Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Sports
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Advanced Manufacturing and Industrials
    • Art and Cultural Property
    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Entertainment & Sports
    • Financial Institutions
    • Healthcare
    • Higher Education
    • Infrastructure
    • Nonprofit Organizations
    • Real Estate
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Alerts
    4. Navigating the intersection of HIPAA and FERPA in Higher Education

      Alerts

    Alert / Higher Education

    Navigating the intersection of HIPAA and FERPA in Higher Education

    Sep 22, 2026

    LinkedInX (Twitter)EmailCopy URL

    A primer to understanding which privacy framework applies to student health information.

    What’s the impact?

    • Student health records at colleges are often governed by FERPA, not HIPAA, depending on who maintains the record and in what capacity.
    • Campus clinics serving students and non-students may need to apply both FERPA and HIPAA, with clear protocols for classifying records.
    • Institutions should also consider state privacy laws, professional confidentiality rules, and their own policies when handling student health information.

    DOWNLOAD

    HIPAA and FERPA in Higher Education (PDF)

    Authors

    • Lindsay Maleson

      Partner / Practice Group Leader, Healthcare
      • Long Island +1 516.832.7627
      • lmaleson@nixonpeabody.com
      Lindsay Maleson
    • Valerie Breslin Montague

      Partner
      • Chicago +1 312.977.4485
      • vbmontague@nixonpeabody.com
      Valerie  Breslin Montague
    • Alexandra A. Mitropoulos

      Counsel
      • Boston +1 617.345.6177
      • amitropoulos@nixonpeabody.com
      Alexandra A. Mitropoulos

    Colleges and universities routinely collect and maintain sensitive health information, including records from campus health centers, counseling services, disability services, and affiliated healthcare providers. Determining which federal privacy requirements apply to that information—either the Family Educational Rights and Privacy Act (FERPA) or the Health Insurance Portability and Accountability Act of 1996 (HIPAA)—can be complicated, particularly for institutions that operate healthcare facilities or have academic medical center or hospital affiliations. Although both laws address the privacy of personal information, they operate differently and apply to different types of records and entities.

    This primer provides an overview of the regulatory scope of FERPA and HIPAA and highlights some of the issues that colleges and universities should consider when handling student health information.

    FERPA and HIPAA: The basic framework

    The starting point is an important distinction: FERPA and the HIPAA Privacy Rule generally do not apply to the same records.

    • FERPA applies to “education records”—records that are directly related to a student and maintained by an educational agency or institution, or by a party acting for the institution.
    • HIPAA, by contrast, safeguards “protected health information” (PHI) held by certain types of entities meeting HIPAA’s definition of a covered entity, including certain healthcare providers and health plans.
    • The HIPAA Privacy Rule expressly excludes from the definition of PHI individually identifiable health information contained in education records covered by FERPA.

    The fact that a record contains health information does not, by itself, mean that HIPAA applies. For colleges and universities, the first question is generally whether the record is an education record under FERPA.

    The 2019 ED/HHS joint guidance

    The US Department of Education (ED) and the US Department of Health and Human Services (HHS) addressed the intersection of FERPA and HIPAA in joint guidance originally issued in 2008 and updated in 2019.

    The guidance emphasizes that the key question is whether the entity creating and maintaining the records is acting on behalf of an educational institution. Administrative control, rather than the physical location of the service or the source of funding, is generally the more important consideration.

    For example:

    Scenario

    Generally applicable framework

    Health clinic operated and controlled by the university

    FERPA

    Independent hospital providing care to a student

    HIPAA, assuming the hospital meets the definition of a covered entity

    School-employed nurse providing services to students

    FERPA

    Independent public health provider providing services on campus but not acting on behalf of the school

    HIPAA may apply

    Faculty member seen at the campus health clinic operated by the university

    HIPAA may apply (FERPA only covers student educational records)

    Spouse or community member seen at a campus clinic open to the public

    HIPAA may apply

    The specific facts and contractual relationships should be examined in each case. For example, a campus clinic serving a family member or a community member may be regulated by HIPAA if it engages in standard transactions under HIPAA, such as electronically billing payors, but may fall outside of HIPAA if it operates on a “cash-pay” basis without engaging in HIPAA standard transactions. If it is engaging in standard transactions, a single campus health clinic may operate under both FERPA and HIPAA simultaneously, with FERPA governing its student-patient records and HIPAA governing its non-student-patient records. This dual-regime reality makes it essential that campus clinics that serve mixed populations maintain clear internal protocols for classifying records, apply the correct privacy framework to each patient encounter, and train workforce members on the distinction. Institutions in this position should also consider whether a HIPAA hybrid entity designation (discussed below) is appropriate.

    Student health records under FERPA

    At the postsecondary level, student health records maintained by an institution or its employees generally are subject to FERPA rather than HIPAA. These records may constitute either education records or treatment records under FERPA.

    What are “treatment records?”

    FERPA contains a specific exception for certain records relating to a student’s treatment. For a student age 18 or older or attending a post-secondary institution, records may qualify as treatment records when they are:

    • Made or maintained by a physician, psychiatrist, psychologist, or other recognized professional or paraprofessional acting in that capacity
    • Made, maintained, or used only in connection with the student’s treatment
    • Disclosed only to individuals providing treatment 

    Treatment records are excluded from FERPA’s definition of “education records,” but they are also excluded from HIPAA coverage.

    The distinction is important because the treatment-record exception is narrow. If records are used for purposes other than treatment or disclosed to individuals other than treating providers, they may become education records subject to FERPA.

    Counseling and mental health records

    Counseling records raise many of the same issues, but institutions should be particularly attentive to the confidentiality representations they make to students. Records created by counselors and psychologists employed by or acting on behalf of an institution generally are education records subject to FERPA. The treatment-record exception may apply in certain circumstances, but only when its requirements are satisfied.

    In addition to FERPA, institutions may have independent obligations based on their own policies and representations. For example, student handbooks, counseling center policies, intake forms, and confidentiality statements may create expectations—or, depending on the circumstances, contractual obligations—concerning the treatment of student information.

    State Licensure-Based Psychotherapist-Patient Privilege

    State law also may impose independent confidentiality or privilege obligations on licensed mental health professionals. Depending on the jurisdiction and the professional’s license, these laws may apply to psychologists, psychiatrists, social workers, mental health counselors, marriage and family therapists, and other licensed professionals. The scope of the protection—and whether it is characterized as a privilege, a confidentiality obligation, or both—varies by state.

    Importantly, FERPA may govern the institutional record, while state law may independently regulate the clinician’s communications with the student. This distinction is important because an institution’s authority under FERPA does not necessarily answer whether a licensed clinician may disclose a particular confidential communication. Institutions should evaluate both the FERPA requirements applicable to the record and the professional’s independent obligations under applicable state law in order to determine what may be shared and in what contexts.

    One practical approach is to distinguish between information contained in an education record and the substance of confidential therapeutic communication. For example, depending on the applicable law and circumstances, a counseling center may be able to confirm that a student is receiving services or share certain administrative information without disclosing the substance of the student’s therapy sessions. Conversely, a request for the clinician’s observations, statements made by the student during therapy, or the content of a treatment session may implicate separate professional confidentiality or privilege protections.

    When HIPAA applies at a college or university

    Where it has been determined that HIPAA does apply (e.g., to a university hospital, a clinic on campus, or a self-insured health plan sponsored by the institution), the regulated entity must comply with HIPAA requirements, including:

    • Notice of Privacy Practices (NPP): Develop, distribute, and seek patient or beneficiary acknowledgement of a Notice of Privacy Practices that describes how PHI may be used and disclosed, individual rights, and the entity’s legal duties.
    • Policies and Procedures: Adopt and implement policies and procedures to ensure compliance with all the HIPAA regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule.
    • Security Risk Analysis: Conduct, on an annual basis or more frequently when the regulated entity changes its operations or technology in a way that may impact the risks to Electronic Protected Health Information (ePHI), a comprehensive, enterprise-wide security risk analysis of the risks and vulnerabilities to the ePHI that it holds.
    • Business Associate Agreements (BAAs): Execute BAAs with any person or entity that creates, receives, maintains, or transmits PHI on behalf of the covered entity. BAAs must include specific provisions regarding permitted uses and disclosures, safeguards, breach reporting, and return or destruction of PHI.
    • Workforce Training: Train all workforce members on the requirements of HIPAA, including the organization’s HIPAA policies and procedures as related to the individual’s job duties. Training should be provided at hire and at least annually thereafter, with documentation retained.
    • Appointment of Privacy and Security Officers: Each HIPAA-regulated organization should appoint an individual to serve as its HIPAA Privacy Officer and its HIPAA Security Officer. These individuals lead the organization’s development, implementation, and enforcement of the organization’s Privacy Rule and Security Rule policies and compliance, respectively.

    Academic medical centers and university hospitals

    Institutions with academic medical centers or affiliated hospitals face additional complexity because the institution may operate simultaneously in an educational capacity and a healthcare capacity.

    Patient records maintained by a university hospital, including records relating to students and non-students, are likely subject to HIPAA. At the same time, records maintained by the educational components of the university may remain subject to FERPA. One potentially important tool for institutions with both types of operations within one legal entity is the HIPAA hybrid covered entity designation. While most academic medical centers and university hospitals separate their educational and healthcare services in separate legal entities, for those operating under a single legal entity, they may designate their healthcare components as subject to HIPAA, segregating them from the non-HIPAA-covered components.

    State law and other privacy requirements

    FERPA and HIPAA do not necessarily provide the complete privacy framework for student health information. Depending on the state and the type of information involved, institutions may also need to consider:

    • State mental health confidentiality laws and other state laws governing specially-protected health information, such as HIV and AIDS-related information, alcohol or drug abuse treatment, and genetic testing information
    • State requirements concerning minors’ consent to healthcare
    • State health privacy and consumer protection statutes
    • Federal requirements governing substance use disorder records under 42 CFR Part 2
    • State data breach notification requirements
    •  

    These requirements can vary significantly by jurisdiction. Institutions operating across multiple states should consider whether different requirements apply to different populations or types of records.

    A practical framework for institutions

    When faced with a question concerning the privacy or disclosure of student health information, institutions may find it useful to work through the following questions:

    • Who maintains the record?
      Is the record maintained by the institution, an affiliated entity, or an independent provider?
    • In what capacity is the record maintained?
      Is the entity acting on behalf of the institution in its educational capacity, or providing healthcare as a HIPAA covered entity?
    • What type of record is it?
      Is it an education record, a treatment record, or PHI maintained by a HIPAA-covered component or a self-insured health plan?
    • How is the record being used?
      Has a treatment record remained limited to treatment, or has it been used for another institutional purpose?
    • Who is seeking access?
      Is the request from the student, a parent, an institutional employee, another treatment provider, law enforcement, or an outside party?
    • Is there an applicable exception?
      Consider the relevant FERPA, HIPAA, or other state or federal law disclosure exception, including provisions concerning school officials, parents, and health or safety emergencies.
    • Are there additional obligations?
      Review institutional policies, contractual confidentiality commitments, state law, and other federal privacy requirements.

    Key takeaway

    Understanding these distinctions can help institutions respond more consistently to routine records requests, parental inquiries, student health and safety concerns, and information-sharing questions involving affiliated healthcare providers.

    Practices

    HealthcareHealthcare Regulatory & ComplianceHealth Information - Privacy, Security & Data SharingCybersecurity & PrivacyDigital Health & Telemedicine

    Industries

    HealthcareHigher Education
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Supplier Code of Conduct
    • Nixon Peabody International LLP
    • PAL
    © 2026 Nixon Peabody. All rights reserved