⚖️ Compliance & Data Privacy

Does HIPAA Apply to Daycares? What Actually Protects Child Health Records

You hold immunization records, allergy lists, and medication forms for every child in your care. Here's the surprising answer to whether HIPAA covers them — and the rules that actually do.

By Eshan de Silva · · 8 min read

Every childcare director eventually hears some version of this question — from a worried parent, a new staff member, or their own late-night Googling: "Aren't we violating HIPAA?" Maybe an allergy list was posted where a visitor could see it. Maybe a parent objected to being asked for a doctor's note. The word HIPAA gets used as shorthand for "medical privacy," so it feels like it must apply to a building full of immunization records and medication forms. The real answer surprises most people: HIPAA almost certainly does not apply to your daycare — but that doesn't mean child health records are unprotected, or that you're off the hook.

This guide explains why HIPAA usually doesn't cover childcare centers, which rules actually do govern health information in California, and the practical steps that keep allergy lists, medication forms, and immunization records both accessible to the staff who need them and private from everyone who doesn't.

Quick note: This article is general guidance, not legal advice. Privacy rules change and every center's situation is different — confirm specifics with your licensing analyst or attorney before making decisions.

The short answer: HIPAA regulates health care providers, not childcare providers

HIPAA — the Health Insurance Portability and Accountability Act — applies to what the law calls covered entities: health care providers who bill electronically, health plans, and health care clearinghouses, plus the "business associates" that handle health data on their behalf. The U.S. Department of Health and Human Services keeps the definitive list, and a daycare, preschool, or family childcare home isn't on it.

The distinction comes down to what your business does, not what information it holds. A pediatrician's office creates and bills for medical care, so it's a covered entity. Your center receives health information from parents so you can keep children safe — that makes you a recipient of health data, not a regulated health care provider. Once a parent hands you their child's immunization record, HIPAA's rules stopped applying to that copy when it left the doctor's system with the parent's consent.

There are narrow exceptions. A program that operates an on-site health clinic that bills insurance, or certain school-based programs, can pick up covered-entity obligations. And programs funded by the U.S. Department of Education — including some state pre-K and Head Start settings — fall under FERPA instead, which treats health records held by the program as protected education records. But for the typical licensed center in California, HIPAA simply isn't the framework.

"So we can do whatever we want with health records?" Absolutely not

Here's where the question gets practical. HIPAA not applying doesn't create a privacy-free zone — it just means different rules carry the weight:

  • California Title 22 licensing rules. Licensed centers must collect and maintain health documentation for every child — a physician's report (LIC 701), current immunization records, and any medication or special-needs instructions — and keep each child's record complete, current, confidential, and readily available to licensing. Title 22 explicitly restricts who may access a child's file: the parent, licensing staff, and people with a legitimate need. Mishandling records is a licensing issue, and licensing visits happen. The CDSS Child Care Licensing Division is the authority here.
  • California's breach notification law. If unencrypted personal information — a category that includes medical information — is exposed in a breach, you generally must notify every affected family. That's true for a hacked email account, a stolen unencrypted laptop, or a misdirected spreadsheet.
  • FERPA, for some programs. If your program receives federal education funding, health records you hold are typically protected as education records, with parent access and disclosure rules attached.
  • Plain professional duty. Parents trusted you with their child's diagnosis, medications, and developmental notes. Losing that trust costs enrollments no law can give back.

If you want the broader picture of the rules covering all family data at your center — not just health records — our guide to childcare data privacy and Title 22 compliance covers Title 22, COPPA, and FERPA in depth.

The questions that come up every week — answered

"Is asking for a doctor's note a HIPAA violation?"

No. HIPAA restricts what a doctor can release without authorization; it says nothing about what you may request from a parent. In California you're actually required to collect health documentation before enrollment. What can't happen is a pediatrician's office faxing records straight to your center without the parent's written authorization — so when a parent says "just call my doctor," the correct answer is "we'd love to, but they'll need your signed authorization first."

"Can we post allergy lists in the classroom and kitchen?"

Yes — and for safety, you should. The staff preparing snacks or supervising lunch must be able to check a child's allergies in seconds. The privacy move is placement: post lists where staff work, not where visitors, vendors, or other parents linger. A laminated sheet inside a cabinet door beats one taped to the lobby wall. The same logic applies digitally: allergy alerts in your childcare app should be visible to assigned teachers, not to every parent in the class feed.

"Who at our center should see full health files?"

Think in two tiers. Everyone who supervises a child needs the safety essentials: allergies, medications, emergency instructions. Only administrators need the full file — diagnoses, physician reports, family notes. Most modern childcare platforms support role-based access that mirrors exactly this split; it just has to be configured, which is where many centers slip.

Storing health records the right way (paper and digital)

Whatever mix of paper and software you use, the same handful of controls does the heavy lifting:

  • Lock the paper, encrypt the digital. Paper health files belong in a locked cabinet in a staff-only area. Digital files belong in encrypted, access-controlled systems — and every laptop or tablet that touches them needs full-disk encryption turned on. Encryption isn't just good practice: California's breach-notification duty is triggered by breaches of unencrypted data.
  • Multi-factor authentication everywhere. Your childcare software, your email, your cloud storage. Most small-organization breaches start with a stolen password, and MFA stops nearly all of them.
  • Know which devices hold health data. You can't encrypt or wipe a tablet you forgot exists. Keep a simple inventory of every device and what lives on it — a tool like SenAsset tracks your center's devices right inside Microsoft Teams, so "which laptop had the enrollment files?" always has an answer.
  • Back up daily, delete deliberately. Title 22 requires records to be available — a dead hard drive isn't an excuse. And when retention periods end, securely shred or wipe. Old health data you no longer need is pure liability.

If you're still mostly on paper, moving health records into a secure digital system is easier than it sounds — our step-by-step paperless guide for California daycares walks through it. And if configuring encryption, MFA, and role-based access sounds like one more job on an already-full plate, that's exactly the kind of setup EDCON's managed IT services for childcare centers handles for centers across Los Angeles, Oxnard, Ventura, and Azusa.

The 5-minute health-records audit: Where is your allergy list posted — staff-only, or visible to visitors? Is every device holding health files encrypted? Could you name each person who can open a full child file? If any answer is "not sure," you've found this week's to-do.

The bottom line

HIPAA is the wrong worry — but privacy is the right one. Your center isn't a covered entity, so you won't face HIPAA enforcement for how you handle a child's health file. You will, however, answer to California licensing, to the state's breach-notification law, and above all to the families who trusted you. The fix isn't a law degree; it's a locked cabinet, encryption, MFA, sensible access rules, and a team that knows health information is need-to-know. Get those right and the next time someone nervously asks "isn't that a HIPAA thing?", you'll have a better answer: "HIPAA doesn't apply to us — but here's everything we do anyway."

Common questions from childcare directors

Does HIPAA apply to daycare and childcare centers?

Usually not. HIPAA applies to covered entities — health care providers, health plans, and clearinghouses — plus their business associates. A typical daycare is none of those, so it isn't directly regulated by HIPAA even though it holds children's health information. Health records at your center are instead protected by Title 22 licensing rules, California confidentiality and breach-notification laws, and in some federally funded programs, FERPA.

Can a daycare ask parents for a doctor's note or immunization records?

Yes. Asking a parent for health documentation is not a HIPAA violation — HIPAA restricts what doctors can share without authorization, not what you can request from a parent. California licensing actually requires immunization records and a physician's report (LIC 701) before enrollment. A pediatrician just can't send records directly to your center without the parent's written authorization.

How should we store allergy lists and medication forms?

Treat them as need-to-know. Staff who feed or supervise a child need instant access to allergies — that's safety. Full medical files should be limited to administrators. Post allergy lists where staff work but visitors can't browse, keep paper files locked, and make sure digital health records live in encrypted, MFA-protected systems on encrypted devices.

What happens if a child's health information leaks from our center?

Even without HIPAA, California's breach notification law applies: if unencrypted personal information — including medical information — is exposed, you generally must notify affected families, and licensing and reputational consequences can follow. Because the duty is triggered by breaches of unencrypted data, encrypting every device and system that touches health records is your best protection.

Not sure your health records setup would pass a hard look?

EDCON helps California childcare centers lock down family and health data — encryption, MFA, role-based access, and audit-ready record systems. Book a free 30-minute consultation and we'll review your setup, flag any gaps, and give you a clear, no-pressure plan.

Book a Free Consultation