College Counseling Center HIPAA Compliance: Guidelines for Dean of Students Report Packets
FERPA Applicability to Counseling Records
When counseling records fall under FERPA
At most colleges and universities, counseling files are FERPA “treatment records” kept by a licensed professional and used only for the student’s treatment. In this status, they are not ordinary education records and are generally not accessible to the student affairs office, faculty, or parents without the student’s authorization.
Once counseling information is shared beyond treatment—for example, included in a Dean of Students Report Packet—it becomes an education record subject to FERPA’s privacy protections. At that point, you need a valid written consent or a documented exception before any disclosure.
Practical implications for report packets
For routine updates, avoid identifiable detail unless you have consent. Provide de-identified trends when possible, or limit content to attendance confirmations and functional impact summaries. Treat FERPA as the governing privacy rule for campus-based counseling centers unless a specific HIPAA condition applies.
Distinction Between HIPAA and FERPA
Which law governs
HIPAA does not apply to records that are already protected by FERPA. Most campus counseling centers are part of the institution and therefore operate under FERPA, not HIPAA. HIPAA may apply when counseling services are delivered by an external covered entity that is not acting on behalf of the school and maintains its own records of Protected Health Information (PHI).
Key differences you should know
- FERPA Privacy Rule: Controls disclosure of education and treatment records; emphasizes consent and specific exceptions.
- HIPAA: Regulates PHI held by covered entities; psychotherapy notes receive heightened protection and are never shared in routine packets.
- Re-disclosure: Both frameworks expect you to warn recipients that further sharing is restricted without new authorization or a valid exception.
Applying the right standard to Dean packets
If FERPA governs, use FERPA-compliant consent and exceptions. If HIPAA governs, use HIPAA-compliant authorization and the “minimum necessary” standard for PHI. In mixed environments, apply the stricter rule and document your rationale.
Confidentiality Standards in Counseling
Ethical baseline
Your default is strict confidentiality. Share only what advances student safety, care coordination, or a documented institutional need, and only with valid authorization. Keep psychotherapy content, session narratives, and collateral details out of routine Dean reports.
Content discipline for report packets
- Summarize functional impact on academics, risk status, and care plan without revealing intimate therapy details.
- Prefer brief attestations (attendance, referrals, safety check-ins) over diagnoses and progress notes.
- Flag any heightened confidentiality areas, such as substance use treatment or sexual assault counseling, which may trigger stricter State Confidentiality Laws or federal rules.
Safeguards
Use need-to-know access, verify recipient identity, and transmit via secure channels. Insert a re-disclosure warning on every packet to reinforce limits under FERPA or HIPAA.
Procedures for Written Consent
Written Consent Requirement
Before releasing identifiable counseling information to the Dean’s office, obtain a signed consent that is specific, time-limited, and voluntary. Explain what will be shared, why, with whom, and how long the consent lasts, and note the right to revoke.
Release of Information Forms: required elements
- Student identifiers and the exact offices or individuals authorized to receive information.
- Scope of disclosure (e.g., attendance only; functional limitations; risk and safety updates; no raw notes).
- Purpose of disclosure (e.g., academic support, safety planning, conduct review).
- Expiration date or event and revocation process.
- Re-disclosure warning and acknowledgement of potential FERPA or HIPAA protections.
- Special handling for sensitive categories governed by stricter State Confidentiality Laws or other federal rules.
Good practices
Review the form with the student in session, allow questions, and avoid pressuring consent. Provide a copy to the student, file it in the chart, and log each disclosure tied to that authorization.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Release of Information Protocols
Assembling a compliant Dean of Students Report Packet
- Confirm a valid consent or document the applicable exception.
- Extract only authorized data; exclude psychotherapy notes and detailed session content.
- Summarize using concise headings: presenting concern, functional impact, risk overview, care plan, and campus support recommendations.
- Insert a re-disclosure warning and the consent reference (date, scope, expiration).
- Use secure transmission; verify the recipient before sending.
- Record the disclosure in your log, including date, recipient, items released, and legal basis.
Minimum necessary in practice
Even where not legally mandated under FERPA, treat “minimum necessary” as a standard. Provide what the Dean needs to act—no more. When in doubt, narrow the scope or seek a targeted, updated consent.
Exceptions to Confidentiality
Confidentiality Exceptions you must know
- Serious and imminent threat to health or safety: disclose to those who can mitigate the danger, which may include the Dean, campus safety, or emergency responders.
- Mandatory reporting: suspected abuse or neglect of a minor or vulnerable adult as required by State Confidentiality Laws.
- Judicial orders and subpoenas: coordinate promptly with institutional counsel and release only what is compelled.
- Medical emergencies and required public health reporting where applicable.
- Substance use disorder records may be subject to stricter federal rules; apply the higher standard and document your analysis.
When invoking an exception, limit details to what is necessary, inform the student when safe and lawful, and document the facts, rationale, recipients, and timing.
Record Maintenance and Access
Segregation and security
Store counseling treatment records separately from student conduct or academic files. Use role-based access, encryption, and audit logs. Keep psychotherapy notes (if created) in a separate, extra-protected location and never include them in report packets.
Retention and documentation
Follow institutional policy, licensing board rules, and State Confidentiality Laws for retention periods. Maintain a disclosure log tied to each Release of Information Form and keep copies of all packets sent.
Counseling Record Access
Under FERPA, students have rights to inspect education records; treatment records used only for treatment are generally not directly accessible but can be reviewed by a professional of the student’s choice. Where HIPAA applies, students may access their PHI except psychotherapy notes, subject to lawful limitations.
Conclusion
For Dean of Students Report Packets, determine whether FERPA or HIPAA governs, obtain a precise consent, disclose the minimum necessary information, and document every step. Handle emergencies through well-defined exceptions, protect PHI and counseling records with strong safeguards, and align practices with State Confidentiality Laws.
FAQs.
When does HIPAA apply to college counseling records?
HIPAA applies when counseling services are provided by a covered entity that is not part of the institution’s FERPA-governed records system and maintains its own PHI. If the records are protected by FERPA, HIPAA’s privacy rule does not apply to those records.
How does FERPA affect counseling record confidentiality?
FERPA protects counseling treatment records maintained by a professional and limits disclosure without consent. If those records are shared beyond treatment—for example, with the Dean—they become education records, requiring written consent or a valid FERPA exception and restricting re-disclosure.
What are the requirements for releasing counseling information to the Dean of Students?
Obtain a signed Release of Information Form that meets the Written Consent Requirement, specify the purpose and scope, include a re-disclosure warning, and send only the minimum necessary content through secure channels. Use a documented exception only when legally justified, and log the disclosure.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.