Indiana Campus Student Health Privacy Law Checklist: FERPA, HIPAA, and Indiana State Compliance

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Indiana Campus Student Health Privacy Law Checklist: FERPA, HIPAA, and Indiana State Compliance

Kevin Henry

Data Privacy

August 31, 2026

8 minutes read
Share this article
Indiana Campus Student Health Privacy Law Checklist: FERPA, HIPAA, and Indiana State Compliance

Overview of FERPA Requirements

The Family Educational Rights and Privacy Act (FERPA) protects students’ personally identifiable information in educational records. On campus, many student health and counseling records are “educational records” or FERPA “treatment records,” not subject to HIPAA, yet still confidential under FERPA.

Key concepts include educational records, Personally Identifiable Information (PII), annual rights notices, written consent for most disclosures, directory information with opt-out, and the health or safety emergency exception. Postsecondary “treatment records” maintained by a licensed professional have special access rules but remain protected by FERPA.

Campus FERPA checklist

  • Define what your institution treats as educational records, treatment records, and directory information, and document the rationale.
  • Publish the annual FERPA notice; offer clear, simple directory information opt-out instructions.
  • Standardize written consent forms, including scope, duration, and revocation; log all disclosures.
  • Set timelines and procedures for student access and amendment requests; train front-line staff on identity verification.
  • Limit access to those with legitimate educational interests; implement role-based controls and audit trails.
  • Coordinate FERPA practices with counseling, disability services, athletics, and residence life to avoid inconsistent handling.

HIPAA Applicability to Student Health

The Health Insurance Portability and Accountability Act (HIPAA) protects Protected Health Information (PHI) held by covered entities and their business associates. HIPAA excludes FERPA “education records” and “treatment records,” so most student health records stored by a school are not PHI.

HIPAA may still apply on campus when a university hospital or clinic provides services to non-students, bills insurers electronically, or operates as a designated health care component of a hybrid entity. Employee health records in an occupational clinic can also be HIPAA-covered.

When HIPAA applies—and when it does not

  • Applies: university medical center serving the public; campus clinic treating non-students; covered telehealth services; business associate relationships handling PHI.
  • Does not apply: student health or counseling records that are FERPA education or treatment records maintained by the school.

HIPAA compliance checklist for campus providers

Indiana State Privacy Regulations

Indiana Code Title 16 contains patient health record confidentiality and access provisions that campus health and counseling services should incorporate. It intersects with communicable disease reporting, immunization registry participation, and mental health record protections.

Schools must align FERPA and HIPAA frameworks with state obligations such as provider confidentiality rules, permitted disclosures for public health, and special handling for mental health and immunization data. This overview is educational and not legal advice.

Indiana-specific focus areas

  • Confidentiality and patient access to records under Indiana Code Title 16, including mental health documentation.
  • Immunization reporting and registry participation for student compliance and public health objectives.
  • Communicable disease reporting to public health authorities consistent with state requirements.
  • Parental/guardian involvement for minors, balanced with minor-consent rules and campus policy.
  • Alignment with state breach-notification duties and retention schedules set by institutional policy and applicable law.

Indiana compliance checklist

  • Map applicable Indiana Code Title 16 provisions to campus workflows; create a FERPA–HIPAA–state law crosswalk.
  • Standardize state-compliant consent and release forms, including mental health disclosures.
  • Document public health reporting triggers and designate responsible roles for timely submissions.
  • Validate immunization data flows between providers, CHIRP or similar registries, and school systems.
  • Review retention and disposal practices for paper and electronic records; verify secure destruction methods.

Roles and Responsibilities of Educational Institutions

Clear ownership enables consistent privacy compliance. Name an Institutional Compliance Officer to coordinate FERPA, HIPAA, and Indiana Code Title 16 requirements across health, counseling, academic, and administrative units.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Core roles

  • Institutional Compliance Officer: program oversight, policy governance, and issue escalation.
  • Registrar/FERPA Officer: educational record stewardship and disclosure logging.
  • HIPAA Privacy Officer and Security Officer: PHI governance, risk management, and incident response.
  • Directors of Student Health, Counseling, and Disability Services: operational controls and staff training.
  • IT Security and Privacy: access controls, encryption, monitoring, and vendor risk management.
  • General Counsel and IRB: complex disclosures, research use, and data-sharing agreements.

Operational responsibilities

  • Maintain data inventories distinguishing PII, PHI, and educational records; document lawful bases for use and disclosure.
  • Run a unified request center for access, amendments, subpoenas, and health/safety exceptions.
  • Vet vendors for FERPA “school official” status or HIPAA business associate status before onboarding.
  • Perform periodic audits; report findings to leadership with corrective action plans and timelines.

Compliance Strategies and Best Practices

Effective programs blend legal requirements with practical controls. Focus on data minimization, role-based access, auditability, and continuous training to reduce risk while supporting student care.

Foundational controls

  • Encrypt data at rest and in transit; require multifactor authentication for EHR and portals.
  • Segment systems that process PHI from broader campus networks; restrict administrator privileges.
  • Standardize secure messaging and telehealth platforms; prohibit unapproved apps for clinical communication.

Operational practices

  • Adopt consent and disclosure templates that meet FERPA and HIPAA standards; log all releases.
  • Use privacy-by-design in new clinics, apps, and research projects; complete privacy impact assessments.
  • Implement identity verification scripts for phone, portal, and in-person interactions.

Documentation and training

  • Publish clear, role-specific procedures; run tabletop exercises for incidents and subpoenas.
  • Track completion of annual FERPA and HIPAA training; test comprehension with scenario-based modules.
  • Maintain an evidence trail: policies, risk analyses, access logs, breach drills, and remediation records.

Distinctions Between FERPA and HIPAA

FERPA governs educational records and PII; HIPAA governs PHI held by covered entities and business associates. On campuses, most student health records fall under FERPA, while HIPAA governs designated clinical components serving non-students or operating as covered entities.

Quick comparison checklist

  • Scope: FERPA covers educational records/PII; HIPAA covers PHI.
  • Default rule: FERPA requires consent for most disclosures; HIPAA permits many TPO disclosures without authorization.
  • Access rights: each law sets timelines and processes; adopt procedures that meet the stricter applicable standard.
  • Emergency disclosures: both allow limited sharing to address imminent health/safety threats; document the rationale.
  • Vendors: FERPA “school officials” with legitimate interests vs. HIPAA business associates with BAAs.
  • Governance: Department of Education (FERPA) vs. HHS Office for Civil Rights (HIPAA).

Edge cases to resolve early

  • Clinics serving both students and the public; designate boundaries and record systems to avoid commingling.
  • Student workers with access to records; train and limit access to job duties.
  • Research and quality improvement; separate de-identified datasets from individually identifiable records.

Enforcement and Penalties for Non-Compliance

Consequences vary by law and forum. FERPA compliance is overseen by the Department of Education; HIPAA enforcement is led by HHS OCR; Indiana may impose additional obligations and remedies under state law.

FERPA enforcement

  • Complaint-driven investigations; negotiated remedies and compliance commitments.
  • Risk of federal funding actions for persistent non-compliance.
  • Institutional exposure to contract disputes or state-law claims tied to privacy failures.

HIPAA enforcement

  • OCR investigations can result in corrective action plans, monitoring, and civil penalties.
  • Criminal enforcement is possible for certain wrongful disclosures or misuse of PHI.
  • Business associates share liability; weak vendor controls amplify risk.

Indiana enforcement levers

  • State confidentiality and reporting requirements under Indiana Code Title 16.
  • Attorney General actions and potential civil penalties under applicable state laws.
  • Professional licensing boards and contractual remedies with service providers.

Incident response essentials

  • Activate a cross-functional team; preserve logs and evidence; assess legal triggers under FERPA, HIPAA, and state law.
  • Notify affected individuals and authorities as required; provide mitigation and identity protection where appropriate.
  • Conduct root-cause analysis; implement and document corrective actions and retraining.

Conclusion

This Indiana Campus Student Health Privacy Law Checklist helps you align FERPA protections, HIPAA obligations, and Indiana Code Title 16 requirements. Map your records, define roles, tighten controls, and train continuously to reduce risk while supporting student care and safety.

FAQs.

What types of student health information does FERPA protect?

FERPA protects PII contained in educational records, which may include immunization records, disability services files, care plans, and counseling documentation when maintained by the school. Postsecondary “treatment records” kept by a health professional are not education records but remain confidential under FERPA with special access and disclosure rules.

How does HIPAA apply to campus health services?

HIPAA applies to covered clinical components that handle PHI, such as a university hospital or clinic treating non-students and transmitting standard electronic transactions. Most student health and counseling records maintained by the institution are FERPA-covered and excluded from HIPAA’s PHI definition.

What specific privacy requirements does Indiana law impose on schools?

Indiana Code Title 16 establishes confidentiality and access standards for patient and mental health records, supports immunization registry participation, and requires certain communicable disease reporting. Schools should integrate these duties with FERPA and HIPAA processes, including consent, access, retention, and reporting workflows.

How should institutions coordinate FERPA and HIPAA compliance?

Designate a hybrid entity structure if needed, assign an Institutional Compliance Officer, and maintain a FERPA–HIPAA–Indiana law crosswalk. Standardize consent and disclosure forms, train staff on role-based access and emergency exceptions, and implement unified intake, access, and incident response procedures across health, counseling, and administrative units.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles