Back to blog
HR Techhealth dataGDPR

Health data in HR: sick leave, medical visits, accommodations — the blind spots

Published on 2026-04-164 min readFlorian

Health data is not always where you expect it

An HRIS isn't supposed to store medical files. In practice: scanned sick notes, workplace accommodations, medical visit proofs — health data moves around.

For more — see our security audit for HR software vendors.

The three angles to review

  • sick note attachments stored like any other HR document;
  • free-text fields in manager tools containing health info;
  • HR exports that include detailed absence reasons by default.
  • What should be clear

    GDPR treats this data as sensitive (Article 9). Encryption, access and logging should reflect that, not the level of a regular HR file.

    For HR & Payroll vendors

    CleanIssue specializes in security reviews for HR, payroll, and recruiting software. If you're building an HRIS, payroll tool, or ATS and want an external review of your exposure before a client audit or security questionnaire, see our offer for HR & Payroll vendors.

    Go further

    Related articles

    Three adjacent analyses to keep exploring the same attack surface.

    Sources

    Written by Florian
    Reviewed on 2026-04-16

    Editorial analysis based on official vendor, project, and regulator documentation.

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit