HIPAA Compliance for School Speech-Language Pathologists: Managing IEPs and PHI
Defining PHI and Its Scope
Protected Health Information (PHI) is individually identifiable health information created, received, maintained, or transmitted by a HIPAA covered entity or its business associate. It includes both paper and electronic forms (ePHI) and ties to a person’s identity, health status, care, or payment.
What counts as PHI in SLP practice
Examples include evaluation reports, therapy notes, diagnoses, service authorizations, progress data, billing details, and audio/video used for treatment. When stored in electronic health records, the same content is ePHI and must meet HIPAA safeguards.
When HIPAA applies in schools
If you are employed by or contracted through a healthcare provider that bills electronically (for example, a clinic delivering on-campus services or teletherapy), your clinical records are PHI. If you are employed directly by a public school and your records are part of a student’s individualized education program or education file, those records are typically governed by FERPA rather than HIPAA.
Distinguishing HIPAA from FERPA
HIPAA protects PHI held by healthcare entities, while FERPA protects student education records held by schools. Most school-based SLP records maintained by the district are education records, even if they include health details, and are not PHI.
Common school scenarios
- School-employee SLP: IEPs, service logs, and progress notes are education records under FERPA.
- Clinic-contracted SLP: The clinic’s copy is PHI; the school’s copy of shared information becomes an education record under FERPA.
- School billing Medicaid: Using standard electronic claim formats does not convert FERPA records into PHI; privacy rules for the student record remain under FERPA.
Business Associate Agreement considerations
A Business Associate Agreement is required when a HIPAA covered entity uses a vendor to handle PHI (for example, an EHR or teletherapy platform for a clinic). Public schools handling FERPA education records generally use data privacy or vendor agreements, not BAAs, unless a true HIPAA relationship exists.
Minimum necessary and consent
Under HIPAA, share only the minimum necessary PHI for a task. Under FERPA, disclose student records outside the school only with valid parent consent or an applicable exception. Align your process with the governing law for the record you hold.
Documentation Requirements for SLPs
Thorough documentation supports educational benefit, medical necessity documentation for payers, and defensible audits. Keep records clear, timely, and aligned to each student’s individualized education program and service authorization.
Core clinical and educational file
- Evaluations/eligibility reports, plan of care, and IEP-linked goals.
- Session notes with date, start/stop time, duration, location, individual vs. group, methods, data, and response.
- Progress summaries tied to goals and decision-making for continuation, modification, or discharge.
- Provider identity, credentials, signatures (and co-signatures for supervised personnel).
- Parent communications, consent forms, and collaboration notes with teachers or outside providers.
Medical necessity documentation
- Clearly link impairments to functional educational impacts and required interventions.
- State measurable goals, frequency, and duration; justify group treatment and service changes.
- Track data trends and response to treatment to substantiate continued need or discharge.
Electronic systems and accuracy
Use electronic health records for clinic-based PHI or the district’s student system for education records. Leverage templates, audit trails, and standardized fields, but avoid copy-forward that introduces errors. Lock notes promptly and correct mistakes with dated addenda.
Records retention policy
Follow your district’s and state’s education-record retention schedules for IEPs and service logs. For HIPAA-covered settings, retain required HIPAA documentation for at least six years and keep medical records as state law and payer rules require. Maintain Medicaid claim support for the period your state specifies, often 5–7 years.
Security Safeguards for PHI
The HIPAA Security Rule requires administrative, technical, and physical safeguards for ePHI. Build controls that fit your workflow without impeding services.
Administrative safeguards
- Complete a documented security risk analysis and remediate identified gaps.
- Adopt policies for access, minimum necessary, incident response, and bring-your-own-device.
- Train the workforce routinely; track completion and reinforce expectations.
- Execute Business Associate Agreements with any vendor handling PHI.
Technical safeguards
- Encrypt devices and data in transit; require strong passwords and multi-factor authentication.
- Use unique user IDs, role-based access, and automatic logoff.
- Enable audit logs in your EHR and review alerts for suspicious activity.
Physical safeguards
- Secure paper files; position screens to prevent shoulder-surfing; lock rooms and cabinets.
- Use device inventory, remote wipe, and secure media disposal (shred or degauss).
Teletherapy compliance
Use a platform with strong encryption, access controls, and waiting-room features. Obtain parent consent, verify student identity, document location, and disable recording unless expressly authorized. Ensure privacy of the setting, manage backgrounds, and follow state licensure and Medicaid telehealth rules.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Medicaid Billing Compliance
Accurate claims require alignment among the IEP, service delivery, medical necessity documentation, and payer rules. Build checks before, during, and after billing.
Provider enrollment and authorizations
- Maintain active licensure, NPI, and enrollment as required by your state’s Medicaid program.
- Follow supervision rules for CFs and assistants, including co-signature when required.
- Verify any physician orders/referrals or prior authorizations your state mandates.
Service documentation for clean claims
- Capture exact dates, times, units, CPT/HCPCS codes, and modifiers (including telehealth when applicable).
- Document location, group size, and the student’s response to treatment.
- Ensure notes are signed and locked promptly; reconcile billed units to service logs.
Parental consent and FERPA coordination
Obtain and maintain parent consent for Medicaid billing as required. Clarify that services are provided at no cost to the family and that consent can be revoked. Share only information necessary for billing and protect education records under FERPA.
Internal audits and corrections
- Run periodic pre- and post-payment reviews; fix errors with corrected claims or refunds.
- Retain supporting documentation for audits, including attendance and progress data.
Parental Rights Regarding IEPs
Parents have robust rights to access, privacy, and participation under FERPA and IDEA. Your communication and documentation should make those rights easy to exercise.
Access and copies
Provide parents the opportunity to inspect and review education records within required timelines, and supply copies when review would otherwise be impracticable. Offer translations or explanations when needed for understanding.
Consent and disclosure
Obtain written parent consent before disclosing education records outside the school, unless a FERPA exception applies. Share only what is necessary for the stated purpose.
Amendments and disputes
Parents may request that inaccurate or misleading records be amended. If a request is denied, they are entitled to a hearing and to add a statement of disagreement to the record.
How HIPAA rights may also apply
When services are provided by a clinic or teletherapy vendor that is a HIPAA covered entity, parents generally act as the child’s personal representative for PHI access, subject to state minor-consent laws. Coordinate responses so families receive timely, consistent information.
Compliance Training and Policy Implementation
Effective programs translate rules into daily habits. Focus on clear roles, practical procedures, and routine monitoring.
Build a practical program
- Designate a privacy lead and, if applicable, a HIPAA security officer.
- Map data flows for IEPs, clinic PHI, billing, and teletherapy to identify handoffs.
- Complete a security risk analysis and prioritize remediation tasks.
- Adopt concise policies: access control, incident response, teletherapy compliance, and records retention policy.
- Standardize documentation templates to support medical necessity and audit readiness.
- Vet vendors; execute the correct agreement type (BAA for PHI, data privacy terms for FERPA records).
- Schedule periodic audits and tabletop exercises for breach response.
Quick-start checklist for SLPs
- Verify whether each record is governed by FERPA or HIPAA before sharing.
- Document sessions the same day; ensure signatures and accurate time/units.
- Use approved systems only; enable MFA; lock screens and secure paper.
- Double-check recipients before sending reports; de-identify when possible.
- Obtain and file consents for Medicaid billing and teletherapy.
- Report lost devices or misdirected emails immediately.
Conclusion
School SLPs operate at the intersection of education and healthcare. By distinguishing FERPA from HIPAA, maintaining strong documentation, implementing targeted safeguards, and aligning Medicaid billing with medical necessity, you protect students, support families, and keep your program audit-ready.
FAQs
What information is considered PHI under HIPAA for SLPs?
PHI includes any individually identifiable health information held by a HIPAA covered entity or its business associate, such as assessments, therapy notes, diagnoses, and billing details. In schools, records maintained as part of a student’s education file or individualized education program are typically FERPA education records, not PHI.
How does FERPA differ from HIPAA in schools?
FERPA governs student education records held by schools, including most SLP documentation created as part of the IEP process. HIPAA applies to PHI held by covered healthcare entities, such as a clinic providing services in a school or a teletherapy vendor for clinic-based care. The same information can be FERPA in the school’s file and PHI in the clinic’s file.
What are the documentation requirements for Medicaid billing?
Maintain medical necessity documentation aligned to the IEP and payer rules, including evaluations, plan of care, dates of service, start/stop times, units, codes/modifiers (including telehealth when used), student response, location, and timely signatures. Keep required authorizations and retain all claim support per state Medicaid rules.
How should SLPs secure teletherapy sessions?
Use an encrypted platform with access controls and waiting-room features, verify identity, obtain parent consent, and ensure a private setting. Disable recording unless authorized, follow state licensure and Medicaid telehealth requirements, and execute the correct vendor agreement (Business Associate Agreement for PHI or a FERPA-focused data privacy agreement for school records).
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.