Employee Health Information and Group Insurance Claims
Employers

Employee Health Information and Group Insurance Claims

Employers
Tim Jones
Tim JonesHead of Employee Lab

Key Takeaway

NZ employers should collect and share only the personal information necessary for a group insurance claim, identify the lawful basis for each information flow, keep health and claim details secure, and use direct insurer or adviser channels where appropriate.

A group insurance claim can involve employment, payroll and health information at a difficult time for an employee or their family. The employer should help the claim reach the right people without treating access to workplace records as permission to collect or disclose everything it holds. This guide explains a practical Privacy Act 2020 approach for New Zealand employers.

Start with the purpose, not a list of documents

Identify the claim process, the information being requested, who will receive it and why it is needed. The Office of the Privacy Commissioner’s Principle 1 guidance says an organisation may collect personal information only for a lawful purpose connected with its work and only when the information is necessary for that purpose.

An insurer’s request does not by itself settle what the employer may collect, use or disclose. Check the current policy and scheme-administration documents, the notice given to employees and the legal basis for this particular information flow.

Keep the employer’s role separate from the claimant’s. Employment or payroll confirmation may come from the employer, while personal claim forms, medical evidence and authorisations will often travel directly between the employee, treating provider and insurer.

Tell the employee how their information will be handled

When an organisation collects personal information directly from a person, Principle 3 requires reasonable steps to explain matters including why it is being collected, who will receive it, whether supply is voluntary or required and what may happen if it is not supplied.

Use a clear, claim-specific explanation. Identify the employer, insurer, adviser or administrator involved; describe the information requested; and explain the purpose and intended recipient. A broad workplace privacy statement may not answer those questions for a particular claim.

Do not ask an employee to send diagnosis details, medical reports or claim forms through an ordinary HR inbox when the insurer or authorised adviser provides a more appropriate direct channel.

Treat employment information as personal information too

Health information is especially sensitive. The Privacy Commissioner’s employee health-information guidance says an employer cannot ask a doctor for medical information unless the employee agrees, while recognising that some return-to-work situations may require more information with the employee’s knowledge and permission.

Employment dates, earnings, absence records and scheme membership are not automatically outside the Privacy Act. They are still personal information. Whether the employer may disclose them depends on why they were collected, what the employee was told, the scheme process and any other applicable legal basis.

Confirm only the information the authorised process needs. Avoid adding manager impressions, assumptions about a diagnosis or unrelated employment history.

Check the basis for use and disclosure

The Privacy Commissioner explains that Principle 10 generally limits use to the purpose for which information was obtained. Principle 11 generally limits disclosure, subject to grounds set out in the Act. A person’s authorisation is one possible ground; it is not sensible to assume every claim request is automatically authorised.

Where authorisation is the basis, make the request clear enough for the employee to understand what information will be shared, with whom and for what claim purpose. Keep a record of the authorisation and stay within it.

Other laws or a specific Privacy Act ground may apply in some circumstances. If the basis is unclear, pause the disclosure and ask the organisation’s privacy officer or a qualified lawyer rather than improvising during the claim.

Secure, retain and correct claim information

Principle 5 requires reasonable safeguards against loss, unauthorised access, use, modification, disclosure and other misuse. Limit claim access to people who need it, use the agreed claim channel and keep sensitive details out of broad email chains and general manager notes.

Principle 9 says personal information must not be kept longer than required for a lawful use. Decide where necessary claim records belong and how long they need to be retained instead of leaving duplicates in inboxes, downloads and shared folders.

People can ask for access to their own information under Principle 6 and request correction under Principle 7. Accurate records of what the employer received and disclosed make those requests easier to handle.

Prepare for a privacy breach

Sending claim information to the wrong recipient, allowing unauthorised access or losing a document can be a privacy breach. Contain the problem, preserve the facts and involve the organisation’s privacy officer promptly.

The Privacy Commissioner’s breach guidance says an organisation must notify the Commissioner and affected people as soon as it is practically able when a breach has caused, or is likely to cause, serious harm.

Do not wait for a claim to create the process. Set the secure channel, access rules, escalation contact and breach response before employees need them.

A practical employer claim workflow

First, give the employee the correct insurer or adviser contact. Second, verify each employer request against the scheme process and the purpose for which the relevant records are held. Third, provide only accurate, necessary information through the agreed channel. Fourth, record the request, basis, recipient and date.

The group insurance claims article explains the roles around a claim. The fuller Claims and Continuation guide covers evidence, complaints and employment ending.

Employers that need process support can visit Claims Support or Claims and Administration Support. For help with a current process, contact Employee Lab, but do not put private medical details in the general contact form.

Sources checked

Frequently Asked Questions

Can an employer share employee health information with an insurer?

Not automatically. The employer should identify a lawful basis under the Privacy Act 2020 and stay within the purpose and scope of that basis. If relying on the employee’s authorisation, explain what will be shared, with whom and why.

Can an employer send salary or absence information without checking first?

Employment and payroll records are still personal information. Check the scheme process, why the information was collected, what the employee was told and the basis for disclosing it. Supply only the accurate information necessary for the authorised process.

Should HR hold the employee’s medical claim documents?

Only when there is a necessary and lawful reason for the employer to hold them. Where the insurer or authorised adviser has a secure direct channel, it will often be more appropriate for the employee and medical provider to use that channel.

What should an employer do after a claim-information privacy breach?

Contain the breach, involve the organisation’s privacy officer and assess the risk of serious harm. If the breach has caused or is likely to cause serious harm, notify the Privacy Commissioner and affected people as soon as practically able.

Related Articles