Early Iterations Of The HIPAA Act
The scenario's most important detail is a claim that is almost certainly untrue. Whether student health records fall under HIPAA or FERPA decides which rules apply and which complaint route exists.
Editorial process
Last reviewed · August 22, 2026
Does HIPAA even apply to a college health center?
Start with the jurisdiction question, because most answers assume HIPAA applies and the real position is more interesting. Records that a postsecondary institution maintains about a student for treatment purposes are generally treatment records under the education-records statute and are specifically excluded from the definition of protected health information, so the college health centre may be governed by education-records law rather than by the health privacy rule. Federal guidance exists precisely because the boundary confuses people, and which side the records fall on decides everything downstream: which rules govern disclosure, whether an enforcement complaint goes to the Office for Civil Rights, and whether the student has an administrative remedy at all. Note also the qualifier: the exclusion turns on records made or maintained for treatment of a student and used only in connection with that treatment, so a centre that bills insurance electronically can find parts of its operation inside the health privacy regime after all.
Then examine the claim the professor makes, because it is the load-bearing fact and it is almost certainly false. Neither framework permits routine access to treatment records by every instructor and staff member. Under either regime, disclosure requires authorisation or a recognised exception, and general staff curiosity is not one. So the analysis has three parts worth separating: whether the disclosure the professor describes would be lawful, whether the professor's statement about institutional practice is accurate, and what the student can actually do. On the last, use the fact the brief supplies. The 2009 delegation consolidated Security Rule enforcement with Privacy Rule enforcement under the Office for Civil Rights, which is why complaints became a single route rather than two, and it is worth noting that a student whose records are education records instead has a different and weaker complaint path, since that framework offers no private right of action and its enforcement office is a different one.
Likely learning objectives
- Determine which privacy framework governs a given set of records.
- Apply the treatment-records exclusion to a college health centre.
- Evaluate a factual claim about institutional practice against the rules.
- Trace the complaint route created by the 2009 enforcement delegation.
Assignment instructions
Read the full question
Review every instruction before using the planning guidance that follows.
Imagine that you are a sophomore at Premier College. Over the past few months, you have not been well due to increased amounts of academic pressure and found yourself unable to concentrate in class or sleep well at night. You went to the student medical center for evaluation and, after consulting with the staff doctor, you were issued a prescription for the treatment of depression. A few days later, one of your professors tells you that he too has had to take medicine for depression in the past. You ask him how he knew about your situation, and he replied that all student medical records are available to every instructor and staff member at Premier College. Hearing this, you feel that your privacy rights have been violated. That afternoon you research privacy rights on the Internet and learn that filing a HIPAA privacy complaint to the OCR had been a tedious process before July 2009. On July 27, 2009, the Secretary of Health and Human Services (HHS) delegated to the Director of OCR the authority to administer and enforce the HIPAA Security Rule. This action improved HHS’ ability to protect individuals’ health information by combining the authority for administration and enforcement of federal standards for health information privacy and security. Those standards are outlined in the HIPAA legislation. With the new regulation, the process of filing a privacy complaint has become simpler and more effective. Then you research the steps involved with filing a privacy complaint with the OCR (http://www.hhs.gov/ocr/privacy/hipaa/complaints/index.html), download the Health Information Privacy Complaint form at (http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/complaints/hipcomplaintform.pdf), and complete the form. While working on the form, you realize some sections are critical to your case and must be addressed carefully. Early Iterations Of The HIPAA Act You decide to write about your experience in a paper for your Legal Issues in Information Security class. For this assignment: 1. Identify the early iterations of the HIPAA act and how the law has been modified to facilitate easier access to consumer complaints and enforcement. 2. Describe the overall process of submitting a health information privacy complaint to the OCR. 3. Identify specific sections of the complaint form that need critical attention while completing the form. 4. Analyze a few situations that can occur if the critical sections are not well identified. 5. Draft a brief summary, collating all your findings. Required Resources · Access to the Internet · http://www.hhs.gov/ocr/privacy/hipaa/complaints/index.html · http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/complaints/hipcomplaintform.pdf Submission Requirements § Format: Microsoft Word § Font: Arial 10-point size, Double-space § Citation Style: APA § Length: No more than 500 words Evaluation Criteria and Rubric 1. Did the student identify early iterations of the HIPAA act and how the law has been modified to facilitate easier access to consumer complaints and enforcement? 2. Did the student identify specific sections of the form that need critical attention while filing the complaint? Did the student analyze the situations that one gets into if the critical sections are not well identified?
Turn the brief into deliverables
- 01A determination of which law governs the records in the scenario.
- 02The treatment-records exclusion, stated accurately.
- 03An assessment of whether the professor's claim about access is lawful.
- 04The complaint process available, matched to the governing framework.
- 05The significance of consolidating enforcement under one office.
Which law governs, then what was breached, then the remedy
Which framework governs
Apply the education-records and treatment-records definitions to this health centre.
What the assessor is likely looking for
The treatment-records exclusion identified rather than assumed away.
What the professor claims
Test the assertion of universal instructor access against both frameworks.
What the assessor is likely looking for
A conclusion that the claimed practice would be unlawful under either.
Privacy Rule and Security Rule
Distinguish the two rules and say which the scenario engages.
What the assessor is likely looking for
A distinction between protecting information and securing systems.
The 2009 delegation
Explain what consolidating enforcement under one office changed for a complainant.
What the assessor is likely looking for
Enforcement consolidation described as procedural, not substantive.
What the student can do
Set out the actual remedy available under the framework you identified.
What the assessor is likely looking for
A remedy that exists under that framework rather than the assumed one.
Where the FERPA and HIPAA boundary is documented
Recommended databases
- U.S. Department of Education
- Office for Civil Rights
- NCBI Bookshelf
- University Library
Search sequence
- 1.Read the joint federal guidance on the FERPA and HIPAA boundary first.
- 2.Confirm the treatment-records exclusion wording rather than paraphrasing it.
- 3.Check what an OCR complaint requires and what it can produce.
- 4.Look up the difference between the Privacy Rule and the Security Rule.
Reference shortlist
These are authoritative starting points, not a ready-made bibliography. A qualified reviewer must confirm that each source fits the assignment and supports the claim beside which it is cited.
Joint Guidance on the Application of FERPA and HIPAA to Student Health Records
U.S. Department of Education and the Office for Civil Rights, U.S. Department of Health and Human Services · 2019
The joint federal guidance that decides which framework governs these records.
Health Insurance Portability and Accountability Act (HIPAA) Compliance
StatPearls, NCBI Bookshelf · 2023
HIPAA compliance, for the Privacy and Security Rule distinction.
Depression
National Institute of Mental Health · 2025
Depression treatment context, for why these records are especially sensitive.
Patient Safety and Quality
Agency for Healthcare Research and Quality, NCBI Bookshelf · 2008
Patient safety and quality, for the organisational accountability framing.
Before you submit this case analysis
Common mistakes
- Assuming HIPAA governs college health records without checking the exclusion.
- Accepting the professor's claim about universal staff access as fact.
- Confusing the Privacy Rule with the Security Rule.
- Describing the complaint process without saying which regime creates it.
- Treating the 2009 delegation as creating the rules rather than consolidating enforcement.
Submission checklist
- Have you resolved the FERPA and HIPAA question before analysing the breach?
- Is the treatment-records exclusion cited to a source?
- Have you evaluated the professor's claim rather than assuming it?
- Does the complaint route match the framework you identified?
- Are the Privacy and Security Rules distinguished?
Use this guide to plan and review your own work. Follow your institution's rules and read Brinevia's academic-integrity policy.
Written by
Maren Caldwell
MSN, RN, CNE
Medical-surgical nursing, pharmacology and NCLEX preparation
Maren is a registered nurse with over 15 years of clinical and educational experience in medical-surgical nursing. She writes on NCLEX preparation, patient care fundamentals, pharmacology and evidence-based practice.

Reviewed by
Dr. Tessa Redmond
DNP, RN, CNE
Evidence-based practice and clinical education
Tessa is a doctorally-prepared nurse educator. She reviews Brinevia content for clinical accuracy and alignment with current evidence-based guidelines.