{"id":28,"date":"2026-03-25T11:10:56","date_gmt":"2026-03-25T11:10:56","guid":{"rendered":"https:\/\/vendor.hub.wp.nau.edu\/hipaa\/hipaa-federal-regulations\/"},"modified":"2026-05-12T17:49:15","modified_gmt":"2026-05-12T17:49:15","slug":"hipaa-ferpa","status":"publish","type":"page","link":"https:\/\/in.nau.edu\/hipaa\/hipaa-ferpa\/","title":{"rendered":"HIPAA and FERPA"},"content":{"rendered":"<p style=\"text-align: left\"><!-- shortcode-right-column -->\n<div class=\"shortcode-right-column\" >\n    <div class=\"shortcode-right-column__container\"><\/p>\n<p style=\"text-align: left\"><!-- shortcode-contact -->\n<div class=\"shortcode-contact\">\n    <div class=\"contact-header\">\n        <h3>Contact the HIPAA Privacy Program<\/h3>\n    <\/div>\n    <div class=\"contact-body\">\n                <a href=\"mailto:hipaa@nau.edu\" aria-label=\"Contact the HIPAA Privacy Program: Email Address\" title=\"Email Address\">\n            <div class=\"contact-icon-container\">\n                <i class=\"fas fa-envelope\" aria-hidden=\"true\"><\/i>\n                <span class=\"sr-only\">Email:<\/span>\n            <\/div>\n            <div class=\"contact-email\">hipaa&#8203;@nau.edu<\/div>\n        <\/a>\n                        <a href=\"tel:928-523-7906\" aria-label=\"Contact the HIPAA Privacy Program: Telephone Number\" title=\"Telephone Number\">\n            <div class=\"contact-icon-container\">\n                <i class=\"fas fa-phone\" aria-hidden=\"true\"><\/i>\n                <span class=\"sr-only\">Call:<\/span>\n            <\/div>\n            <div class=\"contact-phone\">928-523-7906<\/div>\n        <\/a>\n            <\/div>\n<\/div>\n\n<\/span><\/p>\n<p><span style=\"font-size: 16px\"><\/div>\n<\/div>\n<\/span><\/p>\n<h1>HIPAA &amp; FERPA<\/h1>\n<p>The U.S. Department of Education and the Office for Civil Rights at the U.S. Department of Health and Human Services <a href=\"https:\/\/studentprivacy.ed.gov\/sites\/default\/files\/resource_document\/file\/2019%20HIPAA%20FERPA%20Joint%20Guidance%20508.pdf\">published<\/a> joint guidance addressing the application of the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to health records maintained on students.<\/p>\n<p>For colleges and universities, FERPA<strong>\u2014not HIPAA\u2014<\/strong>governs most student health records.<\/p>\n<p>This is because health and counseling records maintained by a postsecondary institution for its own students are considered education records or treatment records under FERPA. The HIPAA Privacy Rule explicitly excludes education records from its definition of PHI.<\/p>\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"When FERPA applies_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>When FERPA applies <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<h4><strong>Campus Health Services (CHS) or Counseling&nbsp;<\/strong><\/h4>\n<ul>\n<li>Records on students are FERPA education or treatment records.<\/li>\n<li>HIPAA does not apply to those student records.<\/li>\n<li>FERPA controls access, disclosure, and parental involvement.<\/li>\n<\/ul>\n<h4><strong>Treatment records vs. Education records<\/strong><\/h4>\n<ul>\n<li><strong>Treatment records<\/strong>: Records made or maintained by a physician, psychiatrist, psychologist, counselor or other recognized professional for the purpose of providing treatment, used only by treating providers, and disclosed only to those providers (or the student&rsquo;s chosen physician for review).\n<ul>\n<li>Treatment records are excluded from the general definition of education records, so they are not subject to routine FERPA disclosures that education records might be (e.g., to school officials with &ldquo;legitimate educational interest&rdquo;). This limits who can see sensitive clinical notes.<\/li>\n<\/ul>\n<\/li>\n<li>If used or disclosed for any other purpose (such as billing insurance), they <em>become<\/em> education records and are subject to FERPA&rsquo;s consent rules.<\/li>\n<\/ul>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"When HIPAA applies at NAU_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>When HIPAA applies at NAU <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<h4><strong>Non&#8209;student patients<\/strong><\/h4>\n<p>NAU&rsquo;s HIPAA&#8209;covered entities are called <a href=\"https:\/\/in.nau.edu\/hipaa\/covered-entities-at-nau\/\">Health Care Components<\/a> (HCCs) and provide care to non&#8209;students:<\/p>\n<ul>\n<li>Non-students can be university staff or family members and the public, obtaining treatment at the university.<\/li>\n<li>These non-student health records created or maintained at a covered entity is PHI under HIPAA.<\/li>\n<\/ul>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Students who are also employees_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Students who are also employees <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>If a student works for the university and receives health care from the institution:<\/p>\n<ul>\n<li>They remain FERPA education or treatment records, not HIPAA PHI.<\/li>\n<li>Such records would be covered as education records by FERPA and thus would not be covered by the HIPAA Rules<\/li>\n<\/ul>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<div class=\"mceTemp\"><\/div>\n<h2 style=\"text-align: center\">Sharing Information<\/h2>\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Under FERPA_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Under FERPA <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Student treatment records may be shared with other treating professionals or when appropriate, school officials, to coordinate the student&rsquo;s care. When the university receives external health records, they become FERPA records. Please see the NAU&rsquo;s <a href=\"https:\/\/in.nau.edu\/ferpa\">FERPA<\/a> webpage for more guidance.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Under HIPAA_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Under HIPAA <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Staff and providers may disclose PHI for treatment, payment or operational purposes without a seperate authorization, when a Notice of Privacy Practices has been given to the patient. Often a valid HIPAA authorization is necessary to share PHI unless a permitted exception exists.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"size-landscape-image wp-image-296 aligncenter\" src=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/52\/2026\/03\/6448_Letters_20260219-medium-464x348.jpg\" alt=\"\" width=\"464\" height=\"348\" srcset=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/52\/2026\/03\/6448_Letters_20260219-medium-464x348.jpg 464w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/52\/2026\/03\/6448_Letters_20260219-medium-800x600.jpg 800w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/52\/2026\/03\/6448_Letters_20260219-medium-232x174.jpg 232w\" sizes=\"auto, (max-width: 464px) 100vw, 464px\" \/><\/h2>\n<h2 style=\"font-weight: 400\"><strong>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0<\/strong><\/h2>\n<h2 style=\"font-weight: 400;text-align: center\"><strong>FAQs<\/strong><\/h2>\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Q: What is the difference between education records and treatment records?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Q: What is the difference between education records and treatment records? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>A:&nbsp;Education records&nbsp;are records&nbsp;<em>directly related to a student and maintained by the university.<\/em>&nbsp;Treatment records&nbsp;are records on an&nbsp;<a href=\"https:\/\/studentprivacy.ed.gov\/content\/eligible-student\"><em>eligible student<\/em><\/a>&nbsp; made or maintained by a clinician and used only for treatment, and are excluded from FERPA&rsquo;s definition of education records while they remain limited to treatment use.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Q: Who can see treatment records?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Q: Who can see treatment records? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>A: Only the treating providers may access treatment records; an <a href=\"https:\/\/studentprivacy.ed.gov\/content\/eligible-student\">eligible student<\/a> may have those records reviewed by a physician or other appropriate professional of their choice. If records are disclosed beyond treating providers for other purposes, they become FERPA education records.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Q: Does HIPAA apply to Campus Health Services or Counseling records?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Q: Does HIPAA apply to Campus Health Services or Counseling records? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p style=\"font-weight: 400\">A: Usually no. FERPA applies to student health records maintained by a university&rsquo;s covered entity and are governed by FERPA (or the school&rsquo;s policies) rather than HIPAA; both treatment and education records at schools are generally excluded from HIPAA.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Q: When can treatment or education records be disclosed without student consent?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Q: When can treatment or education records be disclosed without student consent? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p style=\"font-weight: 400\">A:&nbsp;FERPA allows limited exceptions (e.g.,&nbsp;health\/safety emergencies, lawfully issued subpoenas, transfers to other schools, or disclosures to school officials with legitimate educational interest).<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Q. What is I have more questions related to FERPA privacy?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Q. What is I have more questions related to FERPA privacy? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>The U.S. Department of Education administers and enforce student privacy laws such as the Family Educational Rights and Privacy Act (FERPA). Please visit NAU&rsquo;s <a href=\"https:\/\/in.nau.edu\/ferpa\/\">FERPA<\/a> page for specific sharing and consent procedures.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>HIPAA &amp; FERPA The U.S. Department of Education and the Office for Civil Rights at the U.S. Department of Health and Human Services published joint guidance addressing the application of the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to health records maintained on students. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":316,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","ring_central_script_selection":"","footnotes":""},"class_list":["post-28","page","type-page","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/pages\/28","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/comments?post=28"}],"version-history":[{"count":26,"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/pages\/28\/revisions"}],"predecessor-version":[{"id":387,"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/pages\/28\/revisions\/387"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/media\/316"}],"wp:attachment":[{"href":"https:\/\/in.nau.edu\/hipaa\/wp-json\/wp\/v2\/media?parent=28"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}