Summary
The HIPAA Security Rule requires covered entities and business associates to conduct a thorough, ongoing risk analysis. HIPAA’s Breach Notification Rule requires specific actions when PHI is compromised. - Treating HIPAA as a one-time project — compliance requires ongoing monitoring and updates
HIPAA Readiness Checklist for EdTech: What Schools and Education Platforms Need to Know
Education technology companies increasingly collect sensitive student data — and when that data includes health information, HIPAA compliance becomes a serious legal obligation. Whether you’re building a school wellness app, a mental health platform for students, or a telehealth integration for campus health centers, understanding your HIPAA responsibilities is non-negotiable.
This comprehensive HIPAA readiness checklist for EdTech will help your organization assess its current compliance posture, identify gaps, and take concrete steps toward protecting student health information.
Does HIPAA Actually Apply to Your EdTech Company?
Before diving into the checklist, it’s worth clarifying when HIPAA applies to education technology organizations. Many EdTech companies assume FERPA (Family Educational Rights and Privacy Act) is their only concern — but that’s not always true.
HIPAA applies to EdTech companies when they:
- Operate as a covered entity (e.g., a telehealth platform, school-based health clinic software, or campus health records system)
- Function as a business associate of a covered entity (e.g., a vendor processing health data on behalf of a hospital or clinic)
- Handle Protected Health Information (PHI) that falls outside FERPA’s scope
Note that FERPA and HIPAA can overlap. If a school health record is maintained by the school and used for educational purposes, FERPA typically governs it. But if that same record is created by a covered healthcare provider, HIPAA applies. When in doubt, consult legal counsel.
HIPAA Readiness Checklist for EdTech Organizations
1. Governance and Policy Foundation
Strong HIPAA compliance starts with documented policies and clear organizational accountability.
- [ ] Designate a HIPAA Privacy Officer and a Security Officer
- [ ] Develop and maintain a formal HIPAA Privacy Policy
- [ ] Create a HIPAA Security Policy addressing administrative, physical, and technical safeguards
- [ ] Establish a sanctions policy for workforce members who violate HIPAA rules
- [ ] Document your organization’s role (covered entity vs. business associate) in writing
- [ ] Review and update all policies at least annually
2. Risk Analysis and Risk Management
The HIPAA Security Rule requires covered entities and business associates to conduct a thorough, ongoing risk analysis.
- [ ] Complete a formal Security Risk Analysis (SRA) identifying all PHI your platform touches
- [ ] Document potential threats and vulnerabilities to PHI confidentiality, integrity, and availability
- [ ] Assign risk levels (high, medium, low) to each identified risk
- [ ] Develop a Risk Management Plan with timelines and responsible owners
- [ ] Review and update your risk analysis whenever there are significant operational or technical changes
- [ ] Retain documentation of all risk analyses for a minimum of 6 years
3. Business Associate Agreements (BAAs)
If your EdTech platform shares PHI with third-party vendors — cloud providers, analytics tools, email services — you need signed BAAs in place.
- [ ] Identify all vendors and subcontractors who access, store, or transmit PHI on your behalf
- [ ] Execute a signed Business Associate Agreement (BAA) with each vendor before sharing PHI
- [ ] Ensure BAAs include required HIPAA provisions: permitted uses, safeguards, breach notification obligations, and subcontractor requirements
- [ ] Maintain a BAA inventory with contract dates and renewal schedules
- [ ] Verify that major cloud providers (AWS, Google Cloud, Microsoft Azure) have signed your BAA
4. Technical Safeguards
Your platform’s technical infrastructure must actively protect PHI from unauthorized access and breaches.
- [ ] Implement role-based access controls (RBAC) so users only access PHI they need
- [ ] Enforce multi-factor authentication (MFA) for all systems containing PHI
- [ ] Encrypt PHI at rest and in transit using industry-standard encryption (AES-256, TLS 1.2+)
- [ ] Maintain audit logs of all access to PHI, including who accessed what and when
- [ ] Implement automatic session timeouts for inactive users
- [ ] Conduct regular vulnerability scans and penetration testing
- [ ] Establish a process for emergency access to PHI when needed
5. Physical Safeguards
Even cloud-based EdTech platforms need to address physical security requirements.
- [ ] Control physical access to servers, workstations, and devices that store or process PHI
- [ ] Implement workstation use policies specifying appropriate use and physical positioning of screens
- [ ] Establish device and media controls covering disposal, reuse, and backup of PHI
- [ ] Document policies for remote work scenarios where employees may access PHI from home
- [ ] Ensure third-party data centers used by your platform maintain appropriate physical security certifications (e.g., SOC 2)
6. Administrative Safeguards
Administrative safeguards are often the most overlooked — and the most critical — element of HIPAA compliance.
- [ ] Conduct HIPAA training for all workforce members who handle PHI before they access systems
- [ ] Provide annual refresher training and document completion records
- [ ] Establish a workforce clearance procedure to determine appropriate PHI access levels
- [ ] Create and test an incident response plan for potential security incidents
- [ ] Document a contingency plan including data backup, disaster recovery, and emergency operations procedures
- [ ] Perform periodic internal HIPAA audits to assess compliance
7. Patient and Student Rights Under HIPAA
When HIPAA applies, individuals have specific rights regarding their PHI that your platform must support.
- [ ] Provide individuals with a Notice of Privacy Practices (NPP) explaining how their PHI is used
- [ ] Establish a process for handling access requests (individuals requesting copies of their PHI)
- [ ] Create a procedure for amendment requests when individuals believe their PHI is inaccurate
- [ ] Maintain an accounting of disclosures so individuals can see who has accessed their PHI
- [ ] Respond to all PHI-related requests within 30 days (or 60 days with written notice)
8. Breach Notification Readiness
HIPAA’s Breach Notification Rule requires specific actions when PHI is compromised.
- [ ] Define what constitutes a breach vs. a permissible disclosure in your internal policies
- [ ] Establish a breach assessment process using the four-factor risk assessment test
- [ ] Create notification templates for affected individuals, HHS, and media (when applicable)
- [ ] Notify HHS of breaches affecting 500+ individuals within 60 days of discovery
- [ ] Notify individuals within 60 days of discovering a breach
- [ ] Maintain a breach log for smaller incidents and report annually to HHS
Common HIPAA Mistakes EdTech Companies Make
Understanding where companies typically fall short helps you avoid the same pitfalls:
- Assuming FERPA coverage eliminates HIPAA obligations — the two laws can apply simultaneously
- Skipping BAAs with SaaS vendors — cloud tools like Slack, Zoom, or email providers may process PHI
- Treating HIPAA as a one-time project — compliance requires ongoing monitoring and updates
- Insufficient workforce training — human error remains the leading cause of healthcare data breaches
- No documented risk analysis — this is the most commonly cited HIPAA violation by OCR auditors
FAQ: HIPAA Compliance for EdTech
Is HIPAA or FERPA more important for EdTech companies?
Both laws may apply depending on your platform’s function. FERPA governs educational records maintained by schools, while HIPAA governs PHI created or maintained by healthcare providers. Many EdTech platforms — especially those in student wellness, mental health, or telehealth — must comply with both. Always analyze your specific data flows to determine which law applies.
What happens if an EdTech company violates HIPAA?
HIPAA violations can result in civil penalties ranging from $100 to $50,000 per violation, with annual maximums up to $1.9 million per violation category. Willful neglect that isn’t corrected can result in criminal charges. Beyond financial penalties, breaches damage user trust and can derail partnerships with healthcare institutions.
Do small EdTech startups need to comply with HIPAA?
Yes, if your startup handles PHI as a covered entity or business associate, HIPAA applies regardless of company size. The HHS Office for Civil Rights (OCR) has investigated and fined small organizations. However, the required safeguards can be scaled appropriately to your organization’s size and complexity.
How often should we update our HIPAA compliance program?
At minimum, annually — but also whenever you experience a significant change such as launching a new product feature, onboarding a new vendor, experiencing a security incident, or hiring substantially more staff. Compliance is a living program, not a one-time certification.
What’s the difference between HIPAA readiness and HIPAA certification?
HIPAA does not have an official government certification. “HIPAA readiness” means your organization has implemented the required safeguards and documented your compliance efforts. Third-party audits and certifications (like HITRUST) can validate your program but are not legally required — though they are increasingly expected by enterprise healthcare clients.
Take the Guesswork Out of HIPAA Compliance
Working through this checklist is a strong first step — but building every policy, procedure, and template from scratch is time-consuming and leaves room for costly errors.
Our ready-to-use HIPAA compliance template bundle for EdTech includes everything your team needs to get compliant faster:
- ✅ HIPAA Privacy and Security Policy templates
- ✅ Risk Analysis and Risk Management Plan frameworks
- ✅ Business Associate Agreement (BAA) template
- ✅ Workforce Training Acknowledgment forms
- ✅ Breach Notification Response Plan
- ✅ Notice of Privacy Practices (NPP) template
- ✅ HIPAA Audit Checklist and internal assessment tools
Stop spending weeks building compliance documentation from scratch. Our templates are written by compliance professionals, formatted for immediate use, and designed specifically for EdTech and digital health organizations.
👉 [Download the EdTech HIPAA Compliance Template Bundle Today] and give your team the foundation they need to protect student health data — and your business.
Best for teams building a HIPAA documentation and readiness baseline.
HIPAA Security + Privacy Rule documentation with audit-readiness artifacts
View template →