Does Billing Medicaid Make Schools HIPAA Covered?

Schools Are Billing Medicaid for Behavioral Health Services — Does That Make Your District a HIPAA Covered Entity?

Quick answer: In most cases, yes — technically. The moment your district (or a provider it employs) electronically bills Medicaid for a student’s mental health or behavioral health services, federal rules treat you as a HIPAA “covered entity” for that transaction. In practice, though, HIPAA’s Privacy Rule almost never governs the actual student records — FERPA does, because the information lives in an “education record.” The real compliance risk isn’t a phantom HIPAA violation; it’s assuming neither law applies and skipping the safeguards both actually require.

Why Districts Are Asking This Question Right Now

School-based Medicaid billing for mental and behavioral health services has expanded quickly, and much of that growth is happening outside the traditional special-education framework:

• A growing number of states — including Arkansas, Missouri, Minnesota, Tennessee, and South Carolina — now allow districts to bill Medicaid for behavioral health services without even filing a State Plan Amendment.

• Schools nationally receive an estimated $4–6 billion a year in Medicaid reimbursement for school-based services, and only a fraction of states have expanded reimbursement beyond students served under IDEA.

• Students are roughly six times more likely to access mental health care when it’s offered at school, which is pushing more districts to add counselors, therapists, and telehealth partnerships — and to bill Medicaid for them.

As behavioral health billing becomes a bigger part of how districts fund student services, the HIPAA question follows naturally: if we’re submitting health care claims, are we now a HIPAA-regulated organization?

The Technical Answer: Electronic Medicaid Billing Makes You a Covered Entity

HHS guidance is direct on this point: a school that employs a health care provider — a school psychologist, counselor, therapist, or nurse — who electronically submits a Medicaid claim for a covered transaction becomes a HIPAA “covered entity” for that transaction. This is true whether the district thinks of itself as a health care organization or not.

It doesn’t matter who does the billing. A school nurse submitting a claim, a contracted mental health provider billing on the district’s behalf, or a telehealth vendor billing under the district’s Medicaid provider number can all trigger covered-entity status for the underlying transaction.

But FERPA — Not the HIPAA Privacy Rule — Usually Still Governs the Records

HIPAA’s own regulations carve out an exception: information maintained in “education records” as defined under FERPA is excluded from HIPAA’s definition of protected health information (45 CFR § 160.103).

Because nearly every health-related record a K-12 school keeps on a student — nurse visit logs, counseling session notes, therapy records tied to an IEP or 504 plan — meets FERPA’s definition of an education record, HIPAA’s privacy protections generally don’t apply to it. FERPA’s do instead.

The result is a scenario that confuses a lot of administrators: your district can be a HIPAA covered entity that, for privacy purposes, has no protected health information at all — because everything it holds is a FERPA education record instead.

Where HIPAA Doesn’t Go Away Entirely

Covered-entity status isn’t purely academic. Even when the Privacy Rule steps aside, a few things still apply:

• Your district must still comply with HIPAA’s Transaction, Code Set, and Identifier Rules for the Medicaid billing itself — whoever submits the claim, and whatever software or clearinghouse touches it, has to meet those technical standards.

• If a contracted provider bills independently under its own name — for example, an outside behavioral health agency or telehealth vendor that isn’t itself subject to FERPA — that provider may be a full HIPAA covered entity for the records it creates, privacy rule included.

• Private and religious schools generally don’t receive federal education funding and typically aren’t subject to FERPA at all — which means a private school billing Medicaid electronically may be a HIPAA covered entity with no FERPA exclusion to fall back on.

Why the Distinction Actually Matters for Your Compliance Program

This isn’t just a legal technicality. It changes what your district is required to do in several concrete ways:

1. Consent requirements differ. FERPA requires written parental (or eligible student) consent before disclosing information for Medicaid billing purposes — a separate requirement from HIPAA authorization, and the one that usually governs here.

2. Breach response follows different rules. Education records generally trigger FERPA and state student-data-privacy breach obligations, not the HIPAA Breach Notification Rule — unless an independent, non-FERPA-covered provider’s records are involved.

3. Vendor paperwork needs to match reality. Internal school-based providers typically need FERPA-compliant data-sharing or “school official” agreements. Outside billing vendors, clearinghouses, or telehealth partners that are themselves HIPAA covered entities need Business Associate Agreements.

4. Security expectations are converging either way. FERPA doesn’t include HIPAA’s detailed Security Rule requirements, but cyber insurers, state privacy laws, and CMS program-integrity reviews increasingly expect HIPAA-grade safeguards around any system that touches Medicaid claims data — regardless of which privacy law technically applies to the record.

A Compliance Checklist for Districts Billing Medicaid for Behavioral Health

• Map every point where a district employee or contracted provider submits an electronic Medicaid claim for mental or behavioral health services.

• For each record type, confirm the governing framework: education record → FERPA governs privacy; independent outside provider not subject to FERPA → HIPAA Privacy Rule likely governs.

• Update consent forms so FERPA consent language explicitly covers disclosure of information for Medicaid billing purposes.

• Audit vendor contracts: FERPA-compliant data-sharing agreements for internal providers, Business Associate Agreements for any outside billing vendor, clearinghouse, or telehealth partner that qualifies as a HIPAA covered entity.

• Apply HIPAA-grade technical safeguards — encryption, access controls, audit logging — to whatever system actually submits the Medicaid claims, even if the broader student record system is FERPA-governed.

• Train school health staff, counselors, and administrators on which framework governs which piece of information. This is where most real-world confusion, and risk, actually lives.

Frequently Asked Questions

Does billing Medicaid for a student’s counseling or therapy services make our school district a HIPAA covered entity?

Generally, yes. If the district or a health care provider it employs submits an electronic Medicaid claim for a covered transaction, HHS treats the district as a HIPAA covered entity for that transaction — even if the district doesn’t think of itself as a health care organization.

Does that mean the HIPAA Privacy Rule applies to our students’ behavioral health records?

Usually not. If those records qualify as “education records” under FERPA — which most school-maintained counseling and mental health records do — HIPAA’s Privacy Rule explicitly excludes them, and FERPA governs privacy instead.

Do we still need to worry about HIPAA at all?

Yes. Your district still has to comply with HIPAA’s Transaction, Code Set, and Identifier Rules for the Medicaid billing itself. And if you contract with an outside provider that isn’t subject to FERPA, that provider’s records may be governed by the full HIPAA Privacy Rule.

What’s the difference between FERPA consent and HIPAA authorization for Medicaid billing?

FERPA requires written parental or eligible-student consent before disclosing information for Medicaid billing purposes. HIPAA authorization is a separate, more detailed requirement that generally doesn’t apply when the record is a FERPA education record — but it can apply to an independent HIPAA-covered provider working with your district.

What should our district do first?

Start by mapping every point where student behavioral health information is electronically billed to Medicaid, then confirm which framework — FERPA or HIPAA — governs each record and each vendor relationship involved.

Not Sure Which Rules Apply to Your District’s Medicaid Billing? Find Out Before It Becomes a Problem

FERPA and HIPAA overlap in ways that trip up even well-run compliance programs — especially as more districts add behavioral health billing to their Medicaid programs. The safest move is finding out now exactly which framework governs each piece of your student health data and each vendor relationship, not after an incident forces the question.

Get a free HIPAA Risk Review. We’ll help you map where FERPA and HIPAA intersect in your district’s Medicaid billing and show you exactly where your compliance gaps are.

Schedule Your Free HIPAA Risk Review

Sources

U.S. Department of Health and Human Services & U.S. Department of Education, Joint Guidance on the Application of FERPA and HIPAA to Student Health Records (December 2019 update).

45 CFR § 160.103 — HIPAA definitions; exclusion of FERPA “education records” from “protected health information.”

MACPAC, School-Based Services for Students Enrolled in Medicaid (March 2024), macpac.gov.

Healthy Schools Campaign, Medicaid Funding for School-Based Services.