FERPA vs. HIPAA: Coverage, Exceptions, and Enforcement

FERPA vs. HIPAA comes down to who holds the record, not what the record contains: FERPA protects records kept by schools that receive federal education funding, and HIPAA protects health information kept by healthcare providers, health plans, and clearinghouses that transmit data electronically. The two laws almost never cover the same record at the same time, because HIPAA’s rules explicitly carve out anything that qualifies as an education record under FERPA.1eCFR. 45 CFR 160.103 – Definitions That single carve-out resolves most of the confusion people run into when a school nurse, a college counseling center, or a university hospital gets involved.

The Dividing Line Between the Two Laws

The institution’s identity drives the analysis. A blood pressure reading taken at your doctor’s office is protected health information under HIPAA. The same reading taken by a school nurse at a public school is an education record under FERPA. The content is identical; the law that applies is not. Federal regulators set it up this way deliberately so schools wouldn’t have to comply with two overlapping privacy regimes for the same file.

Knowing which law governs matters because the rights you hold, the exceptions that allow disclosure without your consent, the penalties for violations, and the office you complain to all change depending on the answer.

What FERPA Covers

The Family Educational Rights and Privacy Act applies to every school that receives funding from any program run by the U.S. Department of Education, which includes virtually all public K-12 schools, community colleges, and universities. It gives parents the right to review their child’s education records and request corrections when something is inaccurate or misleading. When a student turns 18 or enrolls in a postsecondary institution at any age, those rights transfer to the student.2Office of the Law Revision Counsel. 20 U.S. Code 1232g – Family Educational and Privacy Rights

Education records include any files or documents maintained by the school that contain information directly related to a student. Grades, transcripts, disciplinary records, and financial aid files all qualify. The school must respond to a request to inspect records within 45 days, and if it refuses to correct something you’ve challenged, you’re entitled to a formal hearing.3U.S. Department of Education. FERPA – Protecting Student Privacy

What HIPAA Covers

HIPAA’s Privacy Rule sets national standards for protecting individually identifiable health information held by covered entities: health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with certain transactions. Your doctor’s office, your hospital, and your insurer are covered entities. Your employer generally is not, and neither is your school.4U.S. Department of Health and Human Services. The HIPAA Privacy Rule

Protected health information includes any individually identifiable data about your health condition, the care you’ve received, or payment for that care. HIPAA gives you the right to access your medical records, request corrections, and receive an accounting of who your information has been disclosed to. Covered entities must also follow the minimum necessary standard, meaning they should limit disclosures to only the information needed for a particular purpose rather than handing over an entire medical file when only one data point was requested.5U.S. Department of Health and Human Services. Minimum Necessary Requirement

Why School Health Records Fall Under FERPA

When a school nurse takes your child’s blood pressure, records immunization dates, or documents a visit for a stomach ache, those notes are education records under FERPA, not protected health information under HIPAA. HIPAA’s definition of protected health information explicitly excludes anything that qualifies as an education record.1eCFR. 45 CFR 160.103 – Definitions

Even when a school bills Medicaid or an insurance company electronically for student health services, which would normally make the school a HIPAA covered entity, the Privacy Rule still doesn’t apply to the student records themselves as long as they’re maintained as education records. The school must follow HIPAA’s transaction standards for the billing, but the underlying student health records stay under FERPA.6U.S. Department of Education. Joint Guidance on the Application of HIPAA and FERPA to Student Health Records

Treatment Records at Colleges and Universities

Postsecondary institutions add a wrinkle. FERPA carves out a special category called treatment records for students age 18 or older, or attending a postsecondary school at any age. These are records created by a physician, psychologist, or other recognized professional that are used only for the student’s treatment and disclosed only to the individuals providing that treatment.7eCFR. 34 CFR 99.3 – Definitions

Treatment records are excluded from FERPA’s definition of education records, and they’re also excluded from HIPAA’s definition of protected health information. They sit in a regulatory space of their own. As long as a university counseling center keeps its notes separate from the student’s main educational file and shares them only with treatment providers, those notes aren’t subject to either law’s full set of requirements. The moment the university discloses them outside the treatment context, they become education records and FERPA applies.

Telehealth and Outside Providers in Schools

When schools bring in outside healthcare providers through telehealth platforms, the analysis shifts. A school nurse employed by the district creates education records under FERPA. A third-party telehealth vendor providing remote medical consultations to students on school grounds typically operates under HIPAA, because the vendor is an outside healthcare provider rather than a school employee maintaining education records. Schools that contract with telehealth services should clarify in their agreements which law governs and who is responsible for safeguarding the records.

When One Institution Deals With Both Laws

Some institutions are subject to both FERPA and HIPAA, but almost never for the same record. The most common scenario is a university that operates a clinic or hospital open to the general public, including staff, faculty families, and community members. Student records at that clinic are governed by FERPA. Records for everyone else are governed by HIPAA.8U.S. Department of Health and Human Services. Joint Guidance on the Application of FERPA and HIPAA

University-affiliated hospitals add another layer. A hospital connected to a university generally doesn’t provide care to students on behalf of the educational institution. It provides care to everyone regardless of student status, and those records are subject to HIPAA. If that same hospital runs the campus student health clinic under an arrangement with the university, the clinic records for students fall under FERPA.

Private Schools and Coverage Gaps

Most private K-12 schools don’t receive federal funding directly from the Department of Education, so FERPA doesn’t apply to them. Whether HIPAA applies instead depends on whether the school employs a healthcare provider who transmits health information electronically in standard HIPAA transactions. If a private school neither receives federal education funding nor conducts covered electronic transactions, neither federal law governs its student health records. State privacy laws may fill some of the gap, but the protections vary widely.

Private colleges and universities almost always receive federal funding through student financial aid programs, which brings them under FERPA.

If your child receives special education services under the Individuals with Disabilities Education Act, IDEA adds requirements on top of FERPA (including broader consent rules and specific record-retention obligations), so FERPA is not the only standard the school must meet.9U.S. Department of Education. IDEA and FERPA Crosswalk

When Records Can Be Shared Without Your Consent

Both laws build in exceptions that allow sharing without your permission. The categories look different because the environments do, but the underlying idea is the same: privacy shouldn’t prevent an institution from functioning or responding to emergencies.

FERPA Exceptions

Schools may share education records without consent with school officials who have a legitimate educational interest, meaning they need the information to do their jobs. That includes teachers, administrators, and outside contractors performing services the school would otherwise handle with its own employees, as long as those contractors follow the same redisclosure restrictions as school staff.10eCFR. 34 CFR 99.31 – Under What Conditions Is Prior Consent Not Required to Disclose Information

Schools may also release records in response to a judicial order or lawfully issued subpoena. In most cases the school must make a reasonable effort to notify the parent or eligible student before complying, so you have a chance to object. That notification requirement disappears when the court or issuing agency specifically orders the school not to disclose the subpoena’s existence.

In a health or safety emergency, FERPA allows disclosure to any appropriate party, including law enforcement and medical personnel, when needed to protect the student or others. The exception is limited to the emergency itself and doesn’t authorize a blanket release of the full record.11U.S. Department of Education. When Is It Permissible to Utilize FERPA’s Health or Safety Emergency Exception for Disclosures

HIPAA Exceptions

HIPAA’s broadest exception permits covered entities to use and disclose protected health information for treatment, payment, and healthcare operations without patient authorization.12eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations Your doctor can share your records with a specialist you’ve been referred to, and a hospital can send billing information to your insurer, without you signing an authorization form each time.

HIPAA also permits disclosures required by law, for public health activities, to avert a serious threat to health or safety, and for certain law enforcement purposes. Even when these exceptions apply, the minimum necessary standard still governs the volume of information shared.

Penalties and Enforcement

FERPA’s only federal enforcement lever is funding. A school that systematically violates the law risks losing money from the Department of Education. In practice, the Student Privacy Policy Office investigates complaints and schools typically enter into a voluntary compliance agreement to fix the problem. Actual termination of funding is extremely rare. FERPA doesn’t create a private cause of action, so you can’t sue a school in federal court for damages, though some states have their own student privacy statutes with different remedies.

HIPAA is far more aggressive. Civil monetary penalties follow a four-tier structure based on the violator’s level of culpability, ranging from violations the covered entity didn’t know about and couldn’t reasonably have known about, up through willful neglect that wasn’t corrected within 30 days. Penalty amounts adjust annually for inflation. For 2026, the per-violation minimum starts at $145 for the lowest tier and reaches $73,011 for willful neglect, with an annual cap of $2,190,294 per violation category.

Criminal penalties apply when someone knowingly obtains or discloses protected health information in violation of HIPAA. The baseline is a fine of up to $50,000 and up to one year in prison. If the violation involves false pretenses, the ceiling rises to $100,000 and five years. For violations committed with intent to sell, transfer, or use health information for commercial gain or malicious harm, the penalties reach $250,000 and ten years.13GovInfo. 42 U.S. Code 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

How to File a Complaint

FERPA complaints go to the Student Privacy Policy Office at the Department of Education. The complaint must be in writing, must describe specific facts giving reasonable cause to believe a violation occurred, and must be filed within 180 days of the alleged violation or within 180 days of when you learned about it. You can email the complaint form to FERPA.Complaints@ed.gov or mail it to the SPPO in Washington, D.C. The Department encourages you to try resolving the issue directly with the school first, but that step isn’t required.14U.S. Department of Education. File a Complaint – Protecting Student Privacy

HIPAA complaints go to the Office for Civil Rights at the Department of Health and Human Services. Anyone can file, not just the person whose information was disclosed. The fastest route is the OCR Complaint Portal online. If OCR finds a violation, the covered entity may be required to take corrective action, enter into a resolution agreement, or face civil monetary penalties.15U.S. Department of Health and Human Services. Filing a Health Information Privacy Complaint

Quick Comparison

  • Who it covers: FERPA applies to schools receiving federal education funding. HIPAA applies to healthcare providers, health plans, and clearinghouses that transmit health data electronically.
  • What it protects: FERPA covers education records. HIPAA covers individually identifiable health information held by covered entities.
  • School health records: generally FERPA, not HIPAA, because they’re maintained as part of the education record.
  • Enforcement: FERPA’s only federal penalty is loss of funding. HIPAA carries per-violation civil fines and criminal penalties up to $250,000 and ten years in prison.
  • Private lawsuits: FERPA does not allow them. HIPAA does not create a federal private right of action either, though some state laws do.
  • Complaint deadlines: FERPA requires filing within 180 days. HIPAA complaints should generally be filed within 180 days as well, though OCR has discretion to extend the deadline.