OSHA 300 Privacy Concern Cases: the Log and Confidential List
An employer may need to record an injury or illness while keeping the worker's name off the OSHA 300 Log. Federal OSHA calls this a privacy concern case. The rule is narrow. It identifies six categories, tells the employer what to put in the name field, and requires a separate confidential list that connects the Log's case number to the worker. It does not let an employer label every embarrassing incident a privacy case or remove all details from a record.
This guide is for the person who maintains injury and illness records at an establishment covered by federal OSHA's Part 1904 recordkeeping rules. It starts after the decision that a case is recordable. If the open question is whether the incident is work related or recordable at all, use the broader OSHA 300 recordkeeping guide first. If a Log entry was entered incorrectly, the correction process belongs in the separate error-correction owner. State-plan and other privacy obligations may also need attention in a particular workplace. The steps below describe the federal Part 1904 baseline.
First decide whether the case is recordable
Privacy classification does not create an entry that would otherwise be absent. The employer first applies the relevant Part 1904 rules to decide whether a work-related injury or illness is recordable. For a case that must be recorded, 29 CFR 1904.29 requires an OSHA 300 Log entry and an OSHA 301 Incident Report, or equivalent forms. The rule gives seven calendar days from receiving information that a recordable case occurred to enter it on both forms.
This distinction matters when a manager receives a sensitive report and wants to protect the worker. The privacy rule changes how a qualifying case is identified on the Log. It does not excuse a covered employer from making the required entry. It also does not mean every allegation, near miss or first-aid event belongs on the Log. Apply the ordinary recordability decision first, then the privacy-case category test. Keep the factual basis for those two decisions separate in your working notes so a later reviewer can see which question was answered.
The six categories are a closed list
Section 1904.29, paragraphs b7 and b8 identifies the privacy concern categories and states that the list is complete for Part 1904. A case qualifies if it is a recordable injury or illness in one of these categories:
1. An injury or illness to an intimate body part or the reproductive system. 2. An injury or illness resulting from a sexual assault. 3. A mental illness. 4. HIV infection, hepatitis or tuberculosis. 5. A needlestick injury or cut from a sharp object contaminated with another person's blood or other potentially infectious material. Section 1904.8 supplies the definitions relevant to this category. 6. Another illness for which the employee voluntarily asks that their name not be entered on the Log.
The final category is easy to overread. It refers to other illnesses, not every injury a worker asks to keep private. The employee's voluntary request matters for that category. The category does not give an employer discretion to create a seventh type of privacy concern case. Nor does the employer need the employee to request privacy when one of the first five categories applies. Treat the category decision as a specific Part 1904 question and record the applicable category in a restricted working record, outside the employee-name field of the shareable Log.
The rule addresses the Log even when the underlying incident is sensitive for other reasons. For example, a highly publicised injury may identify the worker to colleagues, but public attention alone is not a new privacy category. Conversely, a qualifying case does not lose the rule's protection because a supervisor already knows who was involved. Avoid replacing the six categories with a vague internal label such as sensitive incident. Such a label can help route a matter confidentially inside the business, but it cannot answer the OSHA classification question.
What goes in the name field
For a qualifying privacy concern case, section 1904.29, paragraph b6 says the employer may not enter the employee's name on the OSHA 300 Log. Instead, enter privacy case where the name would normally appear. Do not put initials, a personnel number or a coded name in that field as a substitute for the prescribed wording. Those substitutes can defeat the purpose and can make a released Log point back to the individual.
Continue to complete the required Log information for the case. The employer should not blank the whole row or move the case entirely into a private spreadsheet. The rule still expects the recordable case to appear on the Log. The OSHA 301 Incident Report or equivalent form must also be completed for each case entered on the Log. The special Log name-field instruction should not be mistaken for permission to discard the underlying incident report. A team that uses an electronic form should check that its export or printed equivalent still produces the required entries without exposing the name on the 300 Log.
A simple recordkeeping workflow assigns a case number before the Log is circulated. The same case number then appears in the restricted cross-reference list. The number is an administrative link, not an invitation to put identifying details into a public note or file title. Verify the number against the Log before the entry is finalised. A mistyped number can make later updates, inspection responses and retention checks much harder.
Maintain the separate confidential list
Federal OSHA requires a separate, confidential list of the case numbers and employee names for privacy concern cases. The list lets the employer update the case and provide the information to government representatives if asked. Section 1904.29, paragraph b6 is the source of that duty. A Log with the words privacy case but no reliable confidential cross-reference is incomplete as a working system.
Keep the list separate from the ordinary copy of the OSHA 300 Log that will be produced for permitted employee access. Separation can be physical or electronic. The regulation does not prescribe a particular folder structure, encryption product, approval workflow or software feature. Restricted access, a clear record owner and a check before release are sensible employer controls because they make the confidentiality rule workable. Describe those controls as a process choice, not as an OSHA certification requirement.
The minimum cross-reference is the case number and employee name. An employer may need additional working information to find the correct 301 report or follow up on the case, but should avoid copying medical narrative into an unnecessary distribution list. Consider who genuinely needs to amend or produce the records. If a shared-drive export places the confidential list in the same folder as a general safety dashboard, change the access arrangement before the next request for records arrives. A list cannot be confidential merely because its file name says so.
Have a second authorised person check the case-number match where practical. This is a quality control suggestion, not a federal two-person sign-off rule. Keep a record of the category decision, the Log entry date and any later change to the case outcome in a restricted workflow. The Log itself remains the required record. Internal notes help explain how the business maintained it and prevent a privacy classification from being lost when staff change.
Write enough detail without identifying the worker
Removing a name may not be enough. A highly specific job title, location, shift, date or intimate description can identify the worker to someone who sees the Log. Section 1904.29, paragraph b9 lets an employer use discretion in describing a privacy concern case when there is a reasonable basis to believe the information would identify the employee. The employer must still enter enough to show the cause of the incident and the general severity. It need not include details of an intimate or private nature.
The editing test is practical: could a reader understand the type and seriousness of the event without working out whose private condition it concerns? Replace unnecessary intimate detail with a general description, while preserving the cause and general severity the rule requires. Do not turn the description into an empty phrase such as incident occurred. That would hide information the form is intended to capture. Do not put the name back into a free-text field after removing it from the name column. Review exported copies as well as the on-screen form, because print layouts and attachments can expose text that was not visible in a summary view.
This discretion concerns the OSHA 300 and 301 descriptions for privacy concern cases. It is not a general permission to make all OSHA entries anonymous. Review each field that may identify the person and keep the required information. For a case where no privacy category applies, use the ordinary form rules even if a manager would prefer an anonymous Log. Additional privacy laws or workplace policies may affect other records, but they do not rewrite Part 1904's closed privacy concern list.
Employee access to the Log is different from general disclosure
Under section 1904.35, an employee, former employee, personal representative or authorised employee representative may request the current or stored OSHA 300 Log for an establishment where the employee or former employee worked. The employer must provide the relevant copy by the end of the next business day. The rule specifically says the employer may not remove ordinary employee names from that Log before giving the copy to those requesters. The privacy concern entries already use privacy case instead of a name because of section 1904.29.
This combination surprises people. A company may think every access copy should be fully deidentified. That would conflict with the employee-access rule for ordinary entries. Another company may assume that because ordinary names stay on the Log, it may attach the confidential privacy list. The separate list should not be treated as a routine Log attachment. Route each request by requester, requested record and governing rule. The person preparing a copy should inspect the actual file or export, including hidden tabs, notes and attachments, before sending it.
Requests for an OSHA 301 Incident Report follow different recipient and field rules in section 1904.35. An employee's own report and a request by an authorised employee representative are not the same disclosure. This article does not provide a substitute matrix for those requests. The federal employee-access rule should be consulted at the point of release. The separate planned owner for 301 access can address that recipient-specific workflow without turning this privacy-classification guide into a second copy of the broad recordkeeping article.
If the employer chooses to disclose OSHA Forms 300 or 301 voluntarily to people outside the groups entitled to access under sections 1904.35 and 1904.40, section 1904.29, paragraph b10 generally requires names and other personally identifying information to be removed or hidden. The regulation lists limited circumstances in which identifying information may be disclosed, including an employer-hired safety programme auditor or consultant, certain insurance processing and specified public-health or law-enforcement uses. Do not confuse a voluntary client request with a compulsory employee or government request. Check the legal basis and the actual recipient before any release.
Government requests and the confidential cross-reference
Section 1904.40 requires copies of Part 1904 records within four business hours when an authorised government representative asks for them. The rule identifies the representatives entitled to request them. The confidential privacy list exists partly so the employer can provide the identity information to the government when asked. A privacy case is not a reason to refuse a proper Part 1904 request or to destroy the cross-reference.
Set a practical internal route for these requests before an inspection. Identify who receives a request, who verifies the requester's authority, who retrieves the Log, 301 reports and privacy list, and who checks the delivered package. Those are suggested employer controls. They do not alter the four-business-hour rule. Do not treat this guide as advice on an inspection warrant, privilege dispute or a request outside Part 1904. If the request raises those issues, the responsible person should address the particular request through the appropriate company process rather than assume the recordkeeping rule answers every inspection question.
The response copy should be assembled from the maintained records, not reconstructed from memory under deadline. Check whether the request covers the current year, a stored year or both. Log who sent which version and when. That release log is an internal audit aid, not a separately prescribed OSHA form. It can help distinguish a government disclosure from an employee Log request and from an optional client disclosure when the same case appears in several record sets.
Retain the list with the other records
Section 1904.33 requires the OSHA 300 Log, the privacy case list if one exists, the annual summary and OSHA 301 Incident Reports to be saved for five years after the end of the calendar year they cover. The clock is tied to the covered calendar year, not simply five years after the incident date. Treat the privacy list as part of the recordkeeping set when archiving or migrating systems. A migration that preserves the Log but loses the separate case-number list breaks the cross-reference that the rule requires.
During the storage period, the employer must update stored OSHA 300 Logs to add newly discovered recordable cases and show changes in classification. Section 1904.33 does not require updates to stored 300-A summaries or 301 reports, though an employer may update them. If a Log case changes, check whether the confidential cross-reference still points to the correct case number and whether access copies will reflect the revised Log. Do not silently replace the historical Log with an untraceable export. Maintain a clear version history as a process choice so the person responsible for the records can explain the change.
Retention and access are separate questions. Keeping the list for the required period does not mean making it available to every person who may receive a Log copy. Conversely, a restricted list is still a required retained record. When a recordkeeping system is replaced, test both retrieval and privacy controls using a sample case before retiring the old system. Check that the employer can produce the required forms or equivalent forms when needed. Section 1904.29 allows computer records if the system can produce the equivalent forms for access and government requests.
A workable review sequence
Use this sequence when a potentially sensitive recordable case arrives. Each step has a different question and a different record.
| Step | Decision or action | Source of the requirement | | --- | --- | --- | | 1 | Confirm that a Part 1904 Log and 301 entry is required. | Recordability rules and section 1904.29. | | 2 | Check the six privacy concern categories. Document the category in a restricted working note. | Section 1904.29, paragraphs b7 and b8. | | 3 | Put privacy case in the OSHA 300 name field for a qualifying case. Complete the other required fields. | Section 1904.29, paragraph b6. | | 4 | Link the case number and employee name in a separate confidential list. | Section 1904.29, paragraph b6. | | 5 | Review the description for unnecessary identifying detail while retaining cause and general severity. | Section 1904.29, paragraph b9. | | 6 | Check the recipient and the requested record before release. Keep the confidential list out of an ordinary Log access copy. | Sections 1904.35 and 1904.40; list separation under section 1904.29. | | 7 | Retain the Log, list, summary and 301 records for the required period and update the stored Log when necessary. | Section 1904.33. |
The restricted note, release check and review owner are employer process, not new federal forms. They make the specific legal duties less likely to be lost between incident intake, annual closeout and an access request. If your organisation maintains records for more than one establishment, make sure the case number and list identify the right establishment and year. An ambiguous case number can cause a disclosure mistake even when the privacy category was correctly identified.
Common mistakes to prevent
Classifying every sensitive incident as a privacy case. The six categories are exhaustive. Apply the specific category test after recordability, and do not stretch the voluntary-request category beyond other illnesses.
Removing the name but leaving a unique description. Inspect the complete Log and 301 description. Use the limited discretion in section 1904.29 to avoid intimate or identifying details while retaining cause and general severity.
Keeping no confidential cross-reference. Privacy case in the Log name field is only part of the workflow. The separate list must connect case numbers with employee names so the employer can update records and answer a proper government request.
Redacting every name before an employee Log request. Section 1904.35 generally requires the nonprivacy names to remain on a Log supplied to the specified employee-side requesters. Privacy concern cases should already have the prescribed replacement wording.
Using one disclosure template for every requester. An employee Log copy, an authorised representative's 301 request, an authorised government request and a voluntary disclosure to an outsider have different rules. Identify the recipient and form before sending anything.
Archiving the Log without the privacy list. The five-year retention requirement expressly includes the list if one exists. Verify it remains retrievable and appropriately restricted after any system migration.
The aim is accurate records with the specific privacy protection the regulation requires. The Log still explains recordable cases; the confidential list preserves the identity link for authorised use; and a release check prevents one access request from being answered under another requester's rule.
For the broader employer recordkeeping framework, see the OSHA 300 Log guide. If you are comparing systems for maintaining compliance records, visit Complys US and confirm which current features fit your own recordkeeping and privacy workflow. This article does not claim that Complys classifies privacy cases, maintains the confidential list or makes legal recordability decisions automatically.
Related guides
See also: Temporary Worker Injury: Host or Staffing Agency OSHA 300 Log?, How to Correct an OSHA 300 Log Entry After New Information.
Compliance software built for US safety teams
Complys keeps your certifications, training and inspection records in one place, builds your written programs and JHAs, and scores your readiness against OSHA, free to start on your own data.
Start your free 90-day trial