FERPA vs HIPAA for Student Health Records 2027: Which Law Applies to Your Campus Clinic?
FERPA or HIPAA? How campus clinic and counseling records are classified, when both laws apply, and what that means when you choose a HIPAA-compliant EHR.
By ClinikEHR Team
Duration
24 MINSDirectors of college health and counseling centers ask the same question every time they replace a system: are our records governed by FERPA or by HIPAA? The answer decides who may see a student's chart, when parents can be told anything, and which rules shape the contract with your software vendor. The short version is that most records at a clinic serving only students fall under FERPA, not HIPAA, but billing, non-student patients and hospital arrangements change the picture. This guide explains the rules from the official sources and what they mean when you are shopping for a HIPAA-compliant college EHR.
Quick Answer
At a college or university, health records about students are generally education records or treatment records under FERPA, and HIPAA's Privacy Rule excludes both of those categories from the definition of protected health information. That stays true even when the institution is otherwise a HIPAA covered entity. HIPAA comes into play for records about non-students (faculty, staff, community patients) when the provider is a covered entity, which usually means it bills health plans electronically. Either way, the software holding the records needs strong access controls, an audit trail and a vendor willing to sign a Business Associate Agreement. Confirm how these rules apply to your campus with your institution's counsel.
One record system for FERPA and HIPAA records
Note: This article is general information, not legal advice. FERPA and HIPAA interact with state health privacy and minor consent laws, so confirm how they apply to your campus with your institution's counsel. For a comparison of systems, see our Top 5 EHR for College & University Health Centers 2027.
What Does FERPA Cover?
The Family Educational Rights and Privacy Act (20 U.S.C. § 1232g) and its regulations at 34 CFR Part 99 apply to educational agencies and institutions that receive funds under programs administered by the US Department of Education. That includes nearly every public and private college in the country. The Department's Student Privacy Policy Office publishes the official guidance at studentprivacy.ed.gov.
FERPA protects education records: records that are directly related to a student and maintained by the institution, or by a party acting for it. The definition is broad on purpose. It is not limited to grades and transcripts. A note written by a campus nurse, an immunization form kept by the health office and a bill for a clinic visit can all be education records, because they are about a student and the institution keeps them.
Once a student turns 18 or attends a postsecondary institution, the rights under FERPA belong to the student, who is then an "eligible student". Those rights are to inspect and review their records, to ask for corrections, and to control most disclosures. The institution generally needs the student's written consent before it discloses personally identifiable information from an education record, unless one of the exceptions listed in 34 CFR 99.31 applies.
One of those exceptions matters for any software decision. School officials inside the institution may access records in which they have a legitimate educational interest, and the institution is expected to use reasonable methods to make sure officials reach only the records they need. A contractor that performs an institutional service, such as a software vendor, can be treated as a school official under conditions the institution sets. In practice, that is FERPA's version of access control, and it is why role-based permissions and access logs matter even where HIPAA does not apply.
What Does HIPAA Cover?
HIPAA's Privacy and Security Rules apply to covered entities (health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with a standard transaction) and to their business associates. The standard transactions include electronic claims and eligibility checks. So a provider becomes a covered entity through what it does, not through what it is called. HHS explains the categories on its HIPAA for professionals pages.
HIPAA protects protected health information (PHI): individually identifiable health information held or transmitted by a covered entity or business associate. The key detail is in the definition itself, at 45 CFR 160.103. PHI expressly excludes education records covered by FERPA, and it also excludes the student treatment records described in FERPA. Congress and HHS drew that line so the same record would not sit under two different federal privacy regimes.
The Security Rule follows electronic PHI. Where records are PHI, the covered entity must run a risk analysis and put administrative, physical and technical safeguards in place, and it must sign a Business Associate Agreement with any vendor that creates, receives, maintains or transmits PHI for it (HHS: Business Associates).
What Are FERPA "Treatment Records"?
Treatment records are the category most campus clinics actually live in. The FERPA regulations exclude them from the definition of education records (34 CFR 99.3). A record is a treatment record when it is:
- About a student who is 18 or older, or who attends a postsecondary institution;
- Made or maintained by a physician, psychiatrist, psychologist or other recognized professional or paraprofessional acting in that capacity;
- Made, maintained or used only in connection with treatment of the student; and
- Disclosed only to individuals providing the treatment (a physician or other appropriate professional of the student's choice may review it).
Because treatment records are not education records, the student has no FERPA right to inspect them in the usual way, although the student can have them reviewed by a professional of their choice. The protection comes from the narrow use: the records stay within the treating team.
The category is fragile, and that is the point most explainers miss. If an institution discloses a treatment record for any purpose other than treatment, the record becomes an education record under FERPA, with all of FERPA's rights and disclosure rules attached. It does not become PHI. So a counseling note shared with a dean's office for a conduct process has moved from one FERPA category to another. Any system you choose should make it easy to keep treatment records inside the treating team and to see who opened them.
When Is a Campus Clinic's Record FERPA, and When Is It PHI?
HHS and the Department of Education address this directly in their joint guidance on applying FERPA and HIPAA to student health records, summarized on the HHS FERPA and HIPAA page. The general picture looks like this, with the usual caveat that your facts decide the answer.
A clinic that serves only students. When a college or university health center treats only its own students, its records are generally either treatment records or education records under FERPA. Neither is PHI. That holds even if the institution is a HIPAA covered entity because, for example, the clinic bills student health insurance electronically. Electronic billing makes the provider a covered entity, but the students' records remain excluded from PHI by definition.
A clinic that also serves non-students. Many campus clinics see faculty, staff, spouses or members of the public. Records about those patients are not education records, because the patients are not students. If the provider is a covered entity (usually because it conducts standard transactions electronically), those non-student records are PHI and HIPAA applies to them in full. The same waiting room, the same clinicians and the same software can therefore hold records under two different laws.
A clinic that does not bill electronically. A student-only clinic that never conducts a HIPAA standard transaction electronically may not be a covered entity at all. Its records are still FERPA records, and state health privacy law still applies. Some institutions adopt HIPAA-style policies anyway, because they are a well-understood baseline.
A university hospital or academic medical center. When a hospital treats students on the same basis as the general public, and not on the institution's behalf as its student health service, those records are typically PHI under HIPAA. Institutions with a medical center often designate themselves as hybrid entities so that HIPAA applies to the health care components and FERPA to the rest.
K-12 schools. Records kept by a school nurse about a student under 18 in a school district are generally education records under FERPA. The treatment records category is for students who are 18 or older or who attend a postsecondary institution.
FERPA vs HIPAA at a Glance
| Question | FERPA | HIPAA |
|---|---|---|
| Who does it apply to? | Educational agencies and institutions that receive US Department of Education program funds | Health plans, clearinghouses, providers that conduct standard transactions electronically, and their business associates |
| What records? | Education records, directly related to a student and maintained by the institution | Protected health information, excluding FERPA education and treatment records |
| Student clinic records? | Usually treatment records or education records | Usually not PHI, even if the institution is a covered entity |
| Non-student patients? | Not covered (they are not students) | Covered, if the provider is a covered entity |
| Who holds the rights? | The eligible student, once 18 or at a postsecondary institution | The individual, or their personal representative |
| Disclosure to parents? | Permitted only under listed exceptions, such as a dependent student or a health or safety emergency | Generally through the patient's agreement, a personal representative, or a listed permission |
| Emergencies? | Health or safety emergency exception, 34 CFR 99.36 | Serious and imminent threat, 45 CFR 164.512(j) |
| Security requirements? | Reasonable methods to limit officials' access | Security Rule safeguards for electronic PHI |
| Vendor contract? | School-official conditions set by the institution | Business Associate Agreement |
| Enforcer? | Department of Education, Student Privacy Policy Office | HHS Office for Civil Rights |
A Decision Flow for Your Clinic
Use this as a starting point for the conversation with your institution's counsel, not as a conclusion.
- Is the record about a current or former student of the institution? If no, go to step 5.
- Does the institution receive Department of Education program funds? Almost every college does. If yes, the record is governed by FERPA, and the next question is which FERPA category it falls in.
- Was it made by a treating professional, used only for treatment and shared only with the treating team, about a student 18 or older or at a postsecondary institution? If yes, it is a treatment record. If not, or if it has been disclosed for another purpose, it is an education record.
- Either way, it is not PHI. HIPAA's Privacy Rule does not govern it, but FERPA, state health privacy law, professional ethics and your contracts still do.
- For non-student patients: does the provider conduct HIPAA standard transactions electronically? If yes, it is a covered entity and those records are PHI. If no, state law and institutional policy govern them.
- Is a hospital or medical center involved? Check whether the institution is a hybrid entity and which components are designated as health care components.
- Are there substance use disorder or psychotherapy records? Check whether 42 CFR Part 2, HIPAA's psychotherapy notes rules or state mental health confidentiality laws add conditions.
- Write the answer down. Record which law governs each record type, who may access each, and the disclosure procedures, then configure your EHR's roles to match.
When Do Both Laws Matter at Once?
Both laws matter whenever a single operation holds records about students and non-students, or whenever student health work crosses into a HIPAA-covered part of the institution. Common examples:
- A student health center that also runs an employee health or occupational health service for faculty and staff.
- A campus clinic open to spouses, dependants or the local community.
- A university hospital that sees students referred by the campus clinic, or that operates the clinic under contract.
- Athletics medicine, where team physicians may be employed by a health system rather than the university.
In each case the practical rule is the same: classify the record by who the patient is and who holds the record, then apply the matching disclosure rules. The software does not decide which law applies, but it should let you run both sets of rules side by side. That means role-based access, the ability to restrict individual charts, a complete record of who viewed what, and disclosure tracking you can export when a student or patient asks.
Can a Campus Clinic Tell Parents?
Under FERPA, the rights belong to the eligible student. A college may disclose information from education records to parents without the student's consent only under specific exceptions in 34 CFR 99.31. The ones that come up in student health are: the student is a dependant of the parents for federal tax purposes; there is a health or safety emergency; and, for students under 21, a violation of institutional rules or law about alcohol or controlled substances. These exceptions permit disclosure; they do not require it. Many institutions set a narrower policy.
Treatment records add a wrinkle. Because they must be used only for treatment, sharing one with a parent for a non-treatment reason turns it into an education record, and the disclosure must then fit a FERPA exception. Most campus health centers therefore route any parent contact through the student's written consent unless an emergency applies.
Where HIPAA applies instead (for example, a non-student patient), family involvement is governed by the Privacy Rule's provisions on the individual's agreement, personal representatives and the listed permissions. State minor consent laws also matter, particularly for students under 18 who enroll early. Confirm the rules for your state with your institution's counsel.
What Happens in an Emergency?
FERPA's health or safety emergency exception (34 CFR 99.36) lets an institution disclose information to appropriate parties, including parents, when knowledge of it is necessary to protect the health or safety of the student or others. The institution considers the totality of the circumstances, and where it determines there is an articulable and significant threat, it may disclose to those whose knowledge is needed to protect against it. It must record the threat and the parties it disclosed to.
Under HIPAA, 45 CFR 164.512(j) permits a covered entity to disclose PHI when it believes in good faith that doing so is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public, to someone reasonably able to prevent or lessen it.
The two tests are worded differently but aim at the same situations: a student at risk of harming themselves or others, an outbreak, a medical emergency. For the clinic, the operational requirement is identical. Clinicians who need a record in an emergency must be able to open it quickly, the access must be recorded with a reason, and someone accountable must be told.
How Are Counseling Records Treated?
Records kept by a campus counseling center about its students are usually FERPA treatment records, on the same logic as medical records. They carry extra layers, though. State mental health confidentiality laws are frequently stricter than either federal law, and professional licensing rules add their own duties. Where HIPAA does apply (for example, counseling for staff under a covered entity), psychotherapy notes need a specific authorization for most disclosures. And if the center runs a federally assisted substance use disorder program, 42 CFR Part 2 may apply on top.
Counseling centers also tend to share a building, a front desk or a scheduling system with medical services. The record system should let front-desk staff book and bill counseling appointments without seeing clinical content, and let clinicians lock the most sensitive notes to the treating counselor. We cover this in detail in our guide to EHRs for college counseling centers.
What Does This Mean for Choosing an EHR Vendor?
It is tempting to conclude that a FERPA-only clinic does not need a HIPAA-compliant EHR. That is the wrong lesson, for three reasons.
First, few campus clinics are purely FERPA. If you see even a handful of staff patients and bill electronically, some of your records are PHI, and the vendor holding them is a business associate that must sign a BAA. It is far simpler to run one system under one standard than to split records by patient type.
Second, FERPA still expects the institution to control access. The reasonable-methods expectation for school officials, the institution's own information security policy, state data breach laws and your contracts all push toward the same controls the HIPAA Security Rule describes: unique user accounts, role-based access, audit logs, strong sign-in and a secure way to share records.
Third, a vendor can sign a BAA regardless of which law governs a given record. A BAA does not change FERPA's application to student records; it simply sets out the vendor's obligations where PHI is involved, and it tells you the vendor already operates to that standard. Ask your counsel whether the institution's own vendor terms should also name the vendor as a school official under FERPA, and what data use limits they should carry.
So the question to put to vendors is not "FERPA or HIPAA?" It is "Can your system hold both kinds of record under controls that satisfy both, and will you put that in writing?"
What to Look for in an EHR Either Way
- A signed Business Associate Agreement available on the plan you will use, not only on an enterprise tier.
- Individual accounts and role-based permissions, so front-desk, billing, nursing, medical and counseling staff each see only what their job needs.
- Chart-level restriction, so a record can be limited to named staff (useful for student employees, athletes, residence staff and staff patients).
- Sensitive-note locks for counseling, sexual health and substance use records.
- An audit trail that records views, not only edits, kept for years and readable only by accountable people.
- Emergency access with a reason and a time limit, and notification to the people responsible for the record.
- Disclosure accounting you can export, for FERPA recordkeeping and HIPAA accounting requests alike.
- Two-factor sign-in the clinic can enforce for everyone.
- A student-facing portal with privacy controls, including limits on what a guardian or parent can see.
- Data export on demand, so the institution can move or archive records without depending on the vendor.
How ClinikEHR Fits
ClinikEHR is built for HIPAA-regulated work. Accepting the Business Associate Agreement is part of signing up, which puts the workspace under it, and the BAA also covers ClinikMail and ClinikReach. The product records the creation, change, deletion and viewing of clinical records, as well as sign-ins, keeps that trail for seven years, and lets only owners and managers read it. An owner can require two-factor authentication for everyone in the practice, after which clinical data will not open until a second factor is set up. Records can be exported at any time. These facts come from the ClinikEHR Help Center's HIPAA and security pages.
For student privacy specifically, the client privacy features matter most. On every plan, including Free, you can restrict a client so only the clinic owner and the assigned staff see their name and record; everyone else sees a secured label and a number. Any team member can open a secured record in an emergency by giving a reason and choosing a time limit of up to 24 hours, and the owner and assigned staff are told immediately. On the Essential plan and up, you add care team roles, sensitive-record locks for behavioral health, substance use, reproductive health and HIV records, an access log of every open, download and print of a restricted record, disclosure accounting with CSV export, unusual-access alerts and limits on what a guardian's portal view can show. Clients can ask for a restriction from their own portal on every plan; the fuller client portal, where clients book, pay, message and read documents, is on Essential and up.
A campus clinic will outgrow the Free plan quickly: it allows 2 staff and 50 clients. Essential includes 3 staff, with extra clinicians at $40 a month each up to 5. Team includes 5 staff, then $35 a month for each extra clinician. Larger services can ask about Enterprise, which has no staff cap. See pricing for current plan prices. ClinikEHR does not decide whether a record is governed by FERPA or HIPAA; your institution does, and the system then lets you apply the access rules you choose.
Frequently Asked Questions
Are college health center records covered by HIPAA or FERPA?
At a clinic that serves only students, records are generally FERPA treatment records or education records, and HIPAA excludes both from protected health information. Records about non-student patients can be PHI if the provider is a HIPAA covered entity. Confirm with your institution's counsel.
What is a FERPA treatment record?
It is a record about a student who is 18 or older or at a postsecondary institution, made or kept by a physician, psychologist or other recognized professional, used only for treatment, and shared only with those providing treatment. Treatment records are excluded from education records.
Does billing insurance make a campus clinic subject to HIPAA?
Billing health plans electronically can make the provider a HIPAA covered entity. Even then, records about its students stay excluded from PHI because they are FERPA records. Records about non-student patients would be PHI.
Can a college tell parents about a student's health visit?
Only under specific FERPA exceptions, such as a dependent student for tax purposes, a health or safety emergency, or an alcohol or drug violation by a student under 21. The exceptions permit disclosure but do not require it, and many institutions ask for the student's written consent.
Do we need a BAA if our records are covered by FERPA?
A BAA is required where a vendor handles PHI for a covered entity. Many campus clinics hold some PHI, for example records of staff patients, so a BAA is usually needed. A vendor willing to sign one also shows it operates to HIPAA security standards, which helps meet FERPA access expectations.
Are counseling center records treated differently?
Campus counseling records about students are usually FERPA treatment records too, but state mental health confidentiality laws are often stricter, and 42 CFR Part 2 can apply to federally assisted substance use disorder programs. Confirm with your institution's counsel.
Conclusion
For most campus clinics, student records are governed by FERPA, not HIPAA, because HIPAA's definition of PHI leaves FERPA education and treatment records out. HIPAA returns for non-student patients when the provider bills electronically, and for hospital settings that treat students like any other patient. In practice, the controls you need are the same either way: individual accounts, role-based access, chart restriction, an audit trail of every view, emergency access with a reason, and a vendor that will sign a BAA.
Key takeaways:
- Student records at a campus clinic are usually FERPA treatment or education records, not PHI
- A treatment record shared for a non-treatment purpose becomes an education record, not PHI
- Non-student records are PHI when the provider is a covered entity
- Parents can be told only under FERPA exceptions, which permit rather than require disclosure
- Choose an EHR with strong access controls and a BAA, whatever law governs each record
Setting up a campus clinic or counseling center? Try ClinikEHR free, compare our plans, or book a free demo.
Student privacy, built into the chart
Disclaimer: This article is general information and not legal advice. FERPA, HIPAA and state privacy laws depend on your institution's circumstances; confirm how they apply with your institution's counsel.
Related Articles
- Top 5 EHR for College & University Health Centers 2027
- EHR for College Counseling Centers 2027
- Campus Health Clinic Software 2027: Immunizations, Walk-Ins, Student Portals and Billing
- HIPAA-Compliant Messaging 2027: Email vs Portal vs Secure Chat
- Digital Intake Forms With E-Signature: A HIPAA Guide for Clinics (2027)
- 7 Best HIPAA-Compliant Form Builders for Healthcare (2027)
- Best EHR for Multi-Provider Clinics 2026: Shared Calendars, Permissions & Billing
Stay in the loop
Subscribe to our newsletter for the latest updates on healthcare technology, HIPAA compliance, and exclusive content delivered straight to your inbox.