You need to take into consideration the GDP our rules, the California privacy laws, and what other regulations your company has to follow.
I need to take into consideration what I believe to be the presented scenario:  A US company operating out of the US.  

The HR person, in consultation with legal, if needed, can decide what regulations must be followed.  And if there are conflicts (and often there are) which regulation takes precedence.  Having reasonable accommodations in order to perform one's job functions is a huge part of the Americans with Disabilities Act.

But the one thing you don't do is just shrug and not pursue anything because, "that's just the way things are."  The way things are is very often entirely accidental, and, if intentional, those intentions may need to be changed.

