The Practice

As part of group health insurance administration and return-to-work processes, HR routinely forwards employee medical certificates, fitness-for-duty reports, and sick leave documentation to the insurance broker, the insurer, and occasionally to third-party wellness vendors — often via email, without redaction of diagnosis details not required by the recipient.

 

Questions Raised for Compliance Review

  1. Does forwarding employee medical documentation to insurers and vendors require a distinct lawful basis beyond the employment contract?
  2. What risks arise from sharing unredacted medical information with parties whose need is limited to a narrower fact (e.g., fitness to work, claim eligibility)?
  3. What is the compliant approach to handling employee medical documentation in HR administration?

 

Is This Permitted Under DPDP?

Permissible for the narrow purpose of claims administration — but the current unredacted practice exceeds what is compliant.

Health data is treated with particular care under data protection frameworks generally, and DPDP requires that its processing be necessary and proportionate to the declared purpose. An insurer processing a claim needs confirmation of eligibility and diagnosis category relevant to the claim — not the complete medical certificate with incidental details unrelated to that claim.
 

Where the Breach Risks Sit

  • Over-disclosure beyond necessity — A medical certificate issued for a sick leave claim may disclose unrelated health history, medication, or mental health information that the insurer does not need to process that specific claim. Forwarding the full document rather than the relevant extract is a proportionality failure.
  • Email as an uncontrolled channel — Medical documents sent by regular email to a broker or insurer sit in inboxes, forwarding chains, and personal archives indefinitely, with no visibility for the organisation into how long the recipient retains them or who else within their organisation can access them.
  • Wellness vendor scope creep — Third-party wellness or EAP (employee assistance programme) vendors sometimes receive medical information for purposes broader than the specific service being delivered, without a clear boundary on what they may do with it, including whether it feeds into any aggregate reporting shared back with the employer.
  • No employee visibility into onward sharing — Employees who submit a medical certificate to HR are typically unaware of the full list of parties it is subsequently shared with, which undermines the transparency DPDP requires for processing of this nature.

 

The Ideal Compliant Approach

  1. Share only the relevant extract, not the full document. HR should redact or summarise medical certificates to the specific fact the recipient needs — claim eligibility, leave duration, fitness status — rather than forwarding the complete document with all clinical detail.
  2. Route sharing through a secure portal, not email. Where the insurer or broker offers a secure claims portal, use it in place of email attachments. Where none exists, encrypt attachments and confirm the recipient's retention and deletion practice contractually.
  3. Disclose the sharing chain to employees. At the point of enrolment in health insurance, employees should be informed which parties (insurer, broker, wellness vendor) may receive their medical documentation and for what specific purpose.
  4. Formalise data handling terms with brokers and vendors. Execute or update agreements with insurance brokers and wellness vendors to include DPDP-specific terms — retention limits, purpose restriction, and breach notification.

 

DPDP Risk Summary

ElementStatusRecommended Action
Full medical certificates forwarded unredactedExceeds necessityShare only the relevant extract or summary
Medical documents sent via standard emailUncontrolled channelUse secure portal or encrypted transmission
Wellness vendor scope undefinedPurpose not boundedDefine permitted use in vendor agreement
Employees unaware of onward sharingTransparency gapDisclose sharing chain at insurance enrolment
No DPDP terms with broker/insurer/vendorProcessor relationship ungovernedUpdate agreements with DPDP-specific clauses