Colleges and universities routinely collect and maintain sensitive health information, including records from campus health centers, counseling services, disability services, and affiliated healthcare providers. Determining which federal privacy requirements apply to that information—either the Family Educational Rights and Privacy Act (FERPA) or the Health Insurance Portability and Accountability Act of 1996 (HIPAA)—can be complicated, particularly for institutions that operate healthcare facilities or have academic medical center or hospital affiliations. Although both laws address the privacy of personal information, they operate differently and apply to different types of records and entities.
This primer provides an overview of the regulatory scope of FERPA and HIPAA and highlights some of the issues that colleges and universities should consider when handling student health information.
FERPA and HIPAA: The basic framework
The starting point is an important distinction: FERPA and the HIPAA Privacy Rule generally do not apply to the same records.
- FERPA applies to “education records”—records that are directly related to a student and maintained by an educational agency or institution, or by a party acting for the institution.
- HIPAA, by contrast, safeguards “protected health information” (PHI) held by certain types of entities meeting HIPAA’s definition of a covered entity, including certain healthcare providers and health plans.
- The HIPAA Privacy Rule expressly excludes from the definition of PHI individually identifiable health information contained in education records covered by FERPA.
The fact that a record contains health information does not, by itself, mean that HIPAA applies. For colleges and universities, the first question is generally whether the record is an education record under FERPA.
The 2019 ED/HHS joint guidance
The US Department of Education (ED) and the US Department of Health and Human Services (HHS) addressed the intersection of FERPA and HIPAA in joint guidance originally issued in 2008 and updated in 2019.
The guidance emphasizes that the key question is whether the entity creating and maintaining the records is acting on behalf of an educational institution. Administrative control, rather than the physical location of the service or the source of funding, is generally the more important consideration.
For example:
|
Scenario |
Generally applicable framework |
|---|---|
|
Health clinic operated and controlled by the university |
FERPA |
|
Independent hospital providing care to a student |
HIPAA, assuming the hospital meets the definition of a covered entity |
|
School-employed nurse providing services to students |
FERPA |
|
Independent public health provider providing services on campus but not acting on behalf of the school |
HIPAA may apply |
|
Faculty member seen at the campus health clinic operated by the university |
HIPAA may apply (FERPA only covers student educational records) |
|
Spouse or community member seen at a campus clinic open to the public |
HIPAA may apply |
The specific facts and contractual relationships should be examined in each case. For example, a campus clinic serving a family member or a community member may be regulated by HIPAA if it engages in standard transactions under HIPAA, such as electronically billing payors, but may fall outside of HIPAA if it operates on a “cash-pay” basis without engaging in HIPAA standard transactions. If it is engaging in standard transactions, a single campus health clinic may operate under both FERPA and HIPAA simultaneously, with FERPA governing its student-patient records and HIPAA governing its non-student-patient records. This dual-regime reality makes it essential that campus clinics that serve mixed populations maintain clear internal protocols for classifying records, apply the correct privacy framework to each patient encounter, and train workforce members on the distinction. Institutions in this position should also consider whether a HIPAA hybrid entity designation (discussed below) is appropriate.
Student health records under FERPA
At the postsecondary level, student health records maintained by an institution or its employees generally are subject to FERPA rather than HIPAA. These records may constitute either education records or treatment records under FERPA.
What are “treatment records?”
FERPA contains a specific exception for certain records relating to a student’s treatment. For a student age 18 or older or attending a post-secondary institution, records may qualify as treatment records when they are:
- Made or maintained by a physician, psychiatrist, psychologist, or other recognized professional or paraprofessional acting in that capacity
- Made, maintained, or used only in connection with the student’s treatment
- Disclosed only to individuals providing treatment
Treatment records are excluded from FERPA’s definition of “education records,” but they are also excluded from HIPAA coverage.
The distinction is important because the treatment-record exception is narrow. If records are used for purposes other than treatment or disclosed to individuals other than treating providers, they may become education records subject to FERPA.
Counseling and mental health records
Counseling records raise many of the same issues, but institutions should be particularly attentive to the confidentiality representations they make to students. Records created by counselors and psychologists employed by or acting on behalf of an institution generally are education records subject to FERPA. The treatment-record exception may apply in certain circumstances, but only when its requirements are satisfied.
In addition to FERPA, institutions may have independent obligations based on their own policies and representations. For example, student handbooks, counseling center policies, intake forms, and confidentiality statements may create expectations—or, depending on the circumstances, contractual obligations—concerning the treatment of student information.
State Licensure-Based Psychotherapist-Patient Privilege
State law also may impose independent confidentiality or privilege obligations on licensed mental health professionals. Depending on the jurisdiction and the professional’s license, these laws may apply to psychologists, psychiatrists, social workers, mental health counselors, marriage and family therapists, and other licensed professionals. The scope of the protection—and whether it is characterized as a privilege, a confidentiality obligation, or both—varies by state.
Importantly, FERPA may govern the institutional record, while state law may independently regulate the clinician’s communications with the student. This distinction is important because an institution’s authority under FERPA does not necessarily answer whether a licensed clinician may disclose a particular confidential communication. Institutions should evaluate both the FERPA requirements applicable to the record and the professional’s independent obligations under applicable state law in order to determine what may be shared and in what contexts.
One practical approach is to distinguish between information contained in an education record and the substance of confidential therapeutic communication. For example, depending on the applicable law and circumstances, a counseling center may be able to confirm that a student is receiving services or share certain administrative information without disclosing the substance of the student’s therapy sessions. Conversely, a request for the clinician’s observations, statements made by the student during therapy, or the content of a treatment session may implicate separate professional confidentiality or privilege protections.
When HIPAA applies at a college or university
Where it has been determined that HIPAA does apply (e.g., to a university hospital, a clinic on campus, or a self-insured health plan sponsored by the institution), the regulated entity must comply with HIPAA requirements, including:
- Notice of Privacy Practices (NPP): Develop, distribute, and seek patient or beneficiary acknowledgement of a Notice of Privacy Practices that describes how PHI may be used and disclosed, individual rights, and the entity’s legal duties.
- Policies and Procedures: Adopt and implement policies and procedures to ensure compliance with all the HIPAA regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule.
- Security Risk Analysis: Conduct, on an annual basis or more frequently when the regulated entity changes its operations or technology in a way that may impact the risks to Electronic Protected Health Information (ePHI), a comprehensive, enterprise-wide security risk analysis of the risks and vulnerabilities to the ePHI that it holds.
- Business Associate Agreements (BAAs): Execute BAAs with any person or entity that creates, receives, maintains, or transmits PHI on behalf of the covered entity. BAAs must include specific provisions regarding permitted uses and disclosures, safeguards, breach reporting, and return or destruction of PHI.
- Workforce Training: Train all workforce members on the requirements of HIPAA, including the organization’s HIPAA policies and procedures as related to the individual’s job duties. Training should be provided at hire and at least annually thereafter, with documentation retained.
- Appointment of Privacy and Security Officers: Each HIPAA-regulated organization should appoint an individual to serve as its HIPAA Privacy Officer and its HIPAA Security Officer. These individuals lead the organization’s development, implementation, and enforcement of the organization’s Privacy Rule and Security Rule policies and compliance, respectively.
Academic medical centers and university hospitals
Institutions with academic medical centers or affiliated hospitals face additional complexity because the institution may operate simultaneously in an educational capacity and a healthcare capacity.
Patient records maintained by a university hospital, including records relating to students and non-students, are likely subject to HIPAA. At the same time, records maintained by the educational components of the university may remain subject to FERPA. One potentially important tool for institutions with both types of operations within one legal entity is the HIPAA hybrid covered entity designation. While most academic medical centers and university hospitals separate their educational and healthcare services in separate legal entities, for those operating under a single legal entity, they may designate their healthcare components as subject to HIPAA, segregating them from the non-HIPAA-covered components.
State law and other privacy requirements
FERPA and HIPAA do not necessarily provide the complete privacy framework for student health information. Depending on the state and the type of information involved, institutions may also need to consider:
- State mental health confidentiality laws and other state laws governing specially-protected health information, such as HIV and AIDS-related information, alcohol or drug abuse treatment, and genetic testing information
- State requirements concerning minors’ consent to healthcare
- State health privacy and consumer protection statutes
- Federal requirements governing substance use disorder records under 42 CFR Part 2
- State data breach notification requirements
These requirements can vary significantly by jurisdiction. Institutions operating across multiple states should consider whether different requirements apply to different populations or types of records.
A practical framework for institutions
When faced with a question concerning the privacy or disclosure of student health information, institutions may find it useful to work through the following questions:
- Who maintains the record?
Is the record maintained by the institution, an affiliated entity, or an independent provider? - In what capacity is the record maintained?
Is the entity acting on behalf of the institution in its educational capacity, or providing healthcare as a HIPAA covered entity? - What type of record is it?
Is it an education record, a treatment record, or PHI maintained by a HIPAA-covered component or a self-insured health plan? - How is the record being used?
Has a treatment record remained limited to treatment, or has it been used for another institutional purpose? - Who is seeking access?
Is the request from the student, a parent, an institutional employee, another treatment provider, law enforcement, or an outside party? - Is there an applicable exception?
Consider the relevant FERPA, HIPAA, or other state or federal law disclosure exception, including provisions concerning school officials, parents, and health or safety emergencies. - Are there additional obligations?
Review institutional policies, contractual confidentiality commitments, state law, and other federal privacy requirements.
Key takeaway
Understanding these distinctions can help institutions respond more consistently to routine records requests, parental inquiries, student health and safety concerns, and information-sharing questions involving affiliated healthcare providers.


