Difference Between HIPAA and FERPA: A Complete Guide

11 min read
HIPAA and FERPA folders side by side, showing healthcare and education records privacy with padlocks and icons.
Jump to section

Picture a school office with two locked filing cabinets side by side. One holds health forms the nurse guards closely, the other holds report cards and attendance sheets the front office keeps on hand.

Different keys, different rules, different consequences if the wrong person gets inside.

HIPAA and FERPA work the same way. HIPAA (Health Insurance Portability and Accountability Act) protects medical information, while FERPA (Family Educational Rights and Privacy Act) protects student education records.

Mixing them up can turn a routine attendance note into a real compliance headache, so here's how the two laws differ, where they overlap, and what that means for your classroom records.

Two locked filing cabinets, one for HIPAA and one for FERPA, show that different keys protect different student records.

The Difference Between HIPAA and FERPA

Both laws exist to guard privacy, but they were built for two very different rooms: one for the classroom, one for the doctor's office.

What FERPA is and who it protects

FERPA, the Family Educational Rights and Privacy Act, is the federal student privacy law that governs educational records like report cards, disciplinary files, and enrollment data.

According to the CDC's Public Health Law program, FERPA was enacted in 1974 to protect the privacy of student education records. It gives parents, and students themselves once they turn 18, the right to review and control who sees those records.

For a high school counselor, that means a parent's request to see a transcript isn't optional: it's the law.

Counselor hands student records to a parent under a shield labeled FERPA 1974, symbolizing legal protection of the documents.

What HIPAA is and who it protects

HIPAA, the Health Insurance Portability and Accountability Act, is the federal health privacy law that protects PHI (protected health information), the medical details tied to an identifiable person.

HIPAA was enacted in 1996 under President Bill Clinton, and it's administered and enforced by the U.S. Department of Health and Human Services Office for Civil Rights.

What are the 5 HIPAA rules? According to HHS, HIPAA breaks down into five parts:

  • Privacy Rule: sets limits on who can see and share health information.
  • Security Rule: covers how that information has to be protected electronically.
  • Breach Notification Rule: spells out what happens if that protection fails.
  • Enforcement Rule: lays out how violations get investigated and penalized.
  • Patient Safety Rule: protects data shared for safety and quality improvement work.

Shield icon with medical cross and padlock, surrounded by five badges representing HIPAA rules like Privacy and Security.

Which Organizations Each Law Covers

Both laws protect student information, but they don't cover the same organizations. FERPA follows the funding, while HIPAA follows the type of care being delivered.

Schools Covered by FERPA

FERPA applies to any school or education agency that receives federal funding, which in practice means:

  • Public elementary and secondary schools. Nearly every public school district falls under FERPA because of the federal dollars flowing through it.
  • Post-secondary institutions. Colleges and universities that accept federal financial aid or other federal funds are covered too, including private colleges that take federal aid.
  • State and local education agencies. Departments of education and districts that manage student records are bound by the same rules.

Private schools are often exempt, since many K-12 private schools don't receive federal funding directly. That said, if a private school does accept federal money, FERPA applies just like it would at a public school.

One wrinkle worth knowing: FERPA's directory information exception lets schools share basic details, like a student's name or grade level, without consent, unless a parent has opted out.

Infographic showing FERPA applies to entities receiving federal funding, with exceptions for private schools and directory information.

Healthcare Providers Covered by HIPAA

HIPAA covers a different set of players entirely:

  • health plans and providers
  • healthcare clearinghouses
  • business associates (vendors or contractors handling health data on a provider's behalf)

The common thread is electronic transmission: HIPAA applies to entities that transmit health information electronically for billing, claims, or other standard transactions, which is why a school nurse's office isn't automatically covered the way a pediatrician's practice is.

What Information Each Law Protects

FERPA and HIPAA each guard a different slice of a student's life, and knowing where that line falls is the first step toward real compliance.

What Counts as a FERPA Record

FERPA (the Family Educational Rights and Privacy Act) covers education records: the files a school keeps and maintains about a student. That includes:

  • report cards
  • disciplinary notes
  • notably, student health records kept by the school, like a nurse's visit log or an immunization form filed in the office

Anything that counts as personally identifiable information (PII), a name, a student ID, a birthdate tied to a record, falls under this umbrella too.

Here's one teachers often miss: attendance logs count as FERPA records. A simple sign-in sheet or daily roster is still protected once it's tied to a student's name.

What FERPA doesn't protect is just as important. Directory information (like a student's name in a yearbook), a teacher's personal observation never written down, or records created by a law enforcement unit on campus generally fall outside FERPA's reach.

For example, a teacher jotting a private note to remember a seating preference isn't creating a FERPA record unless it's filed and maintained by the school.

Glowing shield icons on protected student folders contrast with dim, unprotected private documents on a teacher's desk.

What Counts as Protected Health Info

HIPAA (the Health Insurance Portability and Accountability Act) protects individually identifiable health info: things like:

  • diagnoses
  • treatment notes
  • medical records held by a covered healthcare provider or insurer

It also covers identifiers like Social Security numbers and home addresses when they're linked to that health data. Unlike FERPA, HIPAA rarely applies inside a typical classroom at all.

Keeping Attendance Records Compliant

Attendance rolls count as education records under FERPA, so how you log, store, and share them matters as much as what you teach.

Use this guide to set up your system once, handle health-related absences without crossing a line, and keep everything audit-ready year over year.


Set up the daily log

Before the first bell of the year, confirm three things about your attendance system:

  • Rolls live in a secure system. No paper rosters in open trays, no shared spreadsheets without login control.
  • Access matches role. You see your own classes; office staff see schoolwide; volunteers see nothing.
  • Codes record the absence, never the condition. The log says a student was out, not why.

That last one is where most well-meaning teachers slip, usually in a comments field:

✅ Oct 12: EX-A (excused absence) ❌ Oct 12: absent, strep throat

The difference: the second entry turns an attendance roll into a health record that everyone with roster access can read.


Health information still flows into school, so the job is routing it, not recording it. Send each piece where it belongs:

When you receive... It goes...
A parent call saying "out sick" An absence code in the roll
A doctor's note The office file, never the log
Details from a nurse visit The nurse's own records

Keeping nurse information in a separate channel means a roster lookup never exposes a medical detail.

⚠️ Watch out: Don't share a doctor's note with other staff without permission. Before you do, get it in writing. Try: "Could you give us written permission to share this note with the front office?"


Keep it compliant over time

Daily habits handle the term; these three checks handle the years. Confirm each one annually:

  • Retention follows your state's timeline. Look up the required period before purging or keeping anything.
  • Cumulative files are archived securely. Locked physical storage or an encrypted digital archive, nothing in between.
  • Access logs get a yearly audit. Review who viewed what, and remove accounts that no longer need access.

At a glance:

Phase Key move What you get
Daily log Codes, role-based access A roll with no health data in it
Health absences Route notes and nurse info separately Medical details stay out of reach
Yearly upkeep Retention, archiving, access audit Records that survive an inspection

A secure tool makes most of this automatic: EMStudio's attendance tracker keeps daily records secure, organized, and audit-ready.

Who actually gets to approve a record leaving the building looks different depending on which law you're under. Both FERPA and HIPAA lean on consent, but they hand that power to different people.

As a rule, written consent is required before a record goes anywhere outside the people who already have a legitimate reason to see it. Who signs that consent, though, depends on the law:

  • Under FERPA, parents control a student's education records, and that control doesn't stay with them forever. According to Protecting Student Privacy, "When a student turns 18 years old, or enters a postsecondary institution at any age, the rights under FERPA transfer from the parents to the student ("eligible student")." A high school senior who turns 18 in the fall now holds those rights, not mom or dad.
  • Under HIPAA, the patient (or their legal guardian for a minor) controls their health records, and that consent is needed before a provider discloses anything.

Either way, the default is the same: ask first.

Infographic comparing FERPA and HIPAA consent rules, showing how student control transfers at 18 or college entry, while patient control remains fixed.

Consent isn't absolute. A few practical exceptions exist on both sides:

  • Emergency or safety threats. If a student's or patient's health or safety is at immediate risk, records can be shared without waiting on a signature.
  • Treatment purposes. HIPAA allows sharing between providers actively treating the same patient, no extra consent required.
  • De-identified information. Strip the identifying details, and what's left generally falls outside both laws' consent rules entirely.

How FERPA and HIPAA Overlap

A school nurse's office sits right at the crossroads of these two laws, and that's exactly where confusion creeps in. The short version: for any given health record, usually only one law applies, not both at once.

Does HIPAA Override FERPA?

No. HIPAA doesn't override FERPA once a student walks onto school grounds.

Student health records kept by a school (immunization logs, a nurse's visit notes, a 504 plan's medical details) are generally excluded from HIPAA's coverage, because FERPA already treats them as part of the student's education record.

In a lot of ways, FERPA is the closest thing schools have to a medical version of itself: it's the law doing the job HIPAA does everywhere else.

Where a clinic sits matters too. Consider a nurse's office that the district runs and staffs: that falls under FERPA.

Now consider a hospital-operated clinic housed in the same building, serving the broader community as well as students: that one follows HIPAA, because the hospital, not the school, controls the records.

A diagram showing a school split into a nurse's office under FERPA rules and a clinic under HIPAA rules.

Sharing Info Between Schools and Providers

HIPAA actually makes provider-to-school sharing fairly easy for treatment purposes. A pediatrician can send relevant health information to a school nurse without much friction, since treatment coordination is one of HIPAA's built-in exceptions.

The reverse is tighter. FERPA restricts a school nurse from freely sharing a student's records with an outside physician. Written parental consent is often still required before that information moves off campus, even when the goal is better care.

Staying Compliant and Avoiding Violations

Knowing the difference between FERPA and HIPAA only matters if your school actually follows both. So what happens when a record gets mishandled, and what does it take to keep that from happening in your building?

What Happens If You Violate These Laws

The consequences aren't abstract. According to ed.gov, a school's failure to comply with FERPA can result in the loss of federal funding, since violating the law can mean termination of an educational entity's federal funding entirely.

HIPAA violations carry their own fines and penalties, scaled to how serious and how repeated the breach is.

Beyond the financial hit, there's reputational damage: once families hear a health form or report card leaked, trust is hard to rebuild.

Think of a counselor who emails a student's disciplinary file to the wrong parent, or a front-office aide who leaves immunization records visible on a shared printer. Small slips, real consequences.

Surprised aide and concerned parent discover exposed student records on a printer, symbolizing lost funding and broken trust.

How to Stay Compliant and Secure

Staying compliant isn't complicated, but it does take consistency:

  • Secure digital and paper records: locked cabinets, password-protected files, restricted access.
  • Use FERPA/HIPAA compliant software, especially for attendance data and health logs.
  • Train employees regularly, not just once at onboarding.
  • Run yearly compliance audits to catch gaps before they become violations.
  • Consult an attorney when a situation doesn't fit neatly into either law.

The right tool for the job, paired with people who know the rules, keeps records safe and your school out of trouble.

HIPAA and FERPA protect different records for different reasons, but it's an easy line to blur in a busy classroom. Knowing which law covers what lets you handle attendance, health notes, and student files with confidence instead of guesswork.

Once those lines are clear, staying compliant becomes part of your routine, not a scramble.

Ready to keep your attendance records organized and compliant? Check out our post, Attendance & Records, to mark attendance quickly and spot patterns across your classes over time.

A teacher reviews student records in a secure office with locked files and FERPA symbols, symbolizing compliant data management.

Frequently asked questions

What are the 5 HIPAA rules?

The five HIPAA rules are the Privacy Rule, Security Rule, Breach Notification Rule, Enforcement Rule, and Patient Safety Rule. Together, they govern the use, protection, disclosure, and enforcement of requirements involving protected health information.

Does HIPAA override FERPA?

No. HIPAA does not override FERPA. Health records maintained by a school are generally education records covered by FERPA, while records held by a HIPAA-covered healthcare provider generally fall under HIPAA.

What does FERPA not protect?

FERPA generally does not protect directory information, a teacher’s personal observation that was never recorded or maintained as a school record, or records created and maintained by a law-enforcement unit for law-enforcement purposes. Schools may also disclose directory information without consent unless a parent or eligible student has opted out.

Is there a medical version of FERPA?

There is no separate federal “medical FERPA,” but FERPA serves a similar privacy role for health records maintained by schools. A school nurse’s records are generally education records under FERPA, while records maintained by an outside hospital or HIPAA-covered clinic are generally governed by HIPAA.

EMStudio

Ready to transform your teaching?

Join thousands of educators who are already saving time and improving student outcomes with EMStudio.

Get Started for Free
EMStudio dashboard preview
Milo

Article by Milo

Founder · Teacher

Milo spent years teaching ESL in South Korea, including time as a curriculum coordinator planning hundreds of lessons a year across twelve academies and dozens of teachers. He built EMStudio after hitting the limits of every planning tool he tried.