HIPAA and FERPA Data Practices.
Which rules apply in a healthcare setting, which apply in a school, and who is responsible for what.
SSG Management supports healthcare and educational organizations, but the legal rules that apply depend on the setting, the type of record, the parties' roles, and the written agreement.
Healthcare Settings
When SSG Management receives protected health information on behalf of a HIPAA-covered entity or business associate, SSG Management acts under the applicable business associate agreement. SSG Management uses and discloses that information only as permitted by the agreement, the covered entity's instructions, and applicable law. The healthcare organization is responsible for its Notice of Privacy Practices, clinical decisions, patient-rights process, medical-record obligations, and determinations about treatment, payment, and healthcare operations.
Educational Settings
When SSG Management maintains education records for a school or educational agency, it acts under the school's instructions and applicable agreement. When the school relies on FERPA's school-official exception, the school must determine that SSG Management performs an institutional service, is under the school's direct control concerning the use and maintenance of education records, meets the school's criteria for a school official with a legitimate educational interest, and uses records only for the authorized purpose. The school remains responsible for notices, access and amendment requests, consent determinations, recordkeeping, and re-disclosure rules.
Minimum Necessary Access and Safeguards
Access should be limited to personnel who need the information for an authorized role.
Organizations should provide only the information reasonably needed for the configured workflow.
Credentials may not be shared, and access must be removed when a user's role ends.
Suspected unauthorized access, disclosure, loss, or security incidents must be reported promptly through the organization's designated process and to SSG Management.
Subcontractors that handle regulated information must be subject to appropriate privacy and security obligations.
Records must be returned, deleted, or retained at the end of services as required by the governing agreement and law.
Limits of This Notice
This notice does not replace a healthcare provider's Notice of Privacy Practices, a school's annual FERPA notice, a business associate agreement, a data-sharing agreement, or a program-specific consent form. Those documents control within their scope.
Ask a person.
Privacy, consent, accessibility and legal questions go to Sara@ssgwellness.com. Anything else, info@ssgwellness.com.
SSG Management LLC is in Canton, Texas.
Don't use these for an emergency. Call 911 or go to the nearest emergency department. In the United States, call or text 988 for suicide or crisis support.
