FERPA HIPAA Data Handling Policy
- Home
- FERPA HIPAA Data Handling Policy
Effective Date: November 03, 2025
Purpose and Scope
This policy describes how The Advocacy Circle (‘TAC’, ‘we’, ‘our’, or ‘us’) collects, stores, processes, and protects data governed by the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act (HIPAA). It applies to all educational and health-related information submitted to TAC by parents, guardians, educational professionals, or other users.
FERPA Applicability
While TAC is not an educational institution under FERPA, we handle education records in compliance with FERPA principles when submitted by parents or legal guardians. We treat all student-related records as confidential and restrict access accordingly.
HIPAA Applicability
TAC is not a covered entity under HIPAA but may receive Protected Health Information (PHI) incidentally or through service delivery. All such data is handled with HIPAA-level administrative, physical, and technical safeguards.
Student and Child Information
We do not knowingly collect personal data directly from children under 13. Any information about a minor must be submitted by a parent or legal guardian, who assumes responsibility for consent.
Parental Rights and Access
In accordance with FERPA, parents and eligible students may request access to or correction of education records. Requests must be submitted in writing to support@theadvocacycircle.com and will be verified and fulfilled within 30 days.
Business Associate Agreements (BAAs)
TAC enters into BAAs with third-party service providers or contractors who may access education or health data in the course of delivering services, ensuring compliance with HIPAA and related privacy obligations.
Data Retention and Deletion
We retain records only as long as necessary to fulfill the purpose of collection or comply with legal obligations. Users may request deletion of their information at any time, subject to verification and applicable data retention laws.
Safeguards and Security
TAC uses encryption, role-based access control, secure cloud servers, and audit logging to protect educational and health data from unauthorized access, loss, or misuse.
Breach Notification
In the event of a suspected or confirmed breach involving sensitive data, TAC will notify affected individuals without undue delay, in accordance with FERPA, HIPAA, and applicable state data breach laws.
Staff Training and Confidentiality
All TAC employees and subcontractors undergo privacy and data protection training. Access to sensitive data is limited to staff with a verified business need, and all personnel are subject to confidentiality agreements.