Many postsecondary institutions operate in dual roles as both educational entities and healthcare providers, making the interaction between FERPA and the Health Insurance Portability and Accountability Act (HIPAA) a persistent compliance challenge. This webinar clarifies which law governs which records and what institutions must do when the two statutes converge.
Key topics include:
- Why HIPAA’s Privacy Rule excludes records protected by FERPA, establishing FERPA as the primary framework for most student health records
- When HIPAA fully applies, including records for non-student patients and independently operating university hospitals
- The hybrid entity designation and the operational separation it requires
- Conflicting disclosure standards: FERPA’s “legitimate educational interest” versus HIPAA’s “minimum necessary” standard
- Diverging emergency disclosure thresholds and the risks they pose in safety situations
- How treatment records instantly convert to FERPA-governed education records upon disclosure outside the direct treatment team
- The ambiguous status of student-employees and their health records
- Recommendations for comprehensive legal audits, unified governance frameworks, and staff training tailored to real-world privacy decisions
Recommended Publications:


share