Educause Security Discussion
mailing list archives
Re: Electronic Health Records (EHR's)?
From: Kevin Halgren <kevin.halgren () WASHBURN EDU>
Date: Wed, 23 Jan 2013 09:42:59 -0600
Since I haven't heard anything, I thought I'd provide at least a partial
answer to some of my questions based on what I've found. There are a
number of government and private sources providing guidance on the topic
For the intersection of HIPAA and FERPA regulations, the following
document is a good reference. I've used it before but regularly go back
In particular items 7 and higher in the FAQ
A good article on the topic:
HIPAA Security Rule Info:
34 CFS Part 99 (FERPA)
Department of Education FERPA policy guidance:
Many other good records:
Health Information and Management Systems Society (HIMSS) has a number
of excellent resources as Electronic Health Records as well:
On 1/22/2013 8:21 AM, Kevin Halgren wrote:
Our counseling unit is looking at Electronic Health Record software.
This is our first real foray into this technology and I'm trying to
get ahead of the curve on this initiative. While they're not asking
for the ability to exchange records with anyone right now, I expect to
have that request in the near future, even if only with internal
healthcare-related units. I have a few questions for those of you who
may already use these:
1) How does the intersection of FERPA and HIPPA affect EHR's? I'm
aware the FERPA trumps HIPPA in situations where both may apply, but
then how would FERPA affect exchanging such records internally or with
external medical organizations?
2) As a practical matter, how is secure exchange of EHR's performed
and how often is it done?
3) What are the best resources you are aware of for getting up to
speed and staying up to date on EHR regulations and technologies?
Any input you can provide for any of these questions would be helpful.