HIPAA says that certain medical entities can't release your medical info to other entities without your express permission. So your company can't go to your doctor and demand to see your records without your involvement. But it isn't illegal for the company to know your medical info if you decide to reveal it.
no subject