The Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g and 34 CFR Part 99, is a US federal law that protects the privacy of student education records. It applies to schools, districts, colleges and universities that receive funding from the US Department of Education.
Schools often need to send and sign documents that contain student information, such as transcripts, enrollment forms, financial aid documents and Individualized Education Programs (IEPs). Fax.Plus and Sign.Plus help your institution handle these documents securely.
Good to know: FERPA applies to educational institutions, not directly to software providers. There is no official FERPA certification for vendors. When a school uses a service like Fax.Plus or Sign.Plus for student records, the school's FERPA obligations are addressed through the agreement between the school and the provider. For Alohi, this is our FERPA Addendum.
What FERPA protects
FERPA protects education records: records directly related to a student that are maintained by an educational institution or by a party acting on its behalf.
Schools generally need written consent from a parent or eligible student before disclosing personally identifiable information (PII) from education records, unless an exception applies.
How FERPA applies to service providers
The exception most relevant to cloud services is the school official exception (34 CFR § 99.31(a)(1)(i)(B)). It allows a school to share education records with an outside provider without consent, as long as the provider:
- Performs a service or function the school would otherwise use its own employees for
- Is under the direct control of the school regarding the use and maintenance of the records
- Uses the records only for the purpose they were shared for
In practice, schools meet these conditions through a written agreement with the provider. With Alohi, this agreement is our FERPA Addendum.
How Alohi helps you protect student records
Encryption in transit
Data moving between our apps (web, mobile and API) and our servers is protected with TLS 1.2 or higher. Please note that the final leg of a fax, the call placed to the recipient's fax number, travels over the telecom carrier's network rather than Alohi systems.
Encryption at rest
All stored documents are encrypted with 256-bit AES, with a unique encryption key for each user.
Access control
Protect accounts with two-factor authentication, and use role-based permissions so only authorized staff can access documents containing student information. Enterprise teams can also enforce 2FA for every member and sign in with SAML SSO.
Audit trails
Keep a record of documents sent, received and signed, with timestamps and delivery confirmations, to support internal reviews and audits.
Retention controls
In Fax.Plus, you can set a document retention period so faxes are permanently purged after the number of days you choose, helping you keep student records only as long as you need them.
Requirements for FERPA coverage
To use Fax.Plus or Sign.Plus for student records, your institution needs:
- A signed Alohi FERPA Addendum. The addendum must be signed before you send any student records through our services.
- An Enterprise plan with Advanced Security Controls enabled. The FERPA Addendum is available on our Enterprise plan only, and FERPA coverage applies only while Advanced Security Controls stay turned on for the covered accounts.
Good to know: Accounts that are not listed in your FERPA Addendum, or that do not have Advanced Security Controls enabled, are not covered and should not be used for student records.
How to request the FERPA Addendum
The FERPA Addendum can be requested by an Admin of an Enterprise account. To request it, please contact our support team and include:
- Your institution's name
- The state your institution is located in
- The product(s) you want covered (Fax.Plus, Sign.Plus)
- The account(s) you want covered, listed by account email address
Our team will prepare the addendum and send it to you for signature.
Best practices for your team
- Use only accounts covered by your FERPA Addendum for student records.
- Keep Advanced Security Controls enabled on all covered accounts.
- Enable two-factor authentication for every user.
- Limit access to student records to staff who need it for their role.
- Double-check the recipient's fax number or email address before sending.
- Review your retention settings and delete documents you no longer need.
- Train staff on handling student information in line with your institution's FERPA policies.
Related articles
This article is for general information only and does not constitute legal advice. Please consult your own legal or compliance advisers about your obligations under FERPA and applicable state student data privacy laws.