HIPAA vs FERPA: Which Law Covers Student Health Data?
A special education coordinator emails your pediatric practice on a Tuesday afternoon: "Please send the complete chart for Student X to support her IEP evaluation. The district has consent on file." No authorization is attached. Your front desk forwards it to you and asks whether the district's consent counts.
It does not. And the reason it does not is the whole substance of hipaa vs ferpa: two federal privacy laws that cover overlapping records but bind entirely different organizations, run on different clocks, and are enforced by different agencies with different penalties. If your practice treats children, staffs a school clinic, provides athletic training coverage, or manages a college health center, you need a written answer to the question "which law governs this record?" before the next request arrives.
HIPAA vs FERPA: Which Law Applies to a Student Health Record?
Four rules resolve most cases:
- HIPAA binds providers, health plans, and clearinghouses that conduct standard electronic transactions — that's your practice. FERPA binds schools and school districts that receive U.S. Department of Education funding.
- A record cannot be both. HIPAA's definition of protected health information at 45 CFR 160.103 expressly excludes education records covered by FERPA and the "treatment records" described in FERPA's statute. Once a health record is a FERPA education record, the HIPAA Privacy and Security Rules do not reach it.
- Your chart stays yours. A copy you send to a school becomes part of the school's education records and is governed by FERPA there. Your original chart remains PHI under HIPAA.
- Employment and control decide the gray cases. A nurse employed by the district, charting in the district's system, is generating education records. A clinician employed by your practice, charting in your system, is generating PHI — even if the exam room sits inside a middle school.
That is the short version. The operational problem is that requests arrive without labels, and the person answering them is usually your front desk.
Why the Distinction Costs You Money
FERPA's disclosure rules are looser than HIPAA's in ways that matter. Schools may share education records internally with "school officials" who have a legitimate educational interest, and they may designate directory information for release. Nothing in FERPA requires the granularity of HIPAA's minimum necessary standard as HHS applies it, and FERPA carries no breach notification requirement at all.
So when you send a full chart to a district because someone said "we have consent," you have moved sensitive information — behavioral health notes, medication history, family history — into a regulatory environment where it can be redisclosed under rules you do not control and cannot audit. If that transfer was not supported by a valid HIPAA authorization or a specific regulatory permission, the impermissible disclosure is yours, and it is reportable under the Breach Notification Rule.
HHS maintains the full regulatory text and its guidance library at the HIPAA laws and regulations page, and the joint HHS–Department of Education guidance on student health records (issued in 2008 and updated in December 2019) remains the controlling interpretive document for these overlaps.
Three Fact Patterns That Land on Your Desk
1. The District Asks for Immunization Records
This is the most common request and the one with a specific carve-out. Under 45 CFR 164.512(b)(1)(vi), you may disclose proof of immunization to a school without a signed authorization when state law requires the school to have that proof before admitting the student — provided you obtain and document agreement from the parent, guardian, or the adult student.
The agreement may be oral. The documentation may not be. Your workflow needs a field or note template that captures who agreed, when, and who took the call. "Mom said it was fine" scribbled on a fax cover sheet is not evidence.
Note the boundary: this permission covers immunization proof. It does not cover the sports physical narrative, the ADHD medication list, or the whole chart.
2. Your Clinicians Work Inside a School
Practices increasingly contract with districts for school-based clinics, sports medicine coverage, or behavioral health. The contract language determines the regulatory outcome, and most drafts do not address it.
If your clinician functions as district staff under the district's direction, using the district's records system, those encounter records are education records under FERPA. If your clinician functions as your employee, in your records, billing under your NPI, they are PHI under HIPAA. Hybrid arrangements — your clinician, your chart, but you push summaries into the district's student information system — create two record sets governed by two laws, and you need a written map of which is which.
Put it in the agreement: whose system, whose employee, whose records, and exactly which data elements cross the boundary and under what authority. Then train the clinician on it. In the field, the person holding the tablet decides, and they will guess wrong without instruction.
3. You Manage or Acquired a College Health Center
Postsecondary institutions are where hipaa vs ferpa gets genuinely technical. FERPA's definition of education records excludes records made by a physician, psychologist, or other recognized professional, about a student who is 18 or older or attending a postsecondary institution, made in connection with treatment and disclosed only to individuals providing that treatment. Those are "treatment records," and HIPAA also excludes them from PHI.
Here is the trap: the exclusion depends on limited disclosure. Disclose a treatment record to someone outside the treatment relationship — a dean, a parent, a disability services office — and it can become an education record subject to FERPA, including the student's right to inspect it. Meanwhile, if the health center bills insurance electronically, the institution may be a HIPAA covered entity for those functions even while FERPA still governs the underlying records.
If your organization operates one of these centers, document the analysis in writing and revisit it whenever billing, staffing, or the records system changes.
What Flips a Record From PHI to an Education Record
Custody and function, not content. The same immunization line item is PHI in your EHR and an education record in the district's student file. This has two operational consequences your privacy officer should internalize.
First, minors' rights diverge. FERPA gives parents access to education records until the student turns 18 or enrolls in a postsecondary institution. HIPAA defers to state law on whether a parent is a minor's personal representative, and many states grant adolescents independent consent rights for reproductive health, mental health, or substance use treatment. A 16-year-old's confidential encounter note that lands in a school file may become parent-accessible under FERPA even though state law shielded it in your chart. That is a strong reason to send the narrowest possible record set.
Second, once the record is at the school, you cannot recall it, restrict it, or account for its onward disclosures. Your accounting of disclosures ends at the fax confirmation.
The BAA Question Schools Get Wrong
Districts routinely send practices a business associate agreement, or ask to sign one, when neither party's role calls for it. A school is not your business associate merely because it receives student information; a business associate performs a function on behalf of a covered entity that involves PHI. A district receiving immunization proof to satisfy its own enrollment requirement is acting for itself.
Conversely, a real BAA obligation often hides in these arrangements and gets missed. If a district's software vendor, telehealth platform, screening company, or scanning service handles PHI on your behalf, that's a business associate and you need an executed agreement before data moves. FERPA's parallel mechanism — the "school official" designation with direct control — is not a substitute and gives you none of HIPAA's required protections.
If you're standing up a school-based program this quarter and need paper for the vendors touching your PHI, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — useful when a program launch is measured in weeks and legal review time is the scarce resource.
Access, Amendment, and Timelines Side by Side
Your staff need both clocks memorized, because families will ask you about records the school holds and vice versa.
- Access — HIPAA: 30 calendar days from the request, with one 30-day extension and written notice of the delay. Fees limited to a reasonable, cost-based amount.
- Access — FERPA: the school must allow inspection and review within 45 days of receiving the request. FERPA generally does not require the school to provide copies unless circumstances effectively prevent inspection.
- Amendment — HIPAA: you must act within 60 days, with one 30-day extension; denial requires a written explanation and a path for the patient's statement of disagreement.
- Amendment — FERPA: the parent or eligible student may request amendment; if the school refuses, it must offer a hearing.
- Breach — HIPAA: individual notice without unreasonable delay and no later than 60 days; incidents affecting 500 or more residents of a state or jurisdiction go to HHS and the media within 60 days; smaller incidents go on your annual log. Posted cases are searchable on the OCR breach reporting portal.
- Breach — FERPA: no notification requirement. Enforcement runs through the Department of Education's Student Privacy Policy Office, and the ultimate remedy is withdrawal of federal funding. The Supreme Court held in Gonzaga University v. Doe (2002) that FERPA creates no private right of action.
That asymmetry is the practical takeaway of hipaa vs ferpa: your side of the line carries civil money penalties, mandatory notification, and a public breach portal. The school's side does not. Do not let a district's relaxed posture set your standard.
The Documented Evidence to Have on File
If an investigator or a client district's counsel asks how you handle student records, these artifacts answer the question:
- A one-page decision rule for front-desk and records staff: who may release what to a school, with the immunization carve-out spelled out and everything else routed to a signed authorization.
- An authorization form that names the school by entity, describes the specific records, and states an expiration — not a blanket "release to school district" checkbox.
- Documented parental agreements for immunization disclosures, captured in the chart with date and staff initials.
- Signed school-based service agreements that state whose employee, whose system, and whose records govern each function.
- A current vendor inventory with executed BAAs for every business associate supporting the program.
- Training records showing that staff handling these requests were trained on the distinction and when.
- Your risk analysis, updated to reflect any new school-based data flows. If yours predates the program, it's out of date — automated tooling that produces a HIPAA risk analysis and the supporting policy set is faster than rebuilding the document by hand.
For background on the security expectations behind that last item, NIST's SP 800-66r2 maps Security Rule requirements to concrete controls and is a defensible reference to cite in your own documentation.
Where Practices Actually Get Burned
Not in the sophisticated edge cases. In the routine ones: a records clerk who releases a full chart because the requester works at a school; a sports medicine contract signed without addressing record custody; a behavioral health note swept into a district file where a parent later reads it; a screening vendor onboarded by the district and handed your patient list with no agreement in place.
Each of those is a five-minute conversation before it happens and a months-long problem afterward. Decide now which of your data flows land on which side of the line, write it down, and make sure the person answering the phone at 4:45 p.m. has the answer in front of them.
If your school-based or contracted arrangements are missing vendor paperwork, start there — build the Business Associate Agreement you need this week, export it for signature, and cross one gap off the list before the next records request arrives.