Do parents have full access to their child's medical records under HIPAA?
Generally yes, but with important exceptions. HIPAA treats parents as personal representatives of minor children, granting broad access. However, state laws may restrict parental access to records related to services where the minor consented independently — such as reproductive health, substance abuse treatment, or mental health counseling. Your compliance program must account for your state's specific rules.
At what age do HIPAA rights transfer from parents to patients?
At age 18, full HIPAA rights transfer to the patient in all states. Before 18, state laws govern when minors can consent independently for specific services, which affects parental access rights. Some states have intermediate ages (12-16) for specific service categories. Patient Protect helps you track these thresholds for your state.
What does HIPAA compliance cost for a pediatric practice?
Patient Protect starts at $39/month with no contracts — covering risk assessments, pediatric-specific policies, staff training, BAA tracking, and continuous compliance monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.
When can a parent be denied access to their child's medical record?
Section 164.502(g) generally treats parents as personal representatives with full access rights, but with state-law-defined exceptions. Most states shield specific record categories from parent access — adolescent reproductive care, mental health, substance use, sexually transmitted infections — when the minor consents to the care under state law. The exception scope varies meaningfully by state, and pediatric practices must apply their state's specific framework.
Does FERPA or HIPAA apply to pediatric records held by school-based health programs?
School-based health programs that operate as covered entities under HIPAA (separate from the school's general operations) handle records under HIPAA's framework. School-employed nurses operating as school employees under FERPA handle records under FERPA. The boundary is operational: who employs the clinician, who controls the records, whether billing occurs. Many programs are functionally hybrid and require specific compliance analysis.
How do COPPA and HIPAA interact for pediatric patient portals?
COPPA (Children's Online Privacy Protection Act) governs commercial collection of personal information from children under 13 online. HIPAA covers the same population's PHI when handled by a covered entity. Pediatric patient portals serving under-13 patients face both frameworks: COPPA-compliant parental consent for portal account creation, HIPAA-compliant handling of the PHI accessed through the portal. Practices using portal vendors should confirm both frameworks are addressed in the BAA and the vendor's privacy practices.
Does a pediatric practice have to complete a HIPAA Security Risk Analysis?
Yes, and access control is the part that carries the most pediatric-specific risk. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a pediatric practice that means the EHR and patient portal including proxy, parent, guardian, adolescent, and transitioning-adult access; immunization registry and public-health workflows; school, daycare, camp, and sports requests; systems holding reproductive-health, mental-health, substance-use, or STI records subject to state adolescent-confidentiality rules; and custody, guardianship, and restricted-access documentation. A portal whose proxy access does not change as a patient ages is a finding waiting to happen.
Which of our pediatric vendors need Business Associate Agreements?
Any organization handling PHI on the practice's behalf: the EHR and portal vendors, billing service, claims clearinghouse, patient-communication and recall platforms, cloud storage and backup, IT support, and any scheduling or intake tool receiving identifiable data. State immunization information systems, public-health agencies, schools, and referral specialists generally are not business associates — those are disclosures made under public-health authority, treatment, or authorization rather than functions performed on the practice's behalf. Treating each of them as a BAA target is a common and avoidable misclassification.
How do we decide who counts as a child's personal representative?
It is a documented determination, not an assumption from the waiting room. Generally a parent or guardian who can act on the minor's behalf under state law is the personal representative and exercises the minor's HIPAA rights. There are three standing exceptions where the minor controls the information instead: where the minor consented to the care and no other consent is required by law, where the minor may lawfully obtain the care without parental consent, and where a parent has agreed to a confidential relationship between the minor and the clinician. State law drives all three, and it varies substantially. A practice needs a written process for making the determination, a place in the record to store it, and portal access that can actually enforce it — including revoking proxy access at the age your state sets.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a pediatric practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.