Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Pediatric Practices

The HIPAA compliance and security operating system for pediatric practices. Access is not one question but four — the parent, the guardian, the adolescent, and the patient turning eighteen — and it changes by age, service, consent, and state. Patient Protect runs the risk analysis, documents personal-representative decisions, controls portal proxy access, and keeps the evidence.

What HIPAA actually looks like for pediatric practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Pediatric practices operate under HIPAA as covered entities through standard electronic transactions. The Children's Online Privacy Protection Act (COPPA) applies separately to commercial online collection of personal information from children under 13 — patient portals serving under-13 patients face both frameworks. The Family Educational Rights and Privacy Act (FERPA) governs records held by school-based health programs, with operational complexity at the boundary between school-employed and contracted clinicians. State adolescent confidentiality laws shield specific record categories from parent access. State immunization registry (IIS) interfaces are state-mandated and subject to HIPAA.

OCR enforcement patterns

OCR's pediatric enforcement record includes cases of disclosure to parents who lacked personal-representative status under §164.502(g), school-coordination disclosure errors, immunization registry data flows that cascaded to broader breach exposure, and disclosure to non-custodial parents during custody disputes. The combination of overlapping frameworks (HIPAA, COPPA, FERPA, state adolescent confidentiality) creates more disclosure-decision complexity than most segments — and OCR has cited practices for failing to navigate the combinations correctly.

Standards beyond HIPAA

Section 164.502(g) personal representative analysis governing parent access. State-by-state adolescent confidentiality rules — typically shielding adolescent reproductive health, mental health, substance use, and STI care from parent access when the minor consents to the care under state law. COPPA's separate framework for under-13 patient portal use. FERPA's framework for school-based health programs that operate as part of the school's general operations. State immunization registry (IIS) interface requirements. EPSDT Medicaid documentation for pediatric Medicaid practices.

Common compliance gaps

Pediatric practices routinely have parental access not properly limited for shielded record categories, COPPA-HIPAA gap on under-13 portal access (COPPA-compliant parental consent for portal account creation isn't always implemented), IIS interfaces operating without explicit BAA infrastructure, school-coordination disclosures that mix HIPAA and FERPA rules, custody-related disclosure scenarios handled inconsistently, and inadequate workforce training on the specific disclosure rules that apply to adolescent patients.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State pediatric record laws govern patient record retention, frequently until age of majority plus six to seven years (effectively retention through patient age 24-26 for records of newborns). State immunization records have their own retention requirements. School-based health program records may be subject to FERPA retention (typically required while the student remains enrolled plus a tail). Federal Vaccines for Children program records have separate retention rules.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to pediatric practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where pediatric practices are most exposed.

Minor consent and parental access create complex disclosure rules

HIPAA gives parents broad access to their child's medical records — but state laws vary significantly on when minors can consent to treatment independently. Reproductive health, substance abuse, and mental health records may have different parental access rules than general pediatric care.

Adolescent privacy requires age-sensitive access controls

As patients approach adulthood, their privacy rights evolve. Some states grant adolescents independent consent for specific services, restricting parental access to those records. Your compliance program needs to track these thresholds and configure access accordingly.

Immunization registries require careful data sharing

State immunization information systems (IIS) require data reporting that intersects with HIPAA disclosure rules. Understanding when immunization data sharing falls under the public health exception versus when it requires authorization is critical for compliance.

School and daycare requests for records are common — and risky

Pediatric practices receive frequent records requests from schools, daycares, and sports programs. Each request requires proper authorization and minimum necessary disclosure. Staff training on handling these requests is essential to prevent over-disclosure.

Built for pediatric practices, not hospital systems.

Pediatric-specific risk assessment

SRA wizard covers minor consent, parental access, immunization reporting, and adolescent privacy — not a generic adult practice questionnaire.

Policy generation for minor consent

Auto-generated policies covering minor consent thresholds, parental access rights, and adolescent privacy protections — customized to your state.

Staff training on pediatric privacy

Training modules covering records release procedures, parental access rules, and age-sensitive disclosure requirements specific to pediatric practice.

Continuous compliance monitoring

Live compliance scoring that tracks your pediatric-specific obligations alongside standard HIPAA requirements — updated as regulations change.

Parental consent and adolescent-confidentiality framework

Pediatric practices navigate state-specific rules on adolescent confidentiality (when minors can consent to their own care, when their records are shielded from parents). Patient Protect's policy generation handles the state-by-state matrix and the §164.502(g) personal representative analysis that determines parent access rights.

Immunization registry compliance and EPSDT documentation

State immunization registries (IIS) and Medicaid EPSDT documentation create electronic transaction surfaces specific to pediatric practice. The risk analysis covers IIS interfaces and the EPSDT documentation framework Medicaid auditors expect.

State-specific HIPAA rules for pediatric practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

District of Columbia compliance requirements for pediatric practices

In addition to federal HIPAA requirements, pediatric practices operating in District of Columbia must comply with the following state-specific obligations.

Breach notification deadline

In the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

The statute does not fix a numeric outer bound. Unreasonable delay is itself a violation and may result in state enforcement action, so treat the operative timeframe as the shortest window your incident circumstances reasonably support.

Attorney General notification

Required for all breaches

Your practice must notify the state AG in addition to affected patients and HHS.

District of Columbia-specific laws & requirements

DC uses the New-York pattern: HIPAA covers individual notice, but AG notice is independent

For HIPAA-regulated entities operating in DC, satisfying HIPAA breach-notification obligations to individuals is deemed to satisfy the § 28-3852 individual-notice requirement under subsection (g). But the separate DC Attorney General notification obligation under § 28-3852(b-1) is triggered independently once a breach affects 50 or more DC residents, and HIPAA compliance does not substitute for that AG notice. Practices notifying HHS under HIPAA still owe a separate written AG notice to DC.

Source: D.C. Code § 28-3852(a)

Verified against primary state authority as of August 2026. General reference — consult legal counsel for your specific obligations.

Primary sources: code.dccouncil.gov · oag.dc.gov

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for pediatric practices.

Do parents have full access to their child's medical records under HIPAA?

Generally yes, but with important exceptions. HIPAA treats parents as personal representatives of minor children, granting broad access. However, state laws may restrict parental access to records related to services where the minor consented independently — such as reproductive health, substance abuse treatment, or mental health counseling. Your compliance program must account for your state's specific rules.

At what age do HIPAA rights transfer from parents to patients?

At age 18, full HIPAA rights transfer to the patient in all states. Before 18, state laws govern when minors can consent independently for specific services, which affects parental access rights. Some states have intermediate ages (12-16) for specific service categories. Patient Protect helps you track these thresholds for your state.

What does HIPAA compliance cost for a pediatric practice?

Patient Protect starts at $39/month with no contracts — covering risk assessments, pediatric-specific policies, staff training, BAA tracking, and continuous compliance monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.

When can a parent be denied access to their child's medical record?

Section 164.502(g) generally treats parents as personal representatives with full access rights, but with state-law-defined exceptions. Most states shield specific record categories from parent access — adolescent reproductive care, mental health, substance use, sexually transmitted infections — when the minor consents to the care under state law. The exception scope varies meaningfully by state, and pediatric practices must apply their state's specific framework.

Does FERPA or HIPAA apply to pediatric records held by school-based health programs?

School-based health programs that operate as covered entities under HIPAA (separate from the school's general operations) handle records under HIPAA's framework. School-employed nurses operating as school employees under FERPA handle records under FERPA. The boundary is operational: who employs the clinician, who controls the records, whether billing occurs. Many programs are functionally hybrid and require specific compliance analysis.

How do COPPA and HIPAA interact for pediatric patient portals?

COPPA (Children's Online Privacy Protection Act) governs commercial collection of personal information from children under 13 online. HIPAA covers the same population's PHI when handled by a covered entity. Pediatric patient portals serving under-13 patients face both frameworks: COPPA-compliant parental consent for portal account creation, HIPAA-compliant handling of the PHI accessed through the portal. Practices using portal vendors should confirm both frameworks are addressed in the BAA and the vendor's privacy practices.

Does a pediatric practice have to complete a HIPAA Security Risk Analysis?

Yes, and access control is the part that carries the most pediatric-specific risk. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a pediatric practice that means the EHR and patient portal including proxy, parent, guardian, adolescent, and transitioning-adult access; immunization registry and public-health workflows; school, daycare, camp, and sports requests; systems holding reproductive-health, mental-health, substance-use, or STI records subject to state adolescent-confidentiality rules; and custody, guardianship, and restricted-access documentation. A portal whose proxy access does not change as a patient ages is a finding waiting to happen.

Which of our pediatric vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR and portal vendors, billing service, claims clearinghouse, patient-communication and recall platforms, cloud storage and backup, IT support, and any scheduling or intake tool receiving identifiable data. State immunization information systems, public-health agencies, schools, and referral specialists generally are not business associates — those are disclosures made under public-health authority, treatment, or authorization rather than functions performed on the practice's behalf. Treating each of them as a BAA target is a common and avoidable misclassification.

How do we decide who counts as a child's personal representative?

It is a documented determination, not an assumption from the waiting room. Generally a parent or guardian who can act on the minor's behalf under state law is the personal representative and exercises the minor's HIPAA rights. There are three standing exceptions where the minor controls the information instead: where the minor consented to the care and no other consent is required by law, where the minor may lawfully obtain the care without parental consent, and where a parent has agreed to a confidential relationship between the minor and the clinician. State law drives all three, and it varies substantially. A practice needs a written process for making the determination, a place in the record to store it, and portal access that can actually enforce it — including revoking proxy access at the age your state sets.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a pediatric practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Pediatric compliance has rules that most HIPAA programs don't address.

See your real exposure in five minutes. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions