The sales call comes every spring. "We handle your HIPAA and OSHA compliance in one package, one annual training, one binder." The office manager, who has a dental practice to run, asks the reasonable question: are those the same thing? They are not. They are two federal laws, written by two departments, answering two different questions, and the only thing they have in common is that both apply to a small medical or dental office on the same Tuesday.
One note before the comparison. One Guy Consulting works on HIPAA. It does not sell OSHA services, and this article is orientation, not an OSHA program. Every OSHA fact below comes from OSHA's own website or the text of its standards; for an actual OSHA program, use OSHA's resources or a safety consultant. The HIPAA facts come from the regulation at 45 CFR Parts 160 and 164.
HIPAA vs OSHA: What Each Law Protects
HIPAA in One Paragraph
HIPAA's Privacy, Security, and Breach Notification Rules protect patients. They govern P.H.I. (Protected Health Information), the individually identifiable health information a practice creates or holds, and they bind covered entities (providers who bill electronically, health plans, clearinghouses) and their business associates. The enforcer is the HHS Office for Civil Rights. The core obligations are a risk analysis, written policies, workforce training, safeguards for paper and electronic records, patient rights such as access, and breach notification. Who is and is not covered is walked through in what is a covered entity under HIPAA.
OSHA in One Paragraph
OSHA, the Occupational Safety and Health Administration in the U.S. Department of Labor, protects workers. Its healthcare page lists the hazards it is concerned with in this setting: "bloodborne pathogens and biological hazards, potential chemical and drug exposures, waste anesthetic gas exposures, respiratory hazards, ergonomic hazards from lifting and repetitive tasks, laser hazards, workplace violence, hazards associated with laboratories, and radioactive material and x-ray hazards." Its dentistry page is direct about how the rules reach a dental office: "There are currently no specific OSHA standards for dentistry. However, exposure to numerous biological, chemical, environmental, physical, and psychological workplace hazards that may apply to dentistry are addressed in specific OSHA standards for general industry." The same is true of a medical office. Nobody wrote an OSHA rule for small clinics; the general industry standards apply to them as employers.
Side by Side
| HIPAA | OSHA | |
|---|---|---|
| Agency | HHS Office for Civil Rights | U.S. Department of Labor, OSHA |
| Who is protected | Patients and their health information | Employees |
| Who must comply | Covered entities and business associates | Employers, including practices with no HIPAA obligations at all |
| Core written document | Policies and procedures (164.316, 164.530(i)); the risk analysis (164.308(a)(1)(ii)(A)) | Exposure Control Plan (1910.1030(c)(1)); written hazard communication program (1910.1200(e)(1)) |
| Training cadence | New workforce members "within a reasonable period of time," and after a material policy change (164.530(b)(2)); security awareness program (164.308(a)(5)) | Bloodborne pathogens: "at the time of initial assignment" and "at least annually thereafter" (1910.1030(g)(2)(ii)) |
| Records retention | Six years from creation or last effective date (164.316(b)(2)(i), 164.530(j)(2)) | Bloodborne pathogens training records: 3 years (1910.1030(h)(2)(ii)); employee medical records per 1910.1020 |
| Fast reporting deadlines | Breach notice to patients within 60 days of discovery (164.404(b)) | Work-related death within 8 hours; in-patient hospitalization, amputation, or loss of an eye within 24 hours |
| What triggers it | Handling PHI | Having employees exposed to a hazard |
The OSHA Standards a Small Office Meets First
Bloodborne pathogens, 29 CFR 1910.1030. This is the standard that reaches every office where anyone draws blood, handles sharps, or cleans instruments. It "applies to all occupational exposure to blood or other potentially infectious materials." Each employer with an exposed employee "shall establish a written Exposure Control Plan designed to eliminate or minimize employee exposure," and that plan "shall be reviewed and updated at least annually." The employer "shall make available the hepatitis B vaccine and vaccination series to all employees who have occupational exposure," and it must be "made available at no cost to the employee." Training is due at initial assignment and at least annually, and "annual training for all employees shall be provided within one year of their previous training." Training records must show the dates, the content, the trainer's name and qualifications, and the names and job titles of attendees, and be kept for three years. The training content itself is covered in bloodborne pathogen training for healthcare.
Hazard communication, 29 CFR 1910.1200. The standard requires "all employers to provide information to their employees about the hazardous chemicals to which they are exposed, by means of a hazard communication program, labels and other forms of warning, safety data sheets, and information and training." Employers must "develop, implement, and maintain at each workplace, a written hazard communication program" that includes "a list of the hazardous chemicals known to be present." Sterilants, disinfectants, and dental materials put most offices inside this rule.
Injury and illness recordkeeping, 29 CFR Part 1904. Size matters here. Under 1904.1(a)(1), "if your company had 10 or fewer employees at all times during the last calendar year, you do not need to keep OSHA injury and illness records" unless OSHA or the Bureau of Labor Statistics says otherwise in writing; the same paragraph adds that all covered employers "must report to OSHA any work-related incident that results in a fatality, the in-patient hospitalization of one or more employees, an employee amputation, or an employee loss of an eye." OSHA's recordkeeping page gives the clocks: 8 hours for a death, 24 hours for the others. Industry matters as much as headcount here. Under 1904.2(a)(1), an establishment classified in an industry group on the list at Appendix A to Subpart B of Part 1904 "does not need to keep OSHA injury and illness records" at all, whatever its size, unless the government asks for them under 1904.41 or 1904.42. That list includes 6211 Offices of Physicians, 6212 Offices of Dentists, and 6213 Offices of Other Health Practitioners, so most private medical and dental practices never keep the 300, 300A, and 301 forms. Hospitals, nursing homes, and home health agencies are not on the list. The fatality and hospitalization reporting duty applies to every employer either way.
Where the Two Rules Touch
1. Your own staff's medical records are OSHA records, not PHI. The hepatitis B vaccination record, the post-exposure evaluation, and the healthcare professional's written opinion for an employee are records 1910.1030(h)(1) requires the employer to keep. HIPAA's definition of PHI in 45 CFR 160.103 excludes information "in employment records held by a covered entity in its role as employer." Those files are governed by OSHA's confidentiality rule, which requires that they be "kept confidential" and "not disclosed or reported without the employee's express written consent to any person within or outside the workplace except as required by this section or as may be required by law." Different rule, same instinct: lock the cabinet.
2. When the practice treats another employer's workers, HIPAA has a door for OSHA. 45 CFR 164.512(b)(1)(v) permits a provider to disclose "findings concerning a work-related illness or injury or a workplace-related medical surveillance" to an employer when the care was provided at the employer's request and the employer "needs such findings in order to comply with its obligations, under 29 CFR parts 1904 through 1928" or a similar state law, provided the provider gives the patient written notice that such information goes to the employer. An occupational medicine visit is the classic case. The findings go; the rest of the chart does not.
3. A needlestick is one incident under two rulebooks. The exposed employee's evaluation and follow-up are OSHA obligations under 1910.1030(f), documented in the employee's OSHA medical record. Any information about the source patient is PHI, handled under HIPAA's minimum necessary standard and the rules on disclosure. The office's incident form should say which file each page goes into.
4. Training days can be shared; training records cannot. Many offices run one annual session covering both. That is fine, as long as the HIPAA sign-in sheet documents the privacy and security content 164.530(b) and 164.308(a)(5) require, and the OSHA record captures the dates, content summary, trainer, and attendees 1910.1030(h)(2) requires, kept for their own retention periods. The HIPAA side is laid out in HIPAA training implementation.
5. Both want a written program, reviewed on a schedule. OSHA's exposure control plan is reviewed "at least annually." HIPAA requires policies to be reviewed and updated "in response to environmental or operational changes" under 164.316(b)(2)(iii), and the security program evaluated periodically under 164.308(a)(8). Two binders, two review dates, one calendar. The HIPAA documentation list is in HIPAA documentation requirements.
The Bundle Question
Vendors sell the two together because the buyer is the same office manager. Whether the OSHA half is any good is outside this article. The HIPAA half is easy to test: ask whether it includes an "accurate and thorough" risk analysis of the practice's own systems, as 164.308(a)(1)(ii)(A) requires, or a checklist with the word "risk" on it. A packaged training video and a policy binder do not satisfy the Security Rule without the risk analysis behind them, and OCR's Security Rule settlements are, by their titles, about that gap. On the privacy side, the enforcement record reaches small offices directly: a dental practice paid $10,000 to settle social media disclosures of patients' PHI (October 2, 2019), and OCR settled a case concerning improper disposal of PHI (August 23, 2022). OSHA publishes its own enforcement data on osha.gov; this article does not summarize it.
What to Write Into the Policy: Two Binders
- HIPAA binder. Risk analysis and remediation plan; privacy and security policies; Notice of Privacy Practices; business associate agreements; training log; incident and breach log; six-year retention.
- OSHA binder. Exposure Control Plan with the annual review date; hazard communication program with the chemical list and safety data sheets; hepatitis B vaccination offers and declinations; bloodborne pathogens training records (three years); injury and illness forms if the office has more than ten employees; the 8-hour and 24-hour reporting contacts.
- One cross-reference page. Which file employee medical records go in (OSHA), which file patient records go in (HIPAA), how a needlestick is documented in both, and the 164.512(b)(1)(v) notice for occupational medicine patients.
- One calendar. HIPAA training at hire and on policy change, security evaluation annually; OSHA bloodborne pathogens training annually within one year of the last session, exposure control plan review annually.
- Two owners. The HIPAA privacy and security official under 164.530(a) and 164.308(a)(2), and whoever the office designates for safety; in a small practice it may be the same person, but the roles are separate.
The dental practice in the opening paragraph does need both. It also needs to know which one the vendor is actually good at. The HIPAA program is built on a risk analysis of that office's records and systems; the rest of the HIPAA picture for dentistry is in HIPAA dental compliance. The OSHA program is built on the hazards in that office's operatories, and that is a different conversation with a different expert.
---
FAQ
Are HIPAA and OSHA the same thing?
No. HIPAA (45 CFR Parts 160 and 164, enforced by HHS Office for Civil Rights) protects patients' health information. OSHA (U.S. Department of Labor) protects employees from workplace hazards. A medical or dental office must comply with both, separately.
Does OSHA have a specific standard for dental or medical offices?
No. OSHA's dentistry page states there are currently no specific OSHA standards for dentistry; the general industry standards, including bloodborne pathogens (1910.1030) and hazard communication (1910.1200), apply to the office as an employer.
Are employee vaccination and exposure records PHI under HIPAA?
No. 45 CFR 160.103 excludes information in employment records held by a covered entity in its role as employer. Those records are OSHA medical records under 1910.1030(h)(1) and must be kept confidential under that standard.
How often is OSHA bloodborne pathogens training required?
At the time of initial assignment to tasks with occupational exposure and at least annually thereafter, with each annual session within one year of the previous one, per 1910.1030(g)(2). Training records are kept for three years.
Does a practice with fewer than ten employees have to keep OSHA injury logs?
Under 1904.1(a)(1), a company with 10 or fewer employees at all times during the last calendar year does not need to keep OSHA injury and illness records unless told to in writing. Most medical and dental offices are exempt on industry grounds as well, since 1904.2 and Appendix A to Subpart B of Part 1904 list offices of physicians, dentists, and other health practitioners. Every employer must still report a work-related death within 8 hours and an in-patient hospitalization, amputation, or loss of an eye within 24 hours.
Conclusion
One Guy Consulting works on the HIPAA half of this article and does not offer OSHA services; the OSHA sections are orientation only. For the HIPAA half, the Full-Scope plan includes the risk analysis, the policy set, the training, and the business associate agreements, with consulting time to keep the HIPAA binder and the OSHA binder from being confused with each other. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- OSHA: Dentistry overview
- OSHA: Healthcare overview
- OSHA: Bloodborne pathogens overview
- 29 CFR 1910.1030 Bloodborne pathogens (osha.gov)
- 29 CFR 1910.1200 Hazard communication (osha.gov)
- 29 CFR 1904.1 Partial exemption for employers with 10 or fewer employees (osha.gov)
- 29 CFR 1904.2 Partial exemption for establishments in certain industries (osha.gov)
- OSHA: Recordkeeping requirements
- 45 CFR 160.103 (definitions, including protected health information)
- 45 CFR 164.512 (disclosures to employers at (b)(1)(v))
Related Reading