Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Pediatric Practices

The HIPAA compliance and security operating system for pediatric practices. Access is not one question but four — the parent, the guardian, the adolescent, and the patient turning eighteen — and it changes by age, service, consent, and state. Patient Protect runs the risk analysis, documents personal-representative decisions, controls portal proxy access, and keeps the evidence.

Pediatric practices that electronically conduct claims, eligibility, authorization, or other adopted transactions are HIPAA covered entities. Once covered, the duties below are required, including the additional work of managing parents, minors, personal representatives, and age-dependent confidentiality.

HIPAA compliance is not optional for a covered pediatric practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What a pediatric practice’s Security Risk Analysis must cover

Pediatric privacy is not simply adult privacy with a parent copied. Access rights can change based on the child's age, custody status, the service provided, who consented to the care, and state law. The SRA and compliance program must account for those changing relationships.

  • The EHR and patient portal, including proxy, parent, guardian, adolescent, and transitioning-adult access
  • Immunization registry, public-health, school, daycare, camp, sports, and specialty-referral workflows
  • Systems containing reproductive-health, mental-health, substance-use, STI, or other state-protected adolescent records
  • Custody, guardianship, foster-care, personal-representative, and restricted-access documentation
  • Claims, laboratories, e-prescribing, messaging, email, text, e-fax, and patient forms
  • Workforce access to sensitive pediatric and adolescent information
  • Vendors and interfaces that receive pediatric information on the practice's behalf

What the pediatric compliance program must also address

  • A documented process for determining who is the patient's personal representative
  • State-specific minor-consent and adolescent-confidentiality rules
  • Access controls that prevent inappropriate proxy access to protected categories of adolescent information
  • Written procedures for schools, non-custodial parents, guardians, courts, public-health agencies, and immunization requests
  • Training that teaches staff how access and disclosure decisions change across age, service type, consent authority, and state law

Parental access cannot be managed through assumption. The practice needs a documented decision framework and systems capable of enforcing it.

What HIPAA actually looks like for pediatric practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Pediatric practices operate under HIPAA as covered entities through standard electronic transactions. The Children's Online Privacy Protection Act (COPPA) applies separately to commercial online collection of personal information from children under 13 — patient portals serving under-13 patients face both frameworks. The Family Educational Rights and Privacy Act (FERPA) governs records held by school-based health programs, with operational complexity at the boundary between school-employed and contracted clinicians. State adolescent confidentiality laws shield specific record categories from parent access. State immunization registry (IIS) interfaces are state-mandated and subject to HIPAA.

OCR enforcement patterns

OCR's pediatric enforcement record includes cases of disclosure to parents who lacked personal-representative status under §164.502(g), school-coordination disclosure errors, immunization registry data flows that cascaded to broader breach exposure, and disclosure to non-custodial parents during custody disputes. The combination of overlapping frameworks (HIPAA, COPPA, FERPA, state adolescent confidentiality) creates more disclosure-decision complexity than most segments — and OCR has cited practices for failing to navigate the combinations correctly.

Standards beyond HIPAA

Section 164.502(g) personal representative analysis governing parent access. State-by-state adolescent confidentiality rules — typically shielding adolescent reproductive health, mental health, substance use, and STI care from parent access when the minor consents to the care under state law. COPPA's separate framework for under-13 patient portal use. FERPA's framework for school-based health programs that operate as part of the school's general operations. State immunization registry (IIS) interface requirements. EPSDT Medicaid documentation for pediatric Medicaid practices.

Common compliance gaps

Pediatric practices routinely have parental access not properly limited for shielded record categories, COPPA-HIPAA gap on under-13 portal access (COPPA-compliant parental consent for portal account creation isn't always implemented), IIS interfaces operating without explicit BAA infrastructure, school-coordination disclosures that mix HIPAA and FERPA rules, custody-related disclosure scenarios handled inconsistently, and inadequate workforce training on the specific disclosure rules that apply to adolescent patients.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State pediatric record laws govern patient record retention, frequently until age of majority plus six to seven years (effectively retention through patient age 24-26 for records of newborns). State immunization records have their own retention requirements. School-based health program records may be subject to FERPA retention (typically required while the student remains enrolled plus a tail). Federal Vaccines for Children program records have separate retention rules.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to pediatric practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where pediatric practices are most exposed.

Minor consent and parental access create complex disclosure rules

HIPAA gives parents broad access to their child's medical records — but state laws vary significantly on when minors can consent to treatment independently. Reproductive health, substance abuse, and mental health records may have different parental access rules than general pediatric care.

Adolescent privacy requires age-sensitive access controls

As patients approach adulthood, their privacy rights evolve. Some states grant adolescents independent consent for specific services, restricting parental access to those records. Your compliance program needs to track these thresholds and configure access accordingly.

Immunization registries require careful data sharing

State immunization information systems (IIS) require data reporting that intersects with HIPAA disclosure rules. Understanding when immunization data sharing falls under the public health exception versus when it requires authorization is critical for compliance.

School and daycare requests for records are common — and risky

Pediatric practices receive frequent records requests from schools, daycares, and sports programs. Each request requires proper authorization and minimum necessary disclosure. Staff training on handling these requests is essential to prevent over-disclosure.

Built for pediatric practices, not hospital systems.

Pediatric-specific risk assessment

SRA wizard covers minor consent, parental access, immunization reporting, and adolescent privacy — not a generic adult practice questionnaire.

Policy generation for minor consent

Auto-generated policies covering minor consent thresholds, parental access rights, and adolescent privacy protections — customized to your state.

Staff training on pediatric privacy

Training modules covering records release procedures, parental access rules, and age-sensitive disclosure requirements specific to pediatric practice.

Continuous compliance monitoring

Live compliance scoring that tracks your pediatric-specific obligations alongside standard HIPAA requirements — updated as regulations change.

Parental consent and adolescent-confidentiality framework

Pediatric practices navigate state-specific rules on adolescent confidentiality (when minors can consent to their own care, when their records are shielded from parents). Patient Protect's policy generation handles the state-by-state matrix and the §164.502(g) personal representative analysis that determines parent access rights.

Immunization registry compliance and EPSDT documentation

State immunization registries (IIS) and Medicaid EPSDT documentation create electronic transaction surfaces specific to pediatric practice. The risk analysis covers IIS interfaces and the EPSDT documentation framework Medicaid auditors expect.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25personnel · No long-term contract

State-specific HIPAA rules for pediatric practices.

HIPAA is federal. What a state adds on top of it varies more than most compliance guidance admits — some states impose their own notification deadline and regulator notice, and others exclude HIPAA covered entities from their breach statute entirely. Select your state to see which of those is true where you practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk analysis structured to §164.308(a)(1)(ii)(A)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 9. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, compliance scoring, secure messaging, and standard PIPAA usage.

Recommended

Pro

$99/mo

Everything in Basic, plus the patient-facing workflows. Patient Management and Digital Forms, expanded PIPAA usage, and up to 50 personnel.

See full feature comparison →

Common questions about HIPAA compliance for pediatric practices.

Do parents have full access to their child's medical records under HIPAA?

Generally yes, but with important exceptions. HIPAA treats parents as personal representatives of minor children, granting broad access. However, state laws may restrict parental access to records related to services where the minor consented independently — such as reproductive health, substance abuse treatment, or mental health counseling. Your compliance program must account for your state's specific rules.

At what age do HIPAA rights transfer from parents to patients?

At age 18, full HIPAA rights transfer to the patient in all states. Before 18, state laws govern when minors can consent independently for specific services, which affects parental access rights. Some states have intermediate ages (12-16) for specific service categories. Patient Protect helps you track these thresholds for your state.

What does HIPAA compliance cost for a pediatric practice?

Patient Protect starts at $39/month with no contracts — covering risk assessments, pediatric-specific policies, staff training, BAA tracking, and continuous compliance monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.

When can a parent be denied access to their child's medical record?

Section 164.502(g) generally treats parents as personal representatives with full access rights, but with state-law-defined exceptions. Most states shield specific record categories from parent access — adolescent reproductive care, mental health, substance use, sexually transmitted infections — when the minor consents to the care under state law. The exception scope varies meaningfully by state, and pediatric practices must apply their state's specific framework.

Does FERPA or HIPAA apply to pediatric records held by school-based health programs?

School-based health programs that operate as covered entities under HIPAA (separate from the school's general operations) handle records under HIPAA's framework. School-employed nurses operating as school employees under FERPA handle records under FERPA. The boundary is operational: who employs the clinician, who controls the records, whether billing occurs. Many programs are functionally hybrid and require specific compliance analysis.

How do COPPA and HIPAA interact for pediatric patient portals?

COPPA (Children's Online Privacy Protection Act) governs commercial collection of personal information from children under 13 online. HIPAA covers the same population's PHI when handled by a covered entity. Pediatric patient portals serving under-13 patients face both frameworks: COPPA-compliant parental consent for portal account creation, HIPAA-compliant handling of the PHI accessed through the portal. Practices using portal vendors should confirm both frameworks are addressed in the BAA and the vendor's privacy practices.

Does a pediatric practice have to complete a HIPAA Security Risk Analysis?

Yes, and access control is the part that carries the most pediatric-specific risk. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a pediatric practice that means the EHR and patient portal including proxy, parent, guardian, adolescent, and transitioning-adult access; immunization registry and public-health workflows; school, daycare, camp, and sports requests; systems holding reproductive-health, mental-health, substance-use, or STI records subject to state adolescent-confidentiality rules; and custody, guardianship, and restricted-access documentation. A portal whose proxy access does not change as a patient ages is a finding waiting to happen.

Which of our pediatric vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR and portal vendors, billing service, claims clearinghouse, patient-communication and recall platforms, cloud storage and backup, IT support, and any scheduling or intake tool receiving identifiable data. State immunization information systems, public-health agencies, schools, and referral specialists generally are not business associates — those are disclosures made under public-health authority, treatment, or authorization rather than functions performed on the practice's behalf. Treating each of them as a BAA target is a common and avoidable misclassification.

How do we decide who counts as a child's personal representative?

It is a documented determination, not an assumption from the waiting room. Generally a parent or guardian who can act on the minor's behalf under state law is the personal representative and exercises the minor's HIPAA rights. There are three standing exceptions where the minor controls the information instead: where the minor consented to the care and no other consent is required by law, where the minor may lawfully obtain the care without parental consent, and where a parent has agreed to a confidential relationship between the minor and the clinician. State law drives all three, and it varies substantially. A practice needs a written process for making the determination, a place in the record to store it, and portal access that can actually enforce it — including revoking proxy access at the age your state sets.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a pediatric practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Pediatric compliance has rules that most HIPAA programs don't address.

See your real exposure in five minutes. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions