HIPAA Compliance for Pediatric Practices: Who Gets the Records When the Patient Is Twelve

Practical guidance for healthcare teams and business associates

Tuesday in a pediatric practice. A father who no longer lives with the family calls for his son's growth chart. A sixteen-year-old asks that today's visit not show up in the portal her mother checks. A school nurse faxes an immunization form with "URGENT" across the top. A mother texts a photo of a rash to the office cell phone. Four routine requests, and every one of them turns on the same question: who is the "individual" HIPAA is protecting, and who else may see the record.

The HHS Office for Civil Rights (OCR) enforcement listing shows that pediatric settings are not exempt from the basics. OCR imposed a $548,265 penalty against Children's Hospital Colorado for HIPAA Privacy and Security Rules violations (December 2024). It imposed a $100,000 penalty against a mental health center for failure to provide timely access to patient records (November 2024). Its Right of Access Initiative, which began with a first settlement in September 2019, has run for years and has never been limited to adult records.

This guide covers why HIPAA applies to a pediatric practice, how the personal representative rule decides which parent gets what and when the minor decides instead, what protected health information looks like when the patient is a child, the violations that cluster around schools, portals, and parents, how to build the program, and which vendors need a Business Associate Agreement.

HIPAA Compliance for Pediatric Practices: Parents, Minors, Schools, and Registries

Why HIPAA Applies to a Pediatric Practice

45 CFR 160.103 defines a covered entity to include "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." A pediatric practice bills Medicaid, CHIP, and commercial plans electronically, so it is a covered entity, bound by the Privacy Rule, the Security Rule, and the Breach Notification Rule. The test is walked through in what is a covered entity under HIPAA.

One boundary in the same section matters for pediatrics. The definition of P.H.I. (Protected Health Information) excludes individually identifiable health information "in education records covered by the Family Educational Rights and Privacy Act." The copy of a physical form that a school keeps is the school's record under FERPA. The practice's own chart is P.H.I. under HIPAA. The same fact can sit under two laws depending on whose file cabinet it is in.

The Personal Representative Rule: Who Counts as the Individual

45 CFR 164.502(g)(1) requires a covered entity to "treat a personal representative as the individual." For a child, 164.502(g)(3)(i) makes the rule and the exceptions explicit: "If under applicable law a parent, guardian, or other person acting in loco parentis has authority to act on behalf of an individual who is an unemancipated minor in making decisions related to health care, a covered entity must treat such person as a personal representative," with respect to the relevant P.H.I., except where the minor may act alone. The exceptions are that the minor "consents to such health care service; no other consent to such health care service is required by law," that the minor "may lawfully obtain such health care service without the consent of a parent," or that a parent "assents to an agreement of confidentiality between a covered health care provider and the minor."

Then 164.502(g)(3)(ii) hands the disclosure question to the states. Where state law permits or requires disclosure to a parent, the practice may disclose. Where state law prohibits it, the practice may not. Where state law is silent, "a licensed health care professional, in the exercise of professional judgment" decides. In plain terms: which services a teenager may consent to alone (contraception, sexually transmitted infection testing, mental health care, substance use treatment) is a state-law question, and it differs by state. The practice needs a one-page policy that names its state's rules, reviewed by counsel, and staff who know where it is.

Two more parts of the rule matter at the front desk. Under 164.502(g)(5), a practice may decline to treat a parent as the personal representative if it reasonably believes the child "has been or may be subjected to domestic violence, abuse, or neglect by such person," or that doing so "could endanger the individual," and a professional judges it not in the child's best interest. And a parent's authority comes from "applicable law," which is why a custody order changes the answer. The practice does not adjudicate custody; it asks for the order, files it, and follows it.

What P.H.I. Looks Like in Pediatrics

  • Well-child records. Growth charts, developmental screening results, vision and hearing screens, and anticipatory guidance notes.
  • Immunization records. Vaccine, lot number, date, and site for every dose, mirrored to the state immunization registry.
  • Newborn screening and specialist reports. State lab results and consult letters that arrive by fax.
  • School, camp, and sports forms. Physical forms, medication administration forms, and immunization certificates requested by schools and coaches.
  • Adolescent confidential visits. Contraception, sexually transmitted infection testing, and behavioral health screens, which may need to be segregated from a parent's portal view.
  • Parent-supplied images. The rash photo texted to the office phone becomes P.H.I. the moment it lands on a practice device.
  • Portal proxy accounts. Each parent's login, what it can see, and when it should stop seeing it.
  • Family information in the chart. Sibling histories, parental health history, and household contact details tied to the child's record.

Common Violations in Pediatric Practices

The portal proxy that never grows up. A parent's proxy account created at birth keeps displaying every visit unless someone changes it. When state law gives a teenager the right to consent to a service, the record of that service belongs to the teenager for HIPAA purposes, and a portal that shows it to the parent is a disclosure the practice made. The fix is a proxy policy with an age trigger and a way to segment confidential visits.

Ignoring the request to call a different number. 164.522(b)(1)(i) requires a provider to "permit individuals to request and must accommodate reasonable requests by individuals to receive communications of protected health information ... by alternative means or at alternative locations," and 164.522(b)(2)(iii) says the provider "may not require an explanation." A sixteen-year-old asking that results go to her cell phone rather than the house line is exercising that right.

Slow record requests. Parents request records for a new school, a new pediatrician, or a custody case. 164.524(b)(2) allows 30 days to act, with one 30-day extension on written notice, and the $100,000 mental health center penalty above is what a missed deadline can cost. The rules on deadlines, fees, and denials are in HIPAA right of access.

School forms sent without the right basis. 164.512(b)(1)(vi) permits disclosure to a school only when the information "is limited to proof of immunization," the school "is required by State or other law to have such proof of immunization prior to admitting the individual," and the practice "obtains and documents the agreement to the disclosure" from a parent (or the student, if an adult). Immunization proof, sent with a documented parental okay, fits the rule. A full physical or a medication form does not; that goes out on the parent's signed request, or the parent carries it. The form for that is in HIPAA authorization requirements.

Rash photos by text. A parent may send anything; the practice's reply and storage are the compliance problem. Standard SMS on a personal phone is an unencrypted channel the practice does not control. The rules and alternatives are in the HIPAA texting guide.

Birthday posts and lobby photos. A child's photo on the practice's social media needs a 164.508 authorization signed by the personal representative, and 164.508(c)(1)(vi) requires "a description of such representative's authority to act for the individual" on the form.

Building the Program

Risk analysis that includes the portal and the registry. 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities" to ePHI (electronic P.H.I.). For a pediatric practice that includes proxy access configuration, the immunization registry interface, the reminder-and-recall texting platform, and the office cell phone.

Three pediatric-specific policies. A personal representative policy that names the state's minor-consent rules and the custody-order procedure; a portal proxy procedure with an age trigger; and a school-form workflow that separates immunization proof from everything else. The state-law overlay is introduced in state privacy laws vs federal HIPAA requirements.

Reporting duties, documented. 164.512(b)(1)(ii) permits disclosure to "a public health authority or other appropriate government authority authorized by law to receive reports of child abuse or neglect," and state mandatory-reporter law requires it. 164.512(b)(1)(i) permits disclosure to a public health authority "authorized by law to collect or receive such information for the purpose of preventing or controlling disease," which is the basis for the state immunization registry. Write both into the policy so no one has to reason it out at 4:45 on a Friday.

Training for the front desk first. 164.530(b)(1) requires training for all workforce members. The front desk fields the parent questions, so it gets the scripts: what to say to a parent, to a step-parent, to a grandparent, and to a teenager. Document the training and keep the record for six years under 164.530(j)(2).

Vendor B.A.A. Checklist for Pediatrics

A business associate under 160.103 is a person who, on the practice's behalf, "creates, receives, maintains, or transmits protected health information" for a regulated function. Public health authorities and schools receive P.H.I. under 164.512, not on the practice's behalf, which is why they appear below without an agreement.

Vendor categoryTypical examplesB.A.A. required?
Pediatric EHR and portalPCC, Office Practicum, athenahealthYes
Reminder, recall, and texting platformSolutionreach, Luma HealthYes
Online developmental screening toolsAny platform scoring screens under the practice's accountYes
Vaccine inventory managementAny platform that links doses to patientsYes
After-hours nurse triage lineAny service taking parent calls for the practiceYes
Telehealth platformAny video visit platformYes
Billing company, IT managed services, cloud fax, shreddingThe standard back-office vendorsYes
State immunization registryThe state's immunization information systemNo. A public health authority receiving data under 164.512(b)(1)(i). Document the basis.
State newborn screening laboratoryThe state public health labNo. Public health disclosure required by state law.
Schools and campsRecipients of immunization proof and formsNo. Disclosures go out under 164.512(b)(1)(vi) or on the parent's signed request, not on the practice's behalf.
Referral specialists and hospitalsProviders the practice shares records with for treatmentNo. 160.103 excludes treatment disclosures to a provider from the business associate definition.

The Proposed Security Rule Update (Proposed, Not Final)

HHS published a Notice of Proposed Rulemaking on January 6, 2025 that would make encryption and multifactor authentication required rather than addressable, require a written asset inventory and network map, and require vulnerability scans "at least once every six months." It is proposed, not final, and OCR is not enforcing it. The status is tracked in HIPAA Security Rule delayed to 2027. For a pediatric practice, multifactor authentication on the portal and the EHR is worth turning on under the current rule, because the portal is where parent, teen, and practice access all meet.

---

FAQ

Can a pediatric practice give records to either parent?

Generally yes. Under 45 CFR 164.502(g)(3), a parent with authority under applicable law to make the child's health care decisions is the personal representative and is treated as the individual. A custody order can limit one parent's authority, so the practice should request the order and follow it rather than assume.

Can a teenager keep a visit confidential from parents under HIPAA?

It depends on state law. Where a minor may lawfully consent to a service alone, 164.502(g)(3)(i) makes the minor the individual for that information, and 164.502(g)(3)(ii) defers to state law on whether a parent may be told. The practice needs a written policy that names its state's minor-consent rules.

Can the practice send immunization records to a school?

Yes, under 164.512(b)(1)(vi), if the disclosure is limited to proof of immunization, the school is required by state law to have it, and the practice obtains and documents the parent's agreement. Anything beyond immunization proof needs the parent's signed request or authorization.

Does a pediatric practice need a BAA with the state immunization registry?

No. The registry is operated by a public health authority, and the disclosure is permitted under 164.512(b)(1)(i) for preventing or controlling disease. The practice should document that basis in its policies. The vendor that builds the interface on the practice's side is a different matter and does need an agreement.

Can a pediatric practice post patient photos on social media with parent permission?

Only with a valid HIPAA authorization under 164.508 signed by the personal representative, including a description of that person's authority to act for the child. A verbal okay at checkout does not meet the rule.

Conclusion

A pediatric practice needs three documents most templates skip: a personal representative policy keyed to the state's minor-consent law, a portal proxy procedure, and a school-form workflow. One Guy Consulting's Full-Scope plan supplies the risk analysis, the policy set, staff training, and B.A.A. tracking, with consulting time to fit the parent-and-minor rules to how the practice actually runs. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading