Header logo
3.9.2

Student Affairs and Services: Student records
 

The institution protects the security, confidentiality, and integrity of student records and maintains security measures to protect and back up data.


Judgment
Judgment Unchecked Icon  Compliance    Judgment Unchecked Icon  Partial Compliance    Judgment Unchecked Icon  Non-Compliance    Judgment Unchecked Icon  Not Applicable

Off-site Committee Comments

The University of Alabama Birmingham provided strong evidence that it complies with federal laws that govern the protection and confidentiality of student information related to the Family Educational Rights Privacy Act (FERPA). Those faculty and staff at the University needing access to student records are required to participate in FERPA training via an online course, take an online test demonstrating understanding of the policies, and acknowledge and accept a security warning statement. The University has appropriate security measures and backup systems through the Alabama Supercomputer Authority and maintains all records with integrity in accordance with the Public Universities of Alabama Functional Analysis and Records Disposition Authority (RDA). Regular data backups are conducted to protect records and, further, all data is transmitted in either an encrypted or encoded manner for further protection.


While patient records are included as a category of student records in the University’s Records Retention Policy, there is no evidence of HIPAA compliance related to the security, confidentiality, and integrity of these records.
 

Institutional Response

 

The UAB Records Retention Policy addresses a wide range of records generated, received, or maintained by the institution, which have been divided into ten categories:

Administrative

Athletics

Student Education

Fiscal

Legal

Personnel

Public Relations

University Police

Conducting Research

Patient Records

 

Although student educational records and patient records are both addressed by the policy, each type of record is distinct in terms of retention and access. Patient records are not a category of student records. 

 

Furthermore, the UAB Student Records Policy defines the educational record as "any records, files, documents, and other materials that contain information directly related to a student and which are maintained by UAB or a party acting for UAB." This policy specifically excludes documentation related to a treatment of a student from his/her education record.   

 


 
Site Map | The University of Alabama at Birmingham Home Page Powered by Compliance Assist