One of the biggest misconceptions in occupational health is that every audiogram is automatically protected by HIPAA. In reality, whether HIPAA applies depends on who maintains the record and in what capacity. The same hearing test can be an employer's OSHA compliance record in one workflow and protected health information in another. According to CDC/NIOSH, roughly 22 million U.S. workers are exposed to hazardous noise, and the audiometric records their programs generate sit at the intersection of OSHA 29 CFR 1910.95, HIPAA, and a growing patchwork of state privacy laws. This guide walks through which framework governs which record, and why the answer matters.
Three Legal Frameworks, Three Different Jobs
OSHA and HIPAA are not interchangeable, and they were never designed to be. Each framework governs a different kind of record held by a different kind of party:
| Framework | Governs | Typical Record Holder |
|---|---|---|
| OSHA (29 CFR 1910.95, 1910.1020) | Employer hearing conservation records: audiometric test records, noise exposure records, STS determinations | Employer |
| HIPAA | Protected health information (PHI) maintained by covered entities and their business associates | Healthcare provider (clinic, physician, audiologist) |
| State privacy laws | Additional privacy protections that may layer on top of federal requirements | Employer and/or provider, depending on the state |
When Does HIPAA Actually Apply?
HIPAA generally applies when:
- A covered entity (a hospital, clinic, physician, audiologist, or other healthcare provider that conducts covered transactions) creates or maintains the record, or
- A business associate maintains the record on behalf of that covered entity.
HIPAA generally does not apply when:
- An employer maintains hearing conservation records for OSHA compliance in its role as employer.
This is not a loophole; it is written into the regulation. HHS excludes “employment records held by a covered entity in its role as employer” from the definition of protected health information (45 CFR 160.103), and an employer that is not a healthcare provider is typically not a covered entity in the first place. OSHA, meanwhile, affirmatively requires employers to maintain and use these records: audiometric test records must be retained under 1910.95(m), treated as employee medical records under 1910.1020, and made available to the employee within 15 days of a request. The two frameworks can touch the same underlying test data, for example when a reviewing audiologist retains a copy in a clinical system, but they attach to different holders playing different roles.
Why Employer Access Exists in the First Place
It can feel counterintuitive that employer personnel handle hearing test data at all. But OSHA's hearing conservation standard assigns the employer obligations that cannot be met without it. Employers must:
- Identify standard threshold shifts (STS) by comparing annual audiograms to baselines
- Notify affected employees in writing within 21 days of an STS determination
- Ensure follow-up actions, including retesting, refitting of hearing protection, and referral where appropriate
- Manage hearing protection requirements for exposed employees
- Maintain records for the duration of employment plus 30 years, and produce them for OSHA compliance officers and authorized employee representatives
Someone at the employer necessarily administers this program. The real question is not whether employer personnel may access hearing conservation records; it is which personnel, with what level of visibility, under what controls.
Role-Based Access: Safety Is Not the Same as a Line Supervisor
Discussions of audiogram privacy often conflate very different roles. A production supervisor who manages an employee's day-to-day work is not in the same position as the people who run the hearing conservation program:
- EHS Manager, responsible for the program's regulatory compliance
- Hearing Conservation Administrator, tracking testing schedules, STS determinations, and follow-up
- Occupational Health Nurse, reviewing results and coordinating referrals
- HR Benefits Administrator, handling recordkeeping and notification obligations
These roles often have legitimate operational reasons to administer the OSHA program. A line supervisor typically does not need underlying threshold data to do their job; knowing that an employee requires refitting or a retest is usually sufficient.
Employers should implement role-based access controls that align with job responsibilities and internal privacy policies. Organizations differ in how they assign access to Safety, HR, Occupational Health, and EHS personnel, and those differences are legitimate. What matters is that access maps to operational need and is documented.
Minimum Necessary vs. Operational Need
Rather than drawing absolute lines about who “can” and “cannot” see an audiogram, organizations should evaluate whether different user roles require different levels of visibility. Some employers prefer that administrators view only compliance status and required follow-up actions. Others authorize designated occupational health or EHS personnel to review complete audiometric histories, because that is what it takes to catch a developing shift and act on it. Both postures can be reasonable; the point is to decide deliberately, document the decision, and enforce it in the systems that hold the records.
Where Business Associate Agreements Fit
Business Associate Agreements (BAAs) are a HIPAA construct: they bind a vendor that handles PHI on behalf of a covered entity. That means whether a BAA is needed depends on whose record the vendor is handling and in what role.
Soundtrace is not a HIPAA covered entity. When Soundtrace provides services to third-party audiologists or physicians who are HIPAA covered entities, Soundtrace executes Business Associate Agreements where appropriate. Employer customers generally do not require BAAs solely because they administer an OSHA hearing conservation program, since employment records held by an employer in its role as employer fall outside HIPAA's definition of PHI. Regardless of which framework applies, strong security practices, including SOC 2 Type II controls, encryption, and access logging, are appropriate for records this sensitive.
How Soundtrace's Architecture Handles Both Worlds
Modern hearing conservation programs often involve both frameworks at once: an employer-administered OSHA program on one side, and reviewing audiologists or physicians on the other. Soundtrace supports both employer-administered OSHA workflows and provider-administered clinical workflows. When supporting HIPAA covered entities, Soundtrace executes BAAs and applies HIPAA safeguards. Employer-administered OSHA workflows are managed separately according to applicable regulatory requirements, with role-based access controls so each organization can align visibility with its own policies.
Frequently Asked Questions
The Key Takeaway
The question isn't whether an audiogram is “medical.” The question is which legal framework governs the record in a particular workflow. OSHA governs employer hearing conservation records. HIPAA governs protected health information maintained by covered entities and their business associates. Modern hearing conservation programs often involve both, which makes role-based governance and clear data ownership essential.
OSHA Workflows and Clinical Workflows, Both Handled
Soundtrace supports employer-administered OSHA programs and provider-administered clinical workflows on one platform, with SOC 2 Type II controls, role-based access, and 30-year retention built in.
Get a Free Quote