Skip to content
HexaTransfer
Back to blog
Productivity & Collaboration

Secure File Sharing for HR Departments

Protect employee data with secure HR file sharing. Manage onboarding documents, contracts, and sensitive personnel records safely.

HR teams handle some of the most sensitive data in the organization — SSNs, medical records, background checks, performance reviews — and most of it moves through email, which is the worst possible channel. A defensible HR file-sharing stack combines a dedicated HRIS (Workday, BambooHR, Rippling) for persistent records, an encrypted transfer tool like HexaTransfer or Tresorit Send for one-off sends to candidates and benefits providers, and a DLP policy that blocks forwarding of tagged personnel files. GDPR Article 9, HIPAA (for health data), and state laws like Illinois's BIPA and California's CPRA all set specific requirements for this data.

What "Sensitive" Means in an HR Context

Employee data spans multiple sensitivity tiers:

  • Identifying data: SSN, driver's license, passport, I-9 supporting documents
  • Financial data: direct deposit account numbers, wage garnishment orders, W-4s
  • Medical data: ADA accommodation requests, FMLA certifications, workers' comp records, health plan enrollment
  • Biometric data: fingerprints, facial scans for timekeeping (triggers BIPA in Illinois, with statutory damages of $1,000 to $5,000 per violation)
  • Performance data: reviews, PIPs, termination documentation, exit interview notes
  • Investigation data: harassment complaints, internal investigation reports, legal hold documents

A breach involving any of these triggers state notification laws. A breach involving medical data under a self-insured health plan also triggers HIPAA notifications. Fines range from $100 per record (basic state laws) to $50,000 per record (HIPAA willful neglect).

Onboarding Document Collection

New hires send in a flurry of documents in their first 72 hours: I-9 supporting documents, signed offer letters, benefits enrollment forms, direct deposit authorizations. The collection flow determines whether that data stays in a controlled environment or leaks to personal email archives.

Best-practice onboarding intake:

  1. Send a branded, passwordless upload link to the candidate
  2. Require specific documents with clear labels (Photo ID, SSN card, voided check)
  3. Accept mobile photo uploads for passport/DL/SSN cards
  4. Auto-expire the link after 14 days
  5. Route uploads directly into the HRIS, not HR inboxes
  6. Delete local copies once the HRIS ingestion is confirmed

Platforms that handle this natively: BambooHR onboarding, Workday onboarding, Rippling, Gusto, and purpose-built tools like Sapling or Enboarder. If your HRIS doesn't have a good candidate upload flow, use an encrypted transfer tool with a custom subdomain.

I-9 and E-Verify Document Handling

Form I-9 requires you to physically (or virtually, per DHS rules) inspect specific documents from List A or List B+C. Since 2023, DHS permanently authorizes virtual I-9 inspection for E-Verify participants that enroll in the alternative procedure.

For virtual I-9:

  • Collect photos of supporting documents through a secure upload
  • Conduct a live video call to verify the document against the person
  • Retain the document image with the I-9 form
  • Store for the required retention period: 3 years after hire or 1 year after termination, whichever is later

I-9 documents are the single most tempting target for identity theft — they contain name, DOB, SSN, and photo ID. Encrypt them at rest and in transit, and restrict access to HR users with a documented need.

Background Check and Reference Data

Third-party background check providers (Checkr, GoodHire, HireRight, Sterling) handle most of the data collection. They return adjudicated reports via their own portals.

When you need to share a report internally — for example, with a hiring manager assessing adverse action — don't download and email. Use the vendor's shared-link feature if available, or export to a password-protected PDF with a 48-hour expiration link. FCRA Section 604 restricts who can access consumer reports; maintain an access log.

Pre-adverse action letters and final adverse action letters are federally mandated and must reach the candidate reliably. Send through a tracked e-delivery method with delivery confirmation, not raw email.

Benefits Enrollment and PHI

Open enrollment pushes thousands of election forms, beneficiary designations, and dependent documentation through HR. If your employer sponsors a self-insured group health plan, HR is handling PHI and has to comply with HIPAA.

Requirements:

  • Business Associate Agreements with every vendor touching PHI
  • Encryption at rest and in transit (minimum AES-256 and TLS 1.3)
  • Access controls limiting PHI to the minimum necessary
  • Audit logs of all PHI access
  • Breach notification within 60 days of discovery

Practical flow: enrollment happens through the benefits administration platform (Workday Benefits, BambooHR, or a broker portal like Ease or Employee Navigator). Dependents' birth certificates, marriage certificates, and domestic partnership affidavits upload through the same secure channel. Never collect PHI via email.

Performance Reviews and Termination Documentation

Performance data becomes litigation evidence. PIPs, written warnings, and termination packets must be generated, delivered, and retained in a way that survives subpoena and chain-of-custody scrutiny.

Delivery standards:

  • Formal reviews: signed in the HRIS or through an e-signature platform (Docusign, Adobe Acrobat Sign) that produces a tamper-evident certificate
  • PIPs and warnings: delivered in person or via tracked video meeting, with follow-up electronic copy sent via secure transfer
  • Termination packets: include separation agreement, final pay statement, COBRA notice, benefits continuation info; deliver via secure link with password

Retain everything for the longer of: your jurisdiction's statute of limitations for employment claims (usually 2 to 4 years), or your document retention policy. Seven years is a common default.

Investigations and Legal Hold

Harassment complaints, discrimination claims, and internal investigations generate documents that might become exhibits in federal court. Chain of custody matters.

During an active investigation:

  • Store all interview notes, witness statements, and evidence in a dedicated, access-controlled folder (not anyone's personal drive)
  • Use a document management system with audit logs (Relativity, Exterro, Logikcull for large matters; a restricted SharePoint or Notion workspace for small matters)
  • Put all affected employees and custodians under legal hold — no deletion, no auto-expiry
  • Route external communication with counsel through privileged channels

When the investigation closes, archive the file per your retention policy. Don't destroy prematurely; don't retain indefinitely without a reason.

Cross-Border Transfer Considerations

Multinational employers move employee data across borders constantly — from an EU subsidiary to US parent, from India to Singapore, and so on. GDPR Article 44-49 restrict transfers out of the EU without an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules.

Practical steps:

  • Maintain SCCs with any non-EU vendor handling EU employee data
  • Prefer EU-hosted HRIS instances for EU employees (Workday, SAP SuccessFactors, BambooHR all offer EU hosting)
  • For ad-hoc transfers, use EU-jurisdiction tools (Swiss-hosted or EU-hosted) with E2EE
  • Document the transfer in your Records of Processing Activities

For Chinese operations, the PIPL adds a separate layer — personal information export requires a security assessment or certification. Don't default to US-hosted services for China HR data.

A Minimum-Viable HR Security Stack

  • HRIS: Workday, BambooHR, Rippling, or ADP
  • Secure transfers: E2EE tool for candidates and vendors
  • E-signature: Docusign or Adobe Acrobat Sign
  • Password manager: 1Password Business
  • MFA everywhere: Yubikey or equivalent
  • Written information security policy reviewed annually
  • Annual phishing simulation and HR-specific training

Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file