Do I need HIPAA forms as a speech-language pathologist?
It depends on where the records live, not on your credential. If you run a private practice and bill a health plan electronically, you are a covered entity and you need the full document set. If you work in a school, the student records you touch are generally FERPA education records, which 45 CFR 160.103 expressly excludes from protected health information.
Plenty of SLPs sit in both worlds at once. The table below maps the common settings before the checklist.
Researched and written by Larry Osakwe · Last verified August 1, 2026
Checked against the current 45 CFR text and the ED/HHS joint FERPA-HIPAA guidance. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
FERPA or HIPAA, by where you work
The two statutes almost never apply to the same record. What decides it is who maintains the record and what kind of record it is.
| Your setting | Generally governed by | Why |
|---|---|---|
| You are employed by a public school district, serving students under IDEA | FERPA | Records the school maintains on a student are education records. 45 CFR 160.103 expressly excludes information in FERPA education records from the definition of protected health information. |
| The school bills Medicaid for your services | FERPA | Medicaid billing does not convert an education record into PHI. The record is still maintained by the school on the student, so the FERPA exclusion still applies. |
| You run a private practice and bill insurance or Medicare electronically | HIPAA | You are transmitting a covered transaction with a health plan, which makes you a covered entity under 45 CFR 160.103. Your records are PHI. |
| You run a private practice, private-pay only, superbills only | Usually neither | No electronic covered transaction means generally no covered-entity status. State confidentiality law and licensure ethics still apply to the records you hold. |
| You contract with a school through your own private practice | Possibly both | Records the school holds are typically its education records; records you keep in your own practice can be PHI if you are a covered entity. Your contract should say who holds what. |
| You work in a hospital, SNF, or outpatient rehab clinic | HIPAA | The facility is a covered entity and you access PHI under its umbrella. Its policies, training, and BAAs govern your access. |
Do speech-language pathologists have to comply with HIPAA?
It depends entirely on where the records live rather than on your credential. A private-practice SLP who transmits health information electronically in connection with a covered transaction, most commonly submitting claims to Medicare or a private payer directly or through a clearinghouse, is a HIPAA covered entity under 45 CFR 160.103. A school-based SLP working with student records is usually governed by FERPA instead, and a purely private-pay practice that never bills electronically may be governed by neither federal statute, leaving state law and board ethics to do the work. The table above maps the common settings.
The covered-entity test, profession by professionI'm a school-based SLP. Is it FERPA or HIPAA?
Generally FERPA, and the reason is unusually clean for a HIPAA question. The definition of protected health information at 45 CFR 160.103 expressly excludes individually identifiable health information in education records covered by the Family Educational Rights and Privacy Act, 20 U.S.C. 1232g. So even where a school district is itself a HIPAA covered entity for some other purpose, the student records it maintains are carved out of PHI by definition. This holds even when the district bills Medicaid for your services, which is the point that trips people up: billing a health plan does not convert an education record into PHI, because the exclusion turns on what kind of record it is and who maintains it, not on how it is funded.
I do school contract work and see private clients. Which rules apply?
Potentially both at once, on different records. The records the school maintains on its students are typically the school's education records under FERPA. The records you create and keep inside your own private practice are your practice's records, and are PHI if your practice is a covered entity. The practical failure mode is an ambiguous contract that never says who holds which record, which leaves you guessing about access requests, retention, and breach obligations. Get that written down before it matters, and keep the two record sets physically and logically separate so the answer stays obvious.
Can I just use ASHA's privacy notice template and be done?
ASHA's sample Notice of Privacy Practices is a genuinely useful starting point, and ASHA sensibly advises against altering its core legal text. But a Notice is one document out of eight. A covered practice also generally needs written privacy and security policies, a documented Security Risk Analysis of the systems that actually hold your data, signed BAAs with your EHR and teletherapy vendors, a training log, a breach procedure, and named Privacy and Security Officials. Downloading a template and filing it is the most common way a practice ends up with one correct document and seven missing ones.
How long do I have to keep speech therapy records?
Under HIPAA the documentation floor is six years: 45 CFR 164.316(b)(2)(i) requires a covered entity to retain the required written policies, documentation, and records for six years from the date of creation or the date it was last in effect, whichever is later. That is a floor for HIPAA paperwork, not a ceiling for clinical records. State record-retention law and payer contracts frequently require longer, and for minors many states run the clock from the age of majority rather than the date of service. Keep evaluations, plans of care, and progress notes to whichever requirement is longest.
The eight documents a covered SLP practice needs
If you landed on the HIPAA side, this is the document set you must be able to produce: the same set every covered practice needs, flavored with the vendors and records an SLP practice actually has. Each item cites the rule that requires it, so you can verify any of it against the regulation.
Notice of Privacy Practices
The notice you give every client or guardian, post in a clear and prominent place, and publish on your website, describing how the practice uses and discloses client information.
45 CFR § 164.520
NPP acknowledgment of receipt
The form documenting your good-faith effort to obtain written acknowledgment that the client or guardian received the notice; it belongs in the intake packet at the evaluation.
45 CFR § 164.520(c)(2)
Authorization + rights request forms
The written-permission form for disclosures HIPAA does not already permit, plus request forms for access, amendment, restrictions, and an accounting of disclosures. For pediatric caseloads these run through the parent or guardian as personal representative.
45 CFR § 164.508; §§ 164.522–164.528
Business Associate Agreements + vendor register
A signed BAA with every vendor that touches client data, tracked in a register. For an SLP practice that typically means your EHR (SimplePractice, Fusion, TheraPlatform, CentralReach), your teletherapy platform, any billing service or clearinghouse, cloud backup, and email.
45 CFR § 164.502(e); § 164.504(e)
Security Risk Analysis
The documented, accurate and thorough assessment of risks to electronic client data across every system that holds it: EHR, teletherapy recordings, AAC and assessment data, email, backups, devices. The most-cited deficiency in OCR enforcement.
45 CFR § 164.308(a)(1)(ii)(A)
Privacy & security policies with a training log
Your written rulebook for access, minimum-necessary use, and safeguards, plus documented workforce training and a sanctions policy, covering SLPAs, billing help, and any administrative staff, not just the SLP.
45 CFR § 164.530(b); § 164.308(a)(5); § 164.316
Breach notification procedure + breach log
What to do when something goes wrong: notification without unreasonable delay and no later than 60 calendar days after discovery, plus your state's breach statute answered specifically.
45 CFR §§ 164.400–414
Privacy Official & Security Official designation
Names, in writing, the person responsible for your privacy policies and the person responsible for security. In a solo or small SLP practice both are usually the owner.
45 CFR § 164.530(a); § 164.308(a)(2)
The full annotated table of contents, with what each document does and an honest binder-vs-software comparison, is on the HIPAA binder template page.
Pediatric caseloads change who signs
Most private-practice SLP caseloads are largely pediatric, which means the person exercising the client’s HIPAA rights is usually not the client. A parent or guardian generally acts as the minor’s personal representative: they receive and acknowledge the Notice of Privacy Practices, sign authorizations, and can request access to and amendment of the record.
Two complications are worth building into your forms rather than handling case by case. Custody arrangements determine which parent can act, and a practice that never captures that at intake ends up reconstructing it under pressure during a dispute. And state law, not HIPAA, sets when an adolescent controls their own record, which varies and can turn on the type of service.
Both of these are intake-form problems more than policy problems. Capture guardianship and custody status at the start, and your authorization forms will hold up later.
Get the documents done
The SLP binder
Every document above, built to order for your practice, state, and software.
Settle the question first
The covered-entity test, profession by profession, before you buy anything.
Generate your NPP
Build your Notice of Privacy Practices now and see it before you pay.
See a sample first
Real excerpts from a delivered binder, citations included.
Sources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
- studentprivacy.ed.gov/resources/joint-guidance-application-ferpa-and-hipaa-student-health-records
- www.cms.gov/priorities/key-initiatives/burden-reduction/administrative-simplification/hipaa/covered-entities
Last verified August 1, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA or FERPA governs a given record turns on who maintains it and on your actual contracts and billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements.
Every HIPAA document your SLP practice needs, done for you
The complete binder, built to order for your practice and state, with every policy citing the rule that requires it.
See the SLP binder and pricing