HHS OCR HIPAA FAQ 513
Does the HIPAA Privacy Rule apply to an elementary or secondary school?
Length: 487 wordsOfficial source
Generally, no. In most cases, the
HIPAA
Privacy Rule does not apply to an elementary or secondary school because the school either: (1) is not a
HIPAA
covered entity or (2) is a
HIPAA
covered entity but maintains health information only on students in records that are by definition “education records” under
FERPA
and, therefore, is not subject to the
HIPAA
Privacy Rule.
The school is not a HIPAA covered entity.
The
HIPAA
Privacy Rule only applies to health plans, health care clearinghouses, and those health care providers that transmit health information electronically in connection with certain administrative and financial transactions (“covered transactions”). See 45
CFR
§ 160.102. Covered transactions are those for which the U.S. Department of Health and Human Services has adopted a standard, such as health care claims submitted to a health plan. See the definition of “transaction” at 45
CFR
§ 160.103 and 45
CFR
Part 162, Subparts K–R. Thus, even though a school employs school nurses, physicians, psychologists, or other health care providers, the school is not generally a
HIPAA
covered entity because the providers do not engage in any of the covered transactions, such as billing a health plan electronically for their services. It is expected that most elementary and secondary schools fall into this category.
The school is a HIPAA covered entity but does not have “protected health information.”
Where a school does employ a health care provider that conducts one or more covered transactions electronically, such as electronically transmitting health care claims to a health plan for payment, the school is a
HIPAA
covered entity and must comply with the
HIPAA
Transactions and Code Sets and Identifier Rules with respect to such transactions. However, even in this case, many schools would not be required to comply with the
HIPAA
Privacy Rule because the school maintains health information only in student health records that are “education records” under
FERPA
and, thus, not “protected health information” under
HIPAA
. Because student health information in education records is protected by
FERPA
, the
HIPAA
Privacy Rule excludes such information from its coverage. See the exception at paragraph (2)(i) to the definition of “protected health information” in the
HIPAA
Privacy Rule at 45
CFR
§ 160.103. For example, if a public high school employs a health care provider that bills Medicaid electronically for services provided to a student under the
IDEA
, the school is a
HIPAA
covered entity and would be subject to the
HIPAA
requirements concerning transactions. However, if the school’s provider maintains health information only in what are education records under
FERPA
, the school is not required to comply with the
HIPAA
Privacy Rule. Rather, the school would have to comply with
FERPA’s
privacy requirements with respect to its education records, including the requirement to obtain parental consent (34
CFR
§ 99.30) in order to disclose to Medicaid billing information about a service provided to a student.
Created 11/25/08