
A 2026 guide to the different legal frameworks that can apply to healthcare and education transcription—and why a single “HIPAA + FERPA compliant” badge can be misleading.
Quick answer: A transcription company does not become “HIPAA and FERPA compliant” through one universal certificate. HIPAA and FERPA apply in different contexts and use different legal mechanisms. For HIPAA, determine whether the vendor is a business associate and execute the required BAA/safeguards where applicable. For FERPA, institutions must analyze whether education records may be disclosed under an applicable exception—often the school-official exception for contractors subject to direct control and use/redisclosure limits. Student health records require special attention because many records maintained by FERPA-covered institutions are excluded from the HIPAA Privacy Rule.
• Do not assume every student health record is governed by both HIPAA and FERPA; official HHS/ED guidance explains important boundaries.
• HIPAA business-associate relationships typically require a written BAA and safeguards when PHI is handled on behalf of a covered entity/business associate.
• FERPA contractor access commonly depends on an applicable exception, institutional criteria and contractual direct control over use/maintenance of education records.
• Security controls are necessary across both contexts: access, encryption, subprocessors, retention, incidents, deletion and secondary/AI use.
• The institution remains responsible for classifying the data/use case and approving the disclosure and vendor workflow.
HIPAA regulates covered entities and business associates in defined healthcare contexts. FERPA protects education records at covered educational agencies/institutions that receive applicable U.S. Department of Education funds. A transcription job can sit in one regime, the other, or sometimes involve records whose legal treatment needs careful classification.
The joint HHS/U.S. Department of Education guidance on student health records is especially important: many health records maintained by a FERPA-covered school are education records or treatment records under FERPA and are excluded from the HIPAA Privacy Rule. That means “apply both automatically” can be the wrong analysis.
When a transcription vendor creates, receives, maintains or transmits PHI to perform a service for a HIPAA covered entity or business associate, it can be a business associate. HHS guidance describes the required written assurances/contracts and safeguard obligations.
Procurement should map the full PHI flow, including human review, cloud storage, automated speech recognition, support systems and subcontractors. Make sure required business-associate obligations flow down and the actual service is the one covered by the agreement.
FERPA generally limits disclosure of personally identifiable information from education records without consent, subject to exceptions. U.S. Department of Education guidance explains that a contractor, consultant, volunteer or other outside party may qualify as a school official when the institution’s criteria and regulatory conditions are met, including performance of an institutional service/function for which employees would otherwise be used and being under the institution’s direct control with respect to use and maintenance of education records.
The institution should document its annual-notice criteria and contract controls, and limit the vendor’s use/redisclosure to the purpose for which the disclosure is made. Do not substitute a vendor marketing statement for the institution’s FERPA analysis.
Contract — HIPAA lens: BAA when required | FERPA lens: Institution contract/direct-control + use/redisclosure limits
Data classification — HIPAA lens: PHI/ePHI and permitted purpose | FERPA lens: Education record/PII + applicable disclosure basis
Access — HIPAA lens: Minimum necessary/role-based controls as applicable | FERPA lens: Only authorized service personnel
Subprocessors — HIPAA lens: Business-associate flow-down where required | FERPA lens: Contractual control and no unauthorized redisclosure
Security — HIPAA lens: Administrative/physical/technical safeguards | FERPA lens: Reasonable institutional/vendor security controls
Retention/deletion — HIPAA lens: Purpose-aligned, contract/policy requirements | FERPA lens: No longer than needed/contract and records obligations
AI/data use — HIPAA lens: No unapproved secondary use; contract it | FERPA lens: No use beyond authorized educational purpose
Incidents — HIPAA lens: BAA/security notification/cooperation | FERPA lens: Contract/institution response and notification as applicable
Before uploading a campus clinic visit, counseling session, disability/accommodation meeting, research interview or class recording, identify who maintains the record, for what purpose, and which institutional policy/legal framework applies. Different records inside the same university can have different treatment.
Research recordings may add IRB, informed-consent, grant, data-management-plan and participant-confidentiality requirements beyond HIPAA or FERPA. Build those project-specific restrictions into the transcription instructions and contract.
1. Which regulated-data workflows do you support, and what agreements apply to each?
2. Will you sign our BAA when the service makes you a HIPAA business associate?
3. For FERPA records, can you contractually accept direct-control, purpose/use and redisclosure restrictions required by the institution?
4. Who can access recordings/transcripts, and from where?
5. Which subprocessors/AI providers can receive content?
6. Is content used to train or improve models/products?
7. What encryption, authentication, logging and endpoint controls apply?
8. How long are audio, drafts, finals and backups retained?
9. How are incidents escalated and customers notified/cooperated with?
10. Can project-level access, retention, glossary and deletion rules be enforced?
A credible compliance claim is specific: the vendor can support the buyer’s legally authorized workflow, required contract, safeguards and data-use restrictions. It is not a universal “HIPAA + FERPA certified” badge.
For Verbalscripts or any provider, have the healthcare/privacy, education privacy, security and legal stakeholders classify the records first, then approve the exact transcription workflow and agreement.
• How to order HIPAA-compliant transcription - BAA/HIPAA ordering guidance.
• IRB-compliant research transcription - IRB and research privacy.
• Transcription for university professors - Academic use cases.
• Transcription for qualitative researchers - Research interviews and focus groups.
• Strict-confidentiality transcription - Confidential workflows.
Do not assume so. Official joint guidance explains that many student health records maintained by FERPA-covered institutions are FERPA records excluded from the HIPAA Privacy Rule. Specific facts matter.
No. A BAA is a HIPAA mechanism. FERPA disclosures to contractors rely on applicable FERPA rules/exception criteria and institutional control/use restrictions, often implemented in contract.
Generally, performing services for a covered entity/business associate that involve creating, receiving, maintaining or transmitting PHI can create a business-associate relationship. Use HHS guidance and counsel for the specific relationship.
No. Security matters, but FERPA also governs authorized disclosure, use, maintenance, direct control and redisclosure of education-record information.
Not automatically. Classification depends on the records and institutional context. Research may also be governed by IRB/consent/data-management requirements. Ask the institution’s privacy/research office.
1. HHS: Business Associates - Official HHS business-associate/BAA guidance.
2. HHS: HIPAA Security Rule - Official safeguard guidance.
3. U.S. Department of Education: FERPA - Official FERPA overview.
4. U.S. Department of Education: Who is a school official under FERPA? - Third-party contractor conditions.
5. HHS/ED: FERPA and HIPAA student health records - Joint student-health-record guidance.
Educational overview only. HIPAA/FERPA applicability is fact-specific. Institutions should obtain advice from their privacy, security, education-records, research and legal teams and use the exact current regulations/guidance.
A 2026 guide to the different legal frameworks that can apply to healthcare and education transcription—and why a single “HIPAA + FERPA compliant” badge can be misleading.
Quick answer: A transcription company does not become “HIPAA and FERPA compliant” through one universal certificate. HIPAA and FERPA apply in different contexts and use different legal mechanisms. For HIPAA, determine whether the vendor is a business associate and execute the required BAA/safeguards where applicable. For FERPA, institutions must analyze whether education records may be disclosed under an applicable exception—often the school-official exception for contractors subject to direct control and use/redisclosure limits. Student health records require special attention because many records maintained by FERPA-covered institutions are excluded from the HIPAA Privacy Rule.
• Do not assume every student health record is governed by both HIPAA and FERPA; official HHS/ED guidance explains important boundaries.
• HIPAA business-associate relationships typically require a written BAA and safeguards when PHI is handled on behalf of a covered entity/business associate.
• FERPA contractor access commonly depends on an applicable exception, institutional criteria and contractual direct control over use/maintenance of education records.
• Security controls are necessary across both contexts: access, encryption, subprocessors, retention, incidents, deletion and secondary/AI use.
• The institution remains responsible for classifying the data/use case and approving the disclosure and vendor workflow.
HIPAA regulates covered entities and business associates in defined healthcare contexts. FERPA protects education records at covered educational agencies/institutions that receive applicable U.S. Department of Education funds. A transcription job can sit in one regime, the other, or sometimes involve records whose legal treatment needs careful classification.
The joint HHS/U.S. Department of Education guidance on student health records is especially important: many health records maintained by a FERPA-covered school are education records or treatment records under FERPA and are excluded from the HIPAA Privacy Rule. That means “apply both automatically” can be the wrong analysis.
When a transcription vendor creates, receives, maintains or transmits PHI to perform a service for a HIPAA covered entity or business associate, it can be a business associate. HHS guidance describes the required written assurances/contracts and safeguard obligations.
Procurement should map the full PHI flow, including human review, cloud storage, automated speech recognition, support systems and subcontractors. Make sure required business-associate obligations flow down and the actual service is the one covered by the agreement.
FERPA generally limits disclosure of personally identifiable information from education records without consent, subject to exceptions. U.S. Department of Education guidance explains that a contractor, consultant, volunteer or other outside party may qualify as a school official when the institution’s criteria and regulatory conditions are met, including performance of an institutional service/function for which employees would otherwise be used and being under the institution’s direct control with respect to use and maintenance of education records.
The institution should document its annual-notice criteria and contract controls, and limit the vendor’s use/redisclosure to the purpose for which the disclosure is made. Do not substitute a vendor marketing statement for the institution’s FERPA analysis.
Contract — HIPAA lens: BAA when required | FERPA lens: Institution contract/direct-control + use/redisclosure limits
Data classification — HIPAA lens: PHI/ePHI and permitted purpose | FERPA lens: Education record/PII + applicable disclosure basis
Access — HIPAA lens: Minimum necessary/role-based controls as applicable | FERPA lens: Only authorized service personnel
Subprocessors — HIPAA lens: Business-associate flow-down where required | FERPA lens: Contractual control and no unauthorized redisclosure
Security — HIPAA lens: Administrative/physical/technical safeguards | FERPA lens: Reasonable institutional/vendor security controls
Retention/deletion — HIPAA lens: Purpose-aligned, contract/policy requirements | FERPA lens: No longer than needed/contract and records obligations
AI/data use — HIPAA lens: No unapproved secondary use; contract it | FERPA lens: No use beyond authorized educational purpose
Incidents — HIPAA lens: BAA/security notification/cooperation | FERPA lens: Contract/institution response and notification as applicable
Before uploading a campus clinic visit, counseling session, disability/accommodation meeting, research interview or class recording, identify who maintains the record, for what purpose, and which institutional policy/legal framework applies. Different records inside the same university can have different treatment.
Research recordings may add IRB, informed-consent, grant, data-management-plan and participant-confidentiality requirements beyond HIPAA or FERPA. Build those project-specific restrictions into the transcription instructions and contract.
1. Which regulated-data workflows do you support, and what agreements apply to each?
2. Will you sign our BAA when the service makes you a HIPAA business associate?
3. For FERPA records, can you contractually accept direct-control, purpose/use and redisclosure restrictions required by the institution?
4. Who can access recordings/transcripts, and from where?
5. Which subprocessors/AI providers can receive content?
6. Is content used to train or improve models/products?
7. What encryption, authentication, logging and endpoint controls apply?
8. How long are audio, drafts, finals and backups retained?
9. How are incidents escalated and customers notified/cooperated with?
10. Can project-level access, retention, glossary and deletion rules be enforced?
A credible compliance claim is specific: the vendor can support the buyer’s legally authorized workflow, required contract, safeguards and data-use restrictions. It is not a universal “HIPAA + FERPA certified” badge.
For Verbalscripts or any provider, have the healthcare/privacy, education privacy, security and legal stakeholders classify the records first, then approve the exact transcription workflow and agreement.
• How to order HIPAA-compliant transcription - BAA/HIPAA ordering guidance.
• IRB-compliant research transcription - IRB and research privacy.
• Transcription for university professors - Academic use cases.
• Transcription for qualitative researchers - Research interviews and focus groups.
• Strict-confidentiality transcription - Confidential workflows.
Do not assume so. Official joint guidance explains that many student health records maintained by FERPA-covered institutions are FERPA records excluded from the HIPAA Privacy Rule. Specific facts matter.
No. A BAA is a HIPAA mechanism. FERPA disclosures to contractors rely on applicable FERPA rules/exception criteria and institutional control/use restrictions, often implemented in contract.
Generally, performing services for a covered entity/business associate that involve creating, receiving, maintaining or transmitting PHI can create a business-associate relationship. Use HHS guidance and counsel for the specific relationship.
No. Security matters, but FERPA also governs authorized disclosure, use, maintenance, direct control and redisclosure of education-record information.
Not automatically. Classification depends on the records and institutional context. Research may also be governed by IRB/consent/data-management requirements. Ask the institution’s privacy/research office.
1. HHS: Business Associates - Official HHS business-associate/BAA guidance.
2. HHS: HIPAA Security Rule - Official safeguard guidance.
3. U.S. Department of Education: FERPA - Official FERPA overview.
4. U.S. Department of Education: Who is a school official under FERPA? - Third-party contractor conditions.
5. HHS/ED: FERPA and HIPAA student health records - Joint student-health-record guidance.
Educational overview only. HIPAA/FERPA applicability is fact-specific. Institutions should obtain advice from their privacy, security, education-records, research and legal teams and use the exact current regulations/guidance.
Get latest updates for our Articles & Blogs. We post fresh content every week.
Sign up for our monthly newsletter