Skip to main content

HIPAA at SLU

Saint Louis University’s Health Information Privacy compliance program is implemented to support sound health care practices, protect the privacy of health information, and fulfill the University’s legal obligations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), including its implementing regulations at 45 CFR Parts 160 and 164 (“Privacy Rule”), as amended, and Missouri state laws.

As a designated hybrid entity, the University applies HIPAA requirements to its defined health care components, which operate as covered entities under the law. SLU takes reasonable steps to ensure the confidentiality, integrity and availability of protected health information (PHI), in accordance with HIPAA and any applicable state laws that provide greater protections.

At SLU, the rules governing health-related information depend on the University component maintaining the information, the purpose for which it is maintained, the source of the information, and applicable law. Health-related information may include PHI maintained by or on behalf of a University Covered Component, research health information (RHI) maintained in a research record or research environment, FERPA-protected student records, employment records, or other health-related information protected by contracts, University policy, and applicable law. Use the decision tree below to determine your data's status and your compliance obligations.

Please note: As of July 1, 2022, SSM Health handles SLUCare-specific HIPAA issues. For patient privacy concerns related to SLUCare, please contact the SSM Ethics and Compliance Helpline at 877-427-7275.

Student Health Privacy at SLU

Student health information at Saint Louis University is governed by the Family Educational Rights and Privacy Act (FERPA) and Missouri state law, not HIPAA. This is due to a required exception in HIPAA’s privacy rule. The University complies with FERPA and applicable state laws to protect student health information, which may differ in scope and requirements from HIPAA.

HIPAA Hybrid Entity Designation

As part of the University’s education mission, SLU has components whose activities include health care provider functions covered by HIPAA as well as many functions unrelated to the provision of health care. To focus its compliance efforts, the University is designated as a hybrid entity. This means HIPAA applies only to certain clinical components of the university that function as "health care components."

SLU’s health care components are:

For a current list of these components, please refer to the official HIPAA hybrid policy.

The Student Health Center and Physical Therapy Clinic are not designated University Covered Components. Their operational practices are informed by HIPAA privacy and security principles, but their records are governed by the legal and institutional requirements applicable to those settings.

Research and Health Privacy

RHI may include information created or received in research that does not involve a University Covered Component. It may also include information lawfully disclosed for research from a University Covered Component or external covered entity through an authorization, waiver or alteration of authorization, limited data set arrangement, de-identification or another permitted mechanism.

SLU distinguishes between PHI maintained by or on behalf of a University Covered Component and health-related information maintained in a separate research record or research environment. SLU researchers may receive health information from a University Covered Component, SSM Health, or another covered entity through a valid HIPAA disclosure mechanism. Once lawfully disclosed and maintained in a research environment where it is not maintained as PHI by or on behalf of a University Covered Component, the research copy becomes RHI. The source clinical copy remains PHI.

PHI remains subject to HIPAA while it is maintained by or on behalf of a University Covered Component in a covered capacity. A valid HIPAA pathway must support any disclosure of PHI for research. The separately maintained research copy may become RHI when it is not maintained as PHI by or on behalf of the Covered Component

HIPAA and Research: Understanding the Hybrid Entity

As a Carnegie R1-research institution, Saint Louis University thrives on global collaboration. Our hybrid entity structure is designed to facilitate these high-level partnerships by providing a clear framework for data sharing. This ensures that while our research mission expands, our clinical data remains protected under the highest regulatory standards.

  • Clinical care (covered): Within a covered component, as defined above (in the HIPAA hybrid policy), the data is protected health information (PHI) and governed by HIPAA.
  • Research (non-covered): Most university research happens in "non-covered components." When a researcher receives health information from a clinical provider through a valid HIPAA disclosure mechanism, the separately maintained research copy may become RHI. The clinical copy held by the provider remains PHI. RHI remains protected by applicable research approvals, consent or authorization terms, contracts, University policy, information security requirements and applicable law. Although RHI is not subject to the HIPAA privacy rule, it is strictly confidential. It is protected by:
    • The Common Rule
    • IRB Protocols
    • SLU data security standards
    • Contractual agreements (data use agreements)
  • Administrative and academic functions (non-covered): Most routine university operations (including teaching, advising, human resources, student services, general administration and academic programs, etc.) are not HIPAA-covered functions. These activities operate outside the HIPAA framework but remain subject to SLU policies, FERPA (where applicable), and SLU’s data security standards.

Mishandling RHI

While not a HIPAA violation, losing or disclosing RHI outside approved protocol is a serious "protocol non-compliance" and may result in IRB suspension or loss of research privileges. Report any suspected loss, unauthorized access, use, or disclosure of RHI to the University Privacy Office and the applicable research oversight office. The University will assess the applicable IRB, contractual, security, privacy, and legal requirements.

Is My Research Data HIPAA-Protected?

Step 1: Determine the Unit Status

Is the specific SLU unit/department conducting the research designated as a university health care component (UHCC) (e.g., Center for Advanced Dental Education, Psychology Clinic, Center for Autism Services, Medical Family Therapy Clinic)?

  • YES: Determine whether the information is maintained by or on behalf of the Covered Component as part of its covered clinical function. If so, the information is PHI. If the information was lawfully disclosed for research and is maintained separately in a research environment where it is not maintained as PHI by or on behalf of the Covered Component, the research copy may be RHI.
  • NO: (e.g., School of Medicine, College of Arts and Sciences, Doisy Research Center). Proceed to Step 2.
Step 2: Determine the Activity Function

Does the research activity itself involve a "covered function"? (Specifically: Are you or is SLU billing a health insurance plan or clearinghouse electronically for research-related procedures?)

  • YES: Stop. HIPAA applies. Note: This is a rare, high-risk scenario. Consult the privacy office immediately.
  • NO: Proceed to Step 3.
Step 3: Determine the Data Source

Does the research involve obtaining health data from an external HIPAA covered entity (e.g., SSM Health, a hospital or a private clinic)?

  • Path A: Yes (Data from external source)
    • Requirement: This requires a HIPAA Authorization (or Waiver of Authorization) to release the data for research.
    • Status change: The external covered entity must use a valid HIPAA disclosure mechanism before releasing the information for research. Once lawfully disclosed and maintained by SLU in a research record or research environment where it is not maintained as PHI by or on behalf of a University Covered Component, the SLU research copy becomes RHI. The source copy at the external covered entity remains PHI.
    • Result: The data becomes research health information (RHI).
    • Action: Protect the information as RHI under the applicable IRB protocol, consent or authorization terms, data-use agreement or other contract, University privacy and security requirements, and applicable law. A Business Associate Agreement is not required.
  • Path B: No (Direct collection)
    • Context: You are collecting study data directly from participants (e.g., surveys, interviews, blood draws in a research lab) without billing insurance.
    • Result: HIPAA does not apply. The data is research health information (RHI).
    • Action: Use the standard research consent/authorization form. Protect as sensitive PII/RHI.

Training

The University provides comprehensive HIPAA training for all workforce members who handle PHI. To request training, please contact the Compliance Office at compliance@slu.edu.

Health Privacy Policies and Forms

All other health privacy policies are available to the SLU community on PolicyStat.

Health Privacy and HIPAA Resources and Support

For questions, comments or concerns about health privacy-related policies and procedures at SLU, please email compliance@slu.edu or hipaa@health.slu.edu.