HIPAA vs FERPA: Which Law Covers the School Nurse, the School-Based Clinic, and the College Health Center

Practical guidance for healthcare teams and business associates

A school nurse keeps a student's asthma action plan, medication log, and immunization record in a locked file and a district database. A pediatrician's office keeps the same information about the same child. One set of records is protected by HIPAA. The other is not, and it is the school's set that HIPAA leaves alone.

That is not an oversight. HIPAA's definition of protected health information excludes education records by name, and the U.S. Department of Education and HHS have published joint guidance, updated in December 2019, explaining where the line sits. This article follows that guidance and the regulations underneath it: what each law covers, which one applies to school nurses, school-based health centers, and college health services, and what happens where the two meet.

HIPAA vs FERPA: The Two Definitions That Decide Everything

FERPA (the Family Educational Rights and Privacy Act, 20 U.S.C. 1232g, with regulations at 34 CFR Part 99) protects education records. 34 CFR 99.3 defines them as records that are "directly related to a student" and "maintained by an educational agency or institution or by a party acting for the agency or institution." FERPA applies to schools, districts, and colleges that receive funds from the U.S. Department of Education. The joint guidance says that generally means public elementary and secondary schools, school districts, and postsecondary institutions, and generally not private elementary and secondary schools. FERPA rights belong to the parent until the student turns 18 or enters a postsecondary institution, at which point they transfer to the student.

HIPAA protects P.H.I. (Protected Health Information), and 45 CFR 160.103 defines PHI to exclude individually identifiable health information "in education records covered by the Family Educational Rights and Privacy Act" and "in records described at 20 U.S.C. 1232g(a)(4)(B)(iv)." That second citation is FERPA's treatment records carve-out: records on a student "who is eighteen years of age or older, or is attending an institution of postsecondary education," made or maintained by a physician, psychologist, or other recognized professional, "used only in connection with the provision of treatment to the student," and not available to anyone other than the treating professionals.

Put the two together and the rule is short. If a record is a FERPA education record or a FERPA treatment record, it is not PHI, and the HIPAA Privacy Rule does not apply to it, even if the institution holding it is a HIPAA covered entity. The joint guidance says so directly: "many schools that meet the definition of a HIPAA covered entity do not have to comply with the requirements of the HIPAA Rules because the school's only health records are considered 'education records' or 'treatment records' under FERPA."

School Nurses in Public K-12 Schools: FERPA

The joint guidance's first question is whether the HIPAA Privacy Rule applies to an elementary or secondary school, and its answer is "Generally, no." Two paths lead there. Most schools are not HIPAA covered entities at all, because their nurses and counselors do not bill health plans electronically, and 160.103 makes a health care provider a covered entity only if it "transmits any health information in electronic form in connection with a transaction covered by this subchapter." A school that bills nobody fails the test. The covered entity guide covers that test for providers generally.

The second path is the interesting one. Some public schools do bill Medicaid electronically, for example for services provided to a student under the Individuals with Disabilities Education Act. The guidance says that school is a HIPAA covered entity and must follow the HIPAA transaction standards for that billing. But if the school keeps its health information only in education records, "the school is not required to comply with the HIPAA Privacy Rule because the Privacy Rule explicitly excludes FERPA 'education records.'" The nurse's file is an education record. FERPA governs it, including the consent rules for disclosing it, and the guidance notes that FERPA consent is needed even to send billing information to Medicaid.

Private K-12 schools that receive no Department of Education funds are outside FERPA. If such a school employs a provider who bills a health plan electronically, the guidance says it "must comply with both the HIPAA transaction requirements and the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules" for the health information it holds. That is the one K-12 setting where a school itself runs a full HIPAA program.

School-Based Health Centers: It Depends Who Runs Them

The guidance draws the line at who the provider is acting for. Health records "maintained by a health care provider, such as a third party contractor, acting for a FERPA-covered elementary or secondary school" are education records, whether or not the provider is a school employee. FERPA applies.

Records kept by a provider "that provides services directly to students and that is not acting for a FERPA-covered educational agency or institution do not constitute FERPA-protected education records." The guidance's example is a public health nurse giving immunizations on school grounds but not for the school. A hospital, health system, or community health center that operates a school-based health center under its own license and its own billing falls on that side of the line. HIPAA applies to those records if the provider is a covered entity, which a provider that bills Medicaid or commercial plans electronically is. In that clinic the patient is a HIPAA patient, the record is PHI, the Notice of Privacy Practices is due at the first visit, and sharing with the school requires a HIPAA permission or an authorization.

The traffic between the two systems has rules of its own. HIPAA's 164.512(b)(1)(vi) lets a covered provider disclose proof of immunization to a school that state law requires to have it, with a documented agreement from the parent or the adult student, which may be oral. The guidance confirms that a covered provider may share PHI with a school nurse for treatment purposes, such as coordinating a medication the nurse will administer, without an authorization. In the other direction, a school that wants to give its education records to the outside clinic needs FERPA consent or a FERPA exception.

College and University Health Services: FERPA, With a HIPAA Wing

Campus health and counseling centers run by a college subject to FERPA hold either education records or treatment records on their student patients. The guidance states that both "are excluded from coverage under the HIPAA Rules, even if the school is a HIPAA covered entity." Treatment records are the therapy and medical notes shared only among the treating professionals; the guidance adds that billing records, and any treatment record disclosed beyond the treating professionals, are ordinary education records. A student can have treatment records reviewed by a physician or professional of the student's choice, and the rights belong to the student, not the parent.

The HIPAA wing appears the moment the clinic treats someone who is not a student. The guidance is explicit: a college clinic open to staff, the public, or students' family members must follow FERPA for its student patients and the HIPAA Rules for the health records of its nonstudent patients, if the institution is a covered entity. A student who is also a university employee is treated as a student, and FERPA applies. A university hospital, by contrast, is a HIPAA covered entity whose patient records are PHI, because it treats the public without regard to student status; only a student clinic the hospital runs on the university's behalf falls back under FERPA. The guidance also notes that a covered university may designate its health unit as the health care component of a hybrid entity under 164.105, so that the HIPAA Privacy Rule reaches only that unit.

Side by Side

SettingLaw that governs the recordWho holds the rights
Public K-12 school nurse or counselorFERPA (education record), even if the school bills Medicaid electronicallyParent, then the student at 18
Contractor nurse or therapist working for the schoolFERPAParent, then the student at 18
Private K-12 school with no federal education funds, billing electronicallyHIPAA in fullParent as personal representative under 164.502(g), subject to state law
School-based health center run by an outside covered providerHIPAAParent as personal representative, subject to state minor-consent law
College health or counseling center, student patientsFERPA (treatment or education records)Student
College health center, staff or public patientsHIPAA, if the institution is a covered entityPatient
University hospitalHIPAAPatient

What the Difference Means Day to Day

Access and amendment. Under HIPAA, 164.524(b)(2) requires action on an access request within 30 days. FERPA sets its own access and amendment procedures for parents and eligible students. A school-based clinic run by an outside provider follows the HIPAA clock; the school nurse next door follows FERPA's. The right of access guide covers the HIPAA side.

Sharing in an emergency. HIPAA permits disclosures to prevent a serious and imminent threat under 164.512(j), and to family involved in care under 164.510(b). FERPA has a health-or-safety emergency exception of its own, which the guidance cites at 34 CFR 99.36. The guidance walks through both.

Security. The HIPAA Security Rule, with its risk analysis and technical safeguards, applies to ePHI held by covered entities and business associates. It does not apply to education records. That does not make school health data unprotected; it means the protection comes from FERPA, state law, and district policy rather than 45 CFR Part 164.

Vendors. A covered school-based clinic needs business associate agreements with its EHR and billing vendors under 164.502(e). A school's student information system vendor is governed by FERPA's rules for school officials and the district's contract, not by a BAA. The BAA guide covers the HIPAA side.

The wrong-form mistake. The most common error in both directions is applying the wrong law's paperwork: a school demanding a HIPAA authorization to release a nurse's record, or an outside clinic accepting a FERPA consent as if it were a 164.508 authorization. Each law has its own consent document, and neither satisfies the other. The authorization requirements guide covers what a HIPAA authorization must contain.

---

FAQ

Does HIPAA apply to school nurses?

Generally no. A public school nurse's records are FERPA education records, and 45 CFR 160.103 excludes education records from protected health information. That holds even when the school bills Medicaid electronically and is technically a HIPAA covered entity for that billing.

Can a pediatrician send immunization records to a school without a signed authorization?

Yes, under 164.512(b)(1)(vi), if the disclosure is limited to proof of immunization, state or other law requires the school to have it before admitting the student, and the provider obtains and documents the parent's or adult student's agreement, which may be oral.

Are college counseling center records covered by HIPAA?

No. Records a college-run clinic keeps on its student patients are FERPA treatment records or education records, which HIPAA excludes from PHI even if the college is a covered entity. The rights belong to the student, and treatment records can be reviewed by a professional of the student's choice.

Does a school-based health center run by a hospital follow HIPAA or FERPA?

HIPAA, if the hospital operates the center under its own license and billing rather than acting for the school. The records are PHI, the clinic issues its own Notice of Privacy Practices, and sharing with the school requires a HIPAA permission or authorization.

Can a clinic accept a FERPA consent form in place of a HIPAA authorization?

No. A HIPAA authorization must contain the elements in 164.508(c), and a FERPA consent is a different document under a different law. Each side of a school and clinic relationship needs its own form.

Conclusion

Providers that serve students from outside the school, and campus clinics that treat staff and the public, end up with two record systems under two laws, and the HIPAA half needs a real program. One Guy Consulting's Full-Scope plan covers the risk analysis, policies, B.A.A. register, and training for the HIPAA side, sized to the clinic. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading