HomeBlogHIPAA and OSHA Audiometric Records: What General Industry Employers Need to Know
audiometry

HIPAA and OSHA Audiometric Records: What General Industry Employers Need to Know

Matt Reinhold, COO & Co-Founder at SoundtraceMatt ReinholdCOO & Co-Founder11 min readApril 1, 2026
HIPAA & Privacy·OSHA Compliance·11 min read·Updated April 2026

One of the biggest misconceptions in occupational health is that every audiogram is automatically protected by HIPAA. In reality, whether HIPAA applies depends on who maintains the record and in what capacity. The same hearing test can be an employer's OSHA compliance record in one workflow and protected health information in another. According to CDC/NIOSH, roughly 22 million U.S. workers are exposed to hazardous noise, and the audiometric records their programs generate sit at the intersection of OSHA 29 CFR 1910.95, HIPAA, and a growing patchwork of state privacy laws. This guide walks through which framework governs which record, and why the answer matters.

Three Legal Frameworks, Three Different Jobs

OSHA and HIPAA are not interchangeable, and they were never designed to be. Each framework governs a different kind of record held by a different kind of party:

FrameworkGovernsTypical Record Holder
OSHA (29 CFR 1910.95, 1910.1020)Employer hearing conservation records: audiometric test records, noise exposure records, STS determinationsEmployer
HIPAAProtected health information (PHI) maintained by covered entities and their business associatesHealthcare provider (clinic, physician, audiologist)
State privacy lawsAdditional privacy protections that may layer on top of federal requirementsEmployer and/or provider, depending on the state

When Does HIPAA Actually Apply?

HIPAA generally applies when:

  • A covered entity (a hospital, clinic, physician, audiologist, or other healthcare provider that conducts covered transactions) creates or maintains the record, or
  • A business associate maintains the record on behalf of that covered entity.

HIPAA generally does not apply when:

  • An employer maintains hearing conservation records for OSHA compliance in its role as employer.

This is not a loophole; it is written into the regulation. HHS excludes “employment records held by a covered entity in its role as employer” from the definition of protected health information (45 CFR 160.103), and an employer that is not a healthcare provider is typically not a covered entity in the first place. OSHA, meanwhile, affirmatively requires employers to maintain and use these records: audiometric test records must be retained under 1910.95(m), treated as employee medical records under 1910.1020, and made available to the employee within 15 days of a request. The two frameworks can touch the same underlying test data, for example when a reviewing audiologist retains a copy in a clinical system, but they attach to different holders playing different roles.

Why Employer Access Exists in the First Place

It can feel counterintuitive that employer personnel handle hearing test data at all. But OSHA's hearing conservation standard assigns the employer obligations that cannot be met without it. Employers must:

  • Identify standard threshold shifts (STS) by comparing annual audiograms to baselines
  • Notify affected employees in writing within 21 days of an STS determination
  • Ensure follow-up actions, including retesting, refitting of hearing protection, and referral where appropriate
  • Manage hearing protection requirements for exposed employees
  • Maintain records for the duration of employment plus 30 years, and produce them for OSHA compliance officers and authorized employee representatives

Someone at the employer necessarily administers this program. The real question is not whether employer personnel may access hearing conservation records; it is which personnel, with what level of visibility, under what controls.

Role-Based Access: Safety Is Not the Same as a Line Supervisor

Discussions of audiogram privacy often conflate very different roles. A production supervisor who manages an employee's day-to-day work is not in the same position as the people who run the hearing conservation program:

  • EHS Manager, responsible for the program's regulatory compliance
  • Hearing Conservation Administrator, tracking testing schedules, STS determinations, and follow-up
  • Occupational Health Nurse, reviewing results and coordinating referrals
  • HR Benefits Administrator, handling recordkeeping and notification obligations

These roles often have legitimate operational reasons to administer the OSHA program. A line supervisor typically does not need underlying threshold data to do their job; knowing that an employee requires refitting or a retest is usually sufficient.

A Defensible Access Posture

Employers should implement role-based access controls that align with job responsibilities and internal privacy policies. Organizations differ in how they assign access to Safety, HR, Occupational Health, and EHS personnel, and those differences are legitimate. What matters is that access maps to operational need and is documented.

Minimum Necessary vs. Operational Need

Rather than drawing absolute lines about who “can” and “cannot” see an audiogram, organizations should evaluate whether different user roles require different levels of visibility. Some employers prefer that administrators view only compliance status and required follow-up actions. Others authorize designated occupational health or EHS personnel to review complete audiometric histories, because that is what it takes to catch a developing shift and act on it. Both postures can be reasonable; the point is to decide deliberately, document the decision, and enforce it in the systems that hold the records.

Where Business Associate Agreements Fit

Business Associate Agreements (BAAs) are a HIPAA construct: they bind a vendor that handles PHI on behalf of a covered entity. That means whether a BAA is needed depends on whose record the vendor is handling and in what role.

Soundtrace is not a HIPAA covered entity. When Soundtrace provides services to third-party audiologists or physicians who are HIPAA covered entities, Soundtrace executes Business Associate Agreements where appropriate. Employer customers generally do not require BAAs solely because they administer an OSHA hearing conservation program, since employment records held by an employer in its role as employer fall outside HIPAA's definition of PHI. Regardless of which framework applies, strong security practices, including SOC 2 Type II controls, encryption, and access logging, are appropriate for records this sensitive.

How Soundtrace's Architecture Handles Both Worlds

Modern hearing conservation programs often involve both frameworks at once: an employer-administered OSHA program on one side, and reviewing audiologists or physicians on the other. Soundtrace supports both employer-administered OSHA workflows and provider-administered clinical workflows. When supporting HIPAA covered entities, Soundtrace executes BAAs and applies HIPAA safeguards. Employer-administered OSHA workflows are managed separately according to applicable regulatory requirements, with role-based access controls so each organization can align visibility with its own policies.


Frequently Asked Questions

Is every audiogram PHI?
No. It depends on who maintains the record and why. A record maintained by a covered entity or its business associate is generally PHI; a record maintained by an employer in its role as employer for OSHA compliance generally is not.
Does HIPAA apply to OSHA hearing conservation records?
Sometimes, but not always. OSHA governs the employer's copy of hearing conservation records. HIPAA attaches when the same test data is maintained by a covered entity, such as a reviewing physician or audiologist, or by that entity's business associate.
Can employer Safety personnel access hearing conservation records?
That depends on the organization's role assignments and applicable legal requirements. Employers generally need authorized personnel to administer their OSHA hearing conservation program, and role-based access controls should align visibility with job responsibilities.
Why does Soundtrace support BAAs?
Because third-party audiologists and physicians using Soundtrace may be HIPAA covered entities. Soundtrace executes BAAs with covered entities where appropriate; employer customers generally do not need one solely to run an OSHA program.

The Key Takeaway

The question isn't whether an audiogram is “medical.” The question is which legal framework governs the record in a particular workflow. OSHA governs employer hearing conservation records. HIPAA governs protected health information maintained by covered entities and their business associates. Modern hearing conservation programs often involve both, which makes role-based governance and clear data ownership essential.

OSHA Workflows and Clinical Workflows, Both Handled

Soundtrace supports employer-administered OSHA programs and provider-administered clinical workflows on one platform, with SOC 2 Type II controls, role-based access, and 30-year retention built in.

Get a Free Quote

Editorial Note

Noise level ranges, exposure figures, and industry statistics referenced in this article are directional estimates provided for educational and awareness purposes. They are drawn from publicly available research and general industry experience and may not reflect measured conditions at any specific workplace. Actual exposure levels can only be determined through workplace noise monitoring conducted at your facility.

Matt Reinhold, COO & Co-Founder at Soundtrace

Matt Reinhold

COO & Co-Founder, Soundtrace

Matt Reinhold is the COO and Co-Founder of Soundtrace, where he drives strategy and operations to modernize occupational hearing conservation. With deep expertise in workplace safety technology, Matt stays at the forefront of regulatory developments, audiometric testing innovation, and noise exposure management, helping employers build smarter, more compliant hearing conservation programs.

Related Articles

Stay in the loop

Get compliance updates, product news, and practical tips delivered to your inbox.