Editor’s Note: As workplaces reopen, many employers are grappling with whether to require employees to be vaccinated or to impose mask mandates. Some have faced resistance in the form of false claims that being asked to disclose one’s vaccination status is a violation of the Health Insurance Portability and Accountability Act’s Privacy Rule, or HIPAA.
To explain the rule, Margaret (Mimi) Foster Riley, a professor of law, public health sciences, and public policy at the University of Virginia, wrote this piece for . Riley has written and presented extensively about health care law, biomedical research, genetics, reproductive technologies, stem cell research, animal biotechnology, health disparities and chronic disease.

