FERPA governs educational records and applies to educational institutions, while HIPAA focuses on healthcare-related information and applies to covered healthcare entities. The intersection occurs when healthcare services are provided within educational institutions, leading to a nuanced interplay of these laws in specific scenarios involving student health information.
FERPA, the Family Educational Rights and Privacy Act, is a federal law that aims to protect students' educational privacy while ensuring educational institutions can appropriately manage and share information for legitimate educational purposes.
FERPA establishes guidelines for educational institutions to obtain written consent before sharing students' personally identifiable information with third parties, except in specific situations outlined in the law. It also allows for the designation of "directory information" that can be disclosed without consent.
See also: Legislation that applies to minor patient data
FERPA applies to students' educational records regardless of the student's age. However, the rights under FERPA transfer from the parents to the student once the student turns 18 or attends a post-secondary institution, regardless of age.
Here's a breakdown:
FERPA: If the educational records, including health records, are maintained by the educational institution, FERPA applies. An adult student's records are generally protected by FERPA, and the educational institution would need written consent from the student to share their records, including health information, with their parent.
HIPAA: If the educational institution provides healthcare services and maintains protected health information (PHI), HIPAA may apply to healthcare-related activities. HIPAA's rules for sharing PHI with parents would come into play in this case.
HIPAA: Generally, if an adult student doesn't give consent to disclose their PHI, healthcare providers covered by HIPAA cannot share their mental health information with family members without permission. HIPAA is stringent about protecting individuals' health information, even if it concerns their well-being.
HIPAA: HIPAA allows healthcare providers to disclose PHI about a minor with a mental health condition or substance use disorder to their parents or guardians, especially if the provider believes the disclosure is in the best interest of the minor's health and well-being.
FERPA: Educational institutions are permitted to share information with appropriate parties, including parents and law enforcement, when there's a legitimate threat to the safety and well-being of the student or others under the "health and safety emergency" exception in FERPA.
HIPAA: HIPAA allows for the disclosure of PHI in situations where there's a serious threat to health or safety. Healthcare providers can share information with individuals who are in a position to prevent or lessen the threat.
FERPA: Under specific conditions, FERPA allows educational institutions to disclose PII from education records, including health records, to law enforcement officials without prior consent. This applies when there's a legitimate law enforcement interest, and the information is necessary to address a situation.
FERPA: FERPA permits the disclosure of PII from education records to NICS in cases where the disclosure is mandated by state law, and the institution is legally obligated to report information to NICS. This is generally related to firearm background checks.
See also: How does HIPAA apply to minor patients?
See also: HIPAA Compliant Email: The Definitive Guide