17.2 HIPAA, FERPA & Privacy
Key Takeaways
- HIPAA covered entities are health plans, health care clearinghouses, and providers who transmit standard electronic transactions. PHI may be used or disclosed for treatment, payment, and health care operations (TPO) without an authorization; uses beyond TPO generally need a valid authorization (45 CFR 164.508).
- Minimum necessary (45 CFR 164.502(b), 164.514(d)) limits payment, operations, and most requests. It does not apply to treatment disclosures between providers, to the individual, or pursuant to a valid authorization.
- Secondary-school AT records maintained by the school are usually FERPA education records. The HIPAA Privacy Rule excludes FERPA education records and FERPA treatment records of eligible postsecondary students from PHI. Hospital and clinic ATs are typically HIPAA. Follow the stricter applicable rule plus state law.
- Directory information may include name, sport participation, and height/weight—not diagnoses. Parents hold FERPA rights for unemancipated minors; those rights transfer to an eligible student (age 18 or attending postsecondary school).
- HIPAA breach notification to affected individuals is without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.404). A health-or-safety emergency (FERPA 34 CFR 99.36) or HIPAA’s serious-threat permission can override silence when harm is imminent—it does not authorize an Instagram injury photo or a reporter’s ACL scoop.
Quick Answer: HIPAA protects protected health information (PHI) held by covered entities (health plans, clearinghouses, and providers who transmit standard electronic transactions). FERPA protects education records at schools that receive U.S. Department of Education funds. Secondary-school ATs employed by the district usually operate under FERPA; hospital and clinic ATs usually operate under HIPAA. The HIPAA Privacy Rule excludes FERPA education records and FERPA treatment records of eligible postsecondary students from PHI. Follow the stricter applicable rule plus state law. Trap: posting an injury photo on Instagram, or telling a reporter the starting quarterback has an ACL tear.
PA8 Domain V requires practice within federal and state privacy law (task 0503, expanded in Chapter 18) and documentation that can be disclosed only through a legal pathway (task 0504). This section is the privacy pathway.
HIPAA: covered entity, PHI, TPO, authorization, minimum necessary
Covered entities (45 CFR 160.103) are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a transaction for which the Department of Health and Human Services (HHS) adopted a standard (claims, eligibility, referrals). An AT in an orthopedic clinic, hospital, or physician practice that bills electronically is typically a workforce member of a covered entity. Business associates (EHR vendors, billing companies, cloud storage) that create, receive, maintain, or transmit PHI need a business associate agreement (BAA).
PHI is individually identifiable health information—past, present, or future physical or mental health, care provided, or payment—when it identifies the person or could reasonably be used to identify them (name plus diagnosis, medical record number, photos of an identifiable injured athlete, and so on). De-identified data under HIPAA’s safe harbor or expert-determination methods is not PHI.
Treatment, payment, and health care operations (TPO) (45 CFR 164.501, 164.506) are the core uses that do not require an authorization:
- Treatment: providing, coordinating, or managing care; consultation; referral. Sharing the full relevant record with the receiving emergency department is treatment.
- Payment: billing, claims, eligibility, collections.
- Health care operations: quality assessment, competency review, legal services, audits—not a press conference.
HHS is explicit: a covered entity may choose to obtain consent for TPO, but HIPAA does not require it, and a consent form is not a valid authorization. Authorization (45 CFR 164.508) is the signed permission for uses beyond TPO—marketing, many media releases, sending records to a recruiter, or briefing a coach who is not a treating provider in a HIPAA setting. Authorizations must be specific (who, what, purpose, expiration) and are revocable.
Minimum necessary (45 CFR 164.502(b) and 164.514(d)): make reasonable efforts to limit use, disclosure, and requests of PHI to the least amount needed for the purpose. It does not apply to disclosures for treatment between providers, to the individual, pursuant to a valid authorization, or as required by law. It does apply to payment, operations, and most third-party requests. Role-based EHR access is how clinics operationalize it: the intern who only inventories tape does not open MRI reports.
Email and SMS are not confidential by default. Unencrypted consumer email and ordinary texts are a Security Rule problem for ePHI and a professional problem even in a FERPA school. Use the EHR portal, a covered messaging tool, or a documented patient request for unsecure email after warning. Never put diagnoses in a group chat with boosters.
Breach Notification Rule (45 CFR 164.404): a breach is an impermissible use or disclosure of unsecured PHI that compromises privacy or security (presumed a breach unless you document a low probability of compromise). Notify each affected individual without unreasonable delay and in no case later than 60 calendar days after discovery. Discovery is when any workforce member knew or should have known—not when the athletic director finally opened the email. Larger incidents also go to HHS (and to media when 500 or more residents of a state or jurisdiction are affected). Encryption that meets HHS guidance can be a safe harbor for otherwise lost devices.
FERPA: education records, treatment records, parents, directory information
The Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. § 1232g; 34 CFR Part 99) applies to educational agencies and institutions that receive funds from programs administered by the U.S. Department of Education. Education records are records directly related to a student and maintained by the school or a party acting for the school.
HHS/ED Joint Guidance (updated December 2019): the HIPAA Privacy Rule expressly excludes (1) education records covered by FERPA and (2) treatment records of eligible students as defined by FERPA. Those records are not PHI.
Elementary and secondary schools: generally not required to follow the HIPAA Privacy Rule for student health files, even if a school nurse or AT creates them, because those files are education records. A public-health nurse giving shots on campus who is not acting for the school may be outside FERPA (joint-guidance example)—that is the exception, not the employed school AT.
Postsecondary “treatment records” (34 CFR 99.3): records of a student who is 18 or older or attending postsecondary school, made and maintained by a physician, psychologist, or other recognized professional or paraprofessional only in connection with treatment, and disclosed only to treating persons (or to the student on request). They are not education records while they stay in that box. If you disclose them for a non-treatment purpose (eligibility, a coach’s personnel file, a media quote), they become education records and FERPA’s consent rules attach. A university hospital treating a student as a regular patient typically creates HIPAA PHI, not a campus treatment record.
Parents and eligible students. FERPA rights belong to parents of a student under 18 who is not yet an eligible student. Rights transfer to the student at age 18 or when the student attends a postsecondary institution at any age. HIPAA uses personal representative rules for unemancipated minors, with state-law exceptions for certain sensitive services. In a high school, you ordinarily talk to parents about injuries; in a college HIPAA clinic, the 18-year-old is the patient unless a personal-representative or authorization document says otherwise. Always add state minor-consent and custody rules.
Directory information (34 CFR 99.3, 99.37) may include name, participation in officially recognized activities and sports, and weight and height of athletes, after public notice and an opt-out window. Directory information is not a diagnosis, an MRI, a concussion count, or “questionable with an ACL.” Linking a name to an injury is not a directory disclosure. Recruiters and media get roster facts, not medical charts, unless a valid written consent (FERPA) or authorization (HIPAA) is on file.
School-official exception. FERPA allows disclosure without consent to school officials with a legitimate educational interest if the annual notice describes that category. A coach might receive playing status under a tightly written policy. That is still not a license to email the operative report to the entire staff group chat. Use minimum necessary analog, written P&Ps, and when in doubt written parent/eligible-student consent.
Which law, which setting, and when safety overrides silence
| Setting | Usual federal privacy frame | Typical AT records |
|---|---|---|
| Public/private K–12 receiving ED funds; AT employed by or acting for the district | FERPA education records | Injury files in the athletic training room |
| Campus health or sports medicine treating only students, records used solely for treatment | FERPA treatment records (eligible students) | College AT clinic notes kept in the treatment silo |
| Hospital, orthopedic clinic, outreach AT employed by a covered provider | HIPAA PHI | Billing EHR, clinic chart |
| University hospital seeing a student as any other patient | HIPAA | Hospital record |
Follow both when they overlap, plus state law, and when they conflict in practice, follow the stricter operational rule (usually: less disclosure, more authentication, better encryption). A hospital-employed outreach AT working in a high school may be a HIPAA workforce member and creating records the school will treat as FERPA—get the BAA, the school memorandum, and legal counsel’s written pathway before Friday night, not after a reporter calls.
Health or safety emergency (FERPA 34 CFR 99.31(a)(10) and 99.36): you may disclose personally identifiable information to appropriate parties (parents of an eligible student, law enforcement, EMS, medical personnel) if knowledge is necessary to protect health or safety and there is an articulable and significant threat under the totality of the circumstances. Record the threat and the recipients. HIPAA similarly permits disclosures to prevent or lessen a serious and imminent threat consistent with law and ethical conduct. Suicidal ideation with a plan, a cervical-spine emergency, or a reported assault in progress can justify a call to EMS, a parent, or campus police. The local television sports desk is not an appropriate party. ED guidance: the health-or-safety exception is not a media release.
Exam traps: an identifiable injury photo on Instagram or the athletics story; confirming to a reporter that the starting quarterback has an ACL tear; emailing unencrypted films to a booster; gossiping a diagnosis in the faculty lounge; assuming “the parent is a season-ticket holder so they already know.” Those are unauthorized disclosures, potential breaches, and—when FERPA applies—possible education-record violations. Playing status, if released at all, follows written policy and signed permission, not adrenaline.
An athletic trainer is employed by a public high-school district and maintains injury files in the school athletic training room. A second athletic trainer works for the local hospital’s outreach program and documents in the hospital EHR that bills electronically. Which privacy framework is the best exam description?
A reporter asks whether the starting quarterback has an ACL tear. A student intern also wants to post a sideline photo of the swollen, identifiable knee on the athletics Instagram. What is the correct privacy response?
Which statement correctly distinguishes HIPAA treatment/payment/operations, consent, authorization, and the minimum-necessary standard?