FERPA Data and HIPAA IT Compliance: Are You Exposed?
Most schools and healthcare practices assume they're covered — until they're not. Here's what FERPA and HIPAA actually require from your IT setup.
Share:
Summary:
Most school administrators and healthcare practice managers in Contra Costa County aren’t ignoring compliance — they’re just assuming someone else has it handled. The district’s IT coordinator. The cloud platform. The billing software vendor. But when a regulator comes knocking, or a breach surfaces, that assumption tends to fall apart fast.
FERPA and HIPAA are two of the most consequential data privacy laws in the country, and both place real technical obligations on the organizations that handle student records and patient information. This guide walks through what those obligations actually look like, where the two laws intersect in ways most people don’t expect, and what it means for the schools and practices serving communities across Contra Costa County.
What FERPA Data Requirements Actually Mean for Schools
FERPA — the Family Educational Rights and Privacy Act — governs how schools handle student education records. That includes grades, transcripts, attendance, disciplinary history, psychological evaluations, course schedules, and family contact information. Any school or district that receives federal funding is covered, which means virtually every public K-12 school in Contra Costa County, from West Contra Costa Unified to San Ramon Valley Unified to Mount Diablo Unified, operates under FERPA’s rules.
The stakes aren’t abstract. A FERPA violation can trigger loss of all federal funding — Title I, IDEA, Pell Grants — which would be catastrophic for most districts. Third-party sharing violations rose 34% in 2024, and about one-third of directory information errors repeat over time once they occur. The most common violations aren’t dramatic cyberattacks — they’re quiet, ongoing gaps in how data is managed and shared.
Why IT Infrastructure Is at the Center of FERPA Compliance
FERPA compliance isn’t just a policy problem. You can have a beautifully written privacy notice and a signed acceptable use policy and still be non-compliant if your IT systems don’t support what those policies promise.
FERPA requires that student records be accessible only to authorized individuals. That means role-based access controls — so a substitute teacher can’t pull up the same data as a school counselor. It means audit logs that track who accessed what and when, so you can actually answer that question if a parent or regulator asks. It means encrypted data storage and transmission, so records aren’t exposed in transit or at rest.
Every third-party vendor with access to student data — the learning management system, the tutoring app, the cloud storage provider — needs a signed data processing agreement confirming they’ll only use that data for its intended purpose. Between 2016 and 2021, 55% of all K-12 data breaches were carried out through schools’ vendors, not through direct attacks on the schools themselves. In 2022, a ransomware attack on a single website hosting company took down the websites of 5,000 schools across the country.
For schools in Contra Costa County, the EdTech adoption pressure is real. Bay Area schools are constantly evaluating new platforms, and each new tool is a new vendor relationship that needs to be assessed for FERPA compliance before it goes live — not after. That requires an IT infrastructure built to evaluate, document, and monitor those relationships on an ongoing basis.
California also adds its own layer here. AB 1584 — the Student Privacy Protection Act — requires California local education agencies to include specific data privacy protections in all technology service agreements. That’s a state-level obligation on top of the federal FERPA requirements, and it affects every district and charter school in Contra Costa County.
The "We Haven't Had a Problem Yet" Assumption Is the Riskiest One
It’s a natural conclusion to draw. If nothing has gone wrong, something must be working. But the absence of a known incident isn’t the same as compliance — and in the world of data security, it’s often just a matter of timing.
Healthcare breaches take an average of 279 days to detect and contain. Education breaches follow similar patterns. Many FERPA violations — particularly around directory information and third-party sharing — go unreported entirely because the affected school doesn’t know they occurred. The Los Angeles Unified School District didn’t find out that approximately 2,000 student assessment records had been posted to the dark web until months after the underlying cyberattack.
The diagnostic question worth asking isn’t “have we had a breach?” — it’s “would we know if we did?” That requires audit logs. It requires 24/7 monitoring that flags unusual access patterns. It requires a vendor management process that tracks which third parties have access to student data and under what terms. Most schools that haven’t invested in compliance-specific IT infrastructure would have to answer honestly: no, we probably wouldn’t know right away.
For smaller schools — charter schools, private schools, smaller districts — this is especially acute. The same FERPA obligations that apply to a large unified district apply equally to a charter school with 300 students and no dedicated IT staff. The law doesn’t scale down based on enrollment. Compliance gaps tend to be larger at smaller organizations precisely because they have fewer resources to address them.
HIPAA IT Compliance for Healthcare Practices in Contra Costa County
HIPAA’s Privacy and Security Rules govern how healthcare organizations handle protected health information — patient records, diagnoses, billing data, treatment notes. For independent medical practices, dental offices, behavioral health providers, and specialty clinics throughout Concord, Walnut Creek, San Ramon, and the broader Contra Costa County area, HIPAA compliance is a legal baseline, not an optional upgrade.
The numbers behind non-compliance are significant. The average healthcare data breach now costs $9.48 million, according to IBM’s 2024 report. In 2024, the HHS Office for Civil Rights collected nearly $12.8 million in civil penalties from healthcare organizations. Civil penalties range from $141 to $71,162 per violation — and each improperly disclosed record can count as a separate violation.
HIPAA Compliance IT Requirements: What Your Systems Need to Support
HIPAA’s Security Rule is explicitly an IT rule. It requires covered entities — which includes most healthcare practices — to implement administrative, physical, and technical safeguards for electronic protected health information. On the technical side, that means access controls, audit logs, automatic logoff, encryption, and integrity controls. It also means conducting a documented risk analysis, which is the single most frequently cited failure in OCR enforcement actions.
The number one reason healthcare organizations get penalized isn’t a dramatic breach or a rogue employee. It’s the failure to document that they ever assessed their own risk. OCR investigators ask for the risk analysis first. If you can’t produce one, the conversation gets difficult quickly — regardless of how secure your systems actually are.
HIPAA also requires a signed Business Associate Agreement (BAA) with every vendor that handles protected health information on your behalf. That includes your EHR provider, your billing service, your cloud storage platform, your IT support company. A BAA isn’t a formality — it’s a legal requirement, and operating without one is itself a HIPAA violation. Many small practices in Contra Costa County are running with vendors they’ve used for years without ever formalizing that agreement.
In 2022, 55% of OCR HIPAA settlements targeted small practices — not large hospital systems. The assumption that regulators only go after major healthcare networks is simply wrong. Small practices are often easier targets precisely because their compliance programs are less mature, their documentation is thinner, and their IT infrastructure is less monitored. An independent practice in Concord with three providers and a part-time office manager typically doesn’t have the dedicated compliance infrastructure that larger health systems maintain.
HIPAA compliance for a small or mid-sized practice isn’t something you can manage reactively. It requires continuous monitoring, documented processes, regular staff training, and a vendor management program that keeps pace with the platforms you’re using.
When FERPA and HIPAA Both Apply — The Overlap Contra Costa County Schools Need to Understand
Most guides treat FERPA and HIPAA as separate topics. For a lot of organizations, that’s fine — schools follow FERPA, healthcare practices follow HIPAA. But there’s a growing category of organizations in Contra Costa County where both laws apply simultaneously, and the overlap is genuinely complicated.
Under normal circumstances, FERPA and HIPAA are mutually exclusive. When health information is stored in a student’s education record — say, a nurse’s note or a medication log kept by the school — it’s covered by FERPA, not HIPAA. The HIPAA Privacy Rule explicitly excludes education records that fall under FERPA. So for most school health offices, FERPA is the governing framework.
But that changes in specific situations. If a school operates a clinic that bills Medicaid, HIPAA may apply to those billing records. If the school hosts independent healthcare providers — a contracted therapist, a vaccination program run by a county health agency — those providers are likely covered entities under HIPAA and must comply accordingly. Under California’s Children and Youth Behavioral Health Initiative (CYBHI), which is actively expanding school-based behavioral health services throughout Contra Costa County, schools are increasingly partnering with county behavioral health agencies in ways that create genuine FERPA-HIPAA overlap scenarios.
The CYBHI program is particularly relevant here. As Contra Costa County schools bring behavioral health services onto campus to support students, the data generated by those services may be governed by HIPAA (if held by the healthcare provider) or FERPA (if incorporated into the student’s education record), or both — depending on how the program is structured and documented. Getting that wrong isn’t a technicality. It’s a compliance exposure with real consequences on both sides.
Navigating the FERPA-HIPAA overlap requires someone who understands both frameworks and can assess how your specific data flows and vendor relationships interact with each one. It’s not enough to know the rules in the abstract. You have to know how they apply to your actual systems.
How to Know If Your IT Setup Is Actually Protecting You
The honest answer for most schools and healthcare practices is that they don’t know — not with any real confidence. They have policies. They have software. They have a vendor or two they’ve been using for years. But the specific technical controls that FERPA and HIPAA require — the audit logs, the access controls, the documented risk assessments, the signed agreements — often haven’t been systematically verified.
That’s not a failure of intention. It’s a resource problem. Compliance-specific IT requires specialized knowledge that most organizations don’t have in-house, and the cost of building it from scratch is significant.
We’ve been working with schools, healthcare practices, and businesses throughout Contra Costa County since 2003. We understand what FERPA and HIPAA actually require at the infrastructure level — not just in policy documents — and we know how California’s AB 1584 and CCPA add to that picture for organizations operating in this state. If you’re not sure where you stand, Red Box Business Solutions offers a free IT HealthCheck that gives you a clear picture of your current exposure before you make any decisions. You can reach us at (925) 513-0000.
Article details:
- Published by:
- Red Box Business Solution
- Published to:
- Last modified:
- August 26, 2026
Share:



