D. May notify law enforcement without the employee ' s authorization is the best exam answer. Employee Assistance Programs ordinarily emphasize confidentiality, but confidentiality is not necessarily absolute when information indicates a serious threat of harm. In appropriate circumstances, a qualified health or mental-health provider may disclose information necessary to prevent or lessen a serious and imminent threat without first obtaining the individual ' s authorization.
HRCI places this subject within the broader SPHR responsibility for employee safety, security, ethical standards, risk management, privacy, and emergency response. Under the five-domain outline requested here, Employee Relations and Engagement included evaluating safety and security strategies and knowledge of “workplace safety and security risks” , ethical standards, and data privacy. The current outline similarly addresses HIPAA, employee safety and security, crisis management, and HR data privacy.
Federal HIPAA guidance provides an important principle supporting the answer. HHS explains that, where the rule applies, a healthcare provider acting consistently with applicable law and professional ethics may disclose necessary information when there is a “serious and imminent threat” to a person or the public. Appropriate recipients can include law enforcement when they are reasonably able to prevent or lessen the threatened harm. Such disclosure can occur without the individual ' s authorization.
A is incorrect because advance notification to the employee is not a universal prerequisite and could sometimes undermine protective intervention.
B is incorrect because there is no general rule requiring the provider to notify the employee after contacting law enforcement.
C is too absolute. Disclosure to both the supervisor and law enforcement is not automatically required in every threatening situation.
D uses the critical word “may.” It recognizes that disclosure can be permissible without employee authorization when applicable safety, legal, and professional standards justify it.
For actual workplace practice, state duty-to-warn/protect laws, professional licensing rules, HIPAA applicability, and special confidentiality requirements can differ; organizations should use qualified legal or clinical guidance for specific incidents.
[References:HRCI, SPHR Exam Content Outline, 2023–2024, Functional Area 05: Employee Relations and Engagement, Responsibilities 03; Knowledge Areas 55, 58, 59, and 61.HRCI, SPHR Exam Content Outline, current edition, Functional Area 05: HR Information Management, Safety, and Security, Responsibilities 5.1–5.2.U.S. Department of Health and Human Services, Office for Civil Rights, HIPAA Privacy Rule—Disclosures to Prevent a Serious and Imminent Threat, 45 CFR §164.512(j)., , ]
Submit