49 CFR 40.351
§ 40.351 What confidentiality requirements apply to service agents?
United States · 49 CFR — Transportation · Status: effective
Cite this
- Citation
- 49 CFR 40.351, § 40.351 What confidentiality requirements apply to service agents?, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/255357
- Permanent ID
ys:prov:255357@1- SHA-256
2f398232a0d60988885407a57ef13ed1377ed09cff831be3cbd78cdf55b5a175
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
Except where otherwise specified in this part, as a service agent the following confidentiality requirements apply to you:
(a) When you receive or maintain confidential information about employees (e.g., individual test results), you must follow the same confidentiality regulations as the employer with respect to the use and release of this information.
(b) You must follow all confidentiality and records retention requirements applicable to employers.
(c) You may not provide individual test results or other confidential information to another employer without a specific, written consent from the employee. For example, suppose you are a C/TPA that has employers X and Y as clients. Employee Jones works for X, and you maintain Jones' drug and alcohol test for X. Jones wants to change jobs and work for Y. You may not inform Y of the result of a test conducted for X without having a specific, written consent from Jones. Likewise, you may not provide this information to employer Z, who is not a C/TPA member, without this consent.
(d) You must not use blanket consent forms authorizing the release of employee testing information.
(e) You must establish adequate confidentiality and security measures to ensure that confidential employee records are not available to unauthorized persons. This includes protecting the physical security of records, access controls, and computer security measures to safeguard confidential data in electronic data bases.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.