint against a company that isn't a covered entity. I'm sure there are other ways to let concerns be known, though. I feel badly this happened to the OP.

I agree with TES. It doesn't include the business/employer who offers the health plan it's the health plan personnel who are the HIPAA covered entity

You're misunderstanding. Fed Ex may have an employer-sponsored health plan as many large companies do' date=' but legally they cannot administer the plan themselves. They contract with a company to do that, and that entity is the one that is subject to HIPAA regulations. I have worked in the medical communications field for 20 years and have been covering these issues for physicians and health plans for over a decade--so this is based on professional experience in this area as well as the clarification from my attorney friend who specializes in this area. I'm not trying to get into an argument about it, I just want people to have the correct information, because if someone did want to submit a complaint, it wouldn't do any good to file a HIPAA complaint against a company that isn't a covered entity. I'm sure there are other ways to let concerns be known, though. I feel badly this happened to the OP.[/quote']

Hmm I must check this out!!

At a very basic level, a "Health Plan" is defined as an ***, a PPO, an employer-sponsored health plan (which I believe Fed Ex has? but they aren't one--they contract with one), and soon, Health Insurance Exchanges mandated by PPACA. So that's what that first line refers to.

the asterisks were the acronym for Health Maintenance Organization -- lol! :)

Archived

This topic is now archived and is closed to further replies.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.