HIPAA Compliance for College Health Centers: What Universities Need to Know
Understanding HIPAA Applicability to Postsecondary Institutions
College health centers often qualify as HIPAA covered entities because they provide health care and transmit standard electronic transactions such as claims, eligibility checks, or referrals. If that’s true for your clinic, the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule apply to the center’s protected health information (PHI).
At the university level, you can use a hybrid entity designation to narrow HIPAA’s scope to specific covered functions. In practice, you treat the clinic, pharmacy, lab, or student health insurance plan as the HIPAA-regulated health care component, while keeping the rest of campus outside HIPAA.
Key threshold questions
- Does your clinic submit HIPAA-standard transactions electronically (e.g., 837 claims)?
- Do you operate a pharmacy, lab, or health plan that creates or receives PHI?
- Have you documented which units are inside the health care component and which are not?
Answering “yes” typically triggers HIPAA obligations for the component, including role-based access, minimum necessary, risk analysis, workforce training, and a posted Notice of Privacy Practices.
Navigating FERPA vs. HIPAA for Student Health Records
For students, most records maintained by the institution are governed by FERPA, not HIPAA. That includes medical or counseling notes stored by a campus clinic when the clinic is part of the university. FERPA treatment records are used only for a student’s treatment by health professionals; if shared beyond treatment providers, they become education records—still under FERPA, not HIPAA.
HIPAA generally does not apply to education records or treatment records protected by FERPA. This means your clinic must align release processes with FERPA consent rules and “legitimate educational interest,” not HIPAA authorizations, when records are FERPA-controlled.
Practical implications
- Do not assume HIPAA governs student charts just because they look like medical records.
- If a record moves from the clinic to academic advising, student affairs, or athletics, it remains under FERPA.
- Use clear intake forms so students know which privacy regime applies to their information.
Managing Health Records of Non-Students
Records for non-students—such as faculty, staff, dependents, campus visitors, or campers—are often not education records. When your clinic treats these individuals as patients, their files are typically PHI subject to the HIPAA Privacy Rule within the health care component.
Be careful with employee information. Health data an employer maintains solely in employment records (e.g., fitness-for-duty, drug testing required by HR) is not PHI, even if created by a clinician. However, care delivered to an employee as a patient of the clinic is PHI inside the component. Define which hat you’re wearing—provider vs. employer—before you collect data.
Operational tips
- Use separate encounter types and locations in the EHR for employment-related evaluations.
- Set role-based access so HR cannot view clinical PHI and clinicians cannot see HR files.
- Maintain distinct retention schedules and disclosure pathways for PHI vs. employment records.
Designating a Health Care Component
A formal health care component designation lets a university operate as a hybrid entity and focus HIPAA on covered functions. This boundary protects PHI while allowing the rest of campus to follow FERPA or other rules without undue burden.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
How to implement
- Inventory covered functions: clinic(s), pharmacy, lab, medical billing, student health plan.
- Document the health care component and any supporting units that must be included.
- Map data flows to and from non-covered units; implement “firewalls” and minimum necessary.
- Assign HIPAA roles, train the workforce, and publish a Notice of Privacy Practices.
- Conduct a security risk analysis for ePHI and address gaps in technical and physical safeguards.
Common pitfalls
- Letting non-component staff access clinic schedules or progress notes “for convenience.”
- Migrating PHI into campus-wide systems (email, ticketing, shared drives) without controls.
- Skipping documentation of the hybrid entity designation and component scope.
Ensuring Compliance with Business Associate Agreements
A business associate agreement (BAA) is required before you disclose PHI to a vendor that creates, receives, maintains, or transmits PHI for your component. Typical business associates include EHR and billing vendors, telehealth platforms, cloud hosting, transcription, secure messaging, and analytics providers.
When you need a BAA
- If the vendor will host or process PHI for the clinic or health plan, execute a business associate agreement first.
- Cloud and messaging providers ordinarily act as business associates; do not rely on a broad “conduit” claim.
- For mixed records, segment data or ensure the BAA clearly covers the PHI use cases.
When a BAA may not apply
- Vendors handling only FERPA-protected education records can be treated as school officials under FERPA, not business associates under HIPAA.
- Pure shipping or telecom carriers acting as true conduits may not require a BAA.
BAA essentials
- Permitted uses/disclosures, breach reporting timelines, subcontractor flow-downs, and return or destruction of PHI.
- Security requirements, audit rights, and indemnification aligned with your risk profile.
- Clear instructions for data segregation when the vendor serves both HIPAA and FERPA realms.
Handling Disclosure of Immunization Records
Immunization record disclosure arises frequently during admissions and clinical placements. Under HIPAA, a provider may disclose proof of immunization to a school with the student’s (or parent’s, if applicable) agreement—written or oral—when state law requires the school to have such proof. Document the agreement, the date, the recipient, and the specific vaccines disclosed.
Where records are FERPA-controlled within the institution, follow FERPA consent rules for releasing immunization information beyond school officials. Apply the minimum necessary standard inside HIPAA components and share only what the requester needs to satisfy policy or law.
Good practices
- Use a standardized form to capture consent or agreement for immunization disclosures.
- Verify state or program requirements before releasing information.
- Route student proofs to the FERPA repository (e.g., admissions or registrar) rather than storing duplicates in general campus systems.
Coordinating Compliance with HIPAA and FERPA
Running both regimes side by side requires clear boundaries, consistent training, and coordinated incident response. Start by classifying data at collection, then keep it in systems designed for that regime. Avoid copying PHI or FERPA records into platforms that lack appropriate safeguards.
Programmatic coordination steps
- Data classification at intake: label records as PHI, FERPA education records, FERPA treatment records, or employment records.
- System separation: keep EHRs, student information systems, and HR systems distinct; restrict cross-loading.
- Access controls: grant role-based access tied to job duties within the health care component or FERPA unit.
- Vendor management: use a business associate agreement for PHI vendors and FERPA-compliant contracts for education records.
- Incident response: run HIPAA breach analysis for PHI, apply FERPA requirements for unauthorized disclosures, and follow state law for personal data where applicable.
- Training and auditing: tailor annual training to each regime and audit for boundary drift.
Key takeaways
- Most college clinics fall under HIPAA, but student records they maintain are usually governed by FERPA.
- A clear hybrid entity designation and well-drawn health care component prevent cross-regime confusion.
- Right-size BAAs, consent workflows, and immunization record disclosure processes to each rule set.
FAQs.
How does HIPAA apply to college health centers?
HIPAA applies to the health care component of a university that functions as a covered entity, such as a clinic, pharmacy, lab, or health plan that conducts standard electronic transactions. Within that component, you must safeguard protected health information, follow the HIPAA Privacy Rule and Security Rule, and meet breach notification requirements.
What are the differences between FERPA and HIPAA for student health records?
Student health records maintained by the institution are covered by FERPA, not HIPAA. FERPA treatment records are used only for treatment by health professionals and become education records if shared beyond treatment providers. HIPAA generally excludes both categories from PHI, so FERPA’s consent and disclosure rules control.
When does HIPAA protect non-student health records?
When your clinic treats non-students—such as employees, dependents, or visitors—as patients, those records are typically PHI inside the health care component. Employment records kept by HR for workplace purposes are not PHI, but clinical care delivered to an employee as a patient is PHI and subject to HIPAA.
How should colleges handle business associate agreements under HIPAA?
Identify vendors that create, receive, maintain, or transmit PHI and execute a business associate agreement before any disclosure. Include clear security, breach reporting, subcontractor, and data return terms. If a vendor handles only FERPA education records, use FERPA-compliant school official agreements instead of a BAA, or segment data when the vendor supports both regimes.
Table of Contents
- Understanding HIPAA Applicability to Postsecondary Institutions
- Navigating FERPA vs. HIPAA for Student Health Records
- Managing Health Records of Non-Students
- Designating a Health Care Component
- Ensuring Compliance with Business Associate Agreements
- Handling Disclosure of Immunization Records
- Coordinating Compliance with HIPAA and FERPA
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.