By Audience: K-12 School Officials

The resources on this page are intended for staff and educators of public K-12 schools and school districts.  Resources found here typically address FERPA and how it applies to the various day-to-day operations of public schools at the administrative level.  Guidance is also provided for specific situations that occur only in the K-12 setting.

Best Practices

Malicious Software Data Breach Facilitator Guide

This Malicious Software Data Breach Scenario is an interactive exercise designed to provide participants with the opportunity to experience firsthand the process and pitfalls of responding to a data breach at the organizational level. Over the course of one to two hours, participants explore the scenario of a malicious ransomware incident affecting student information as well as other personally identifiable information (PII) from their organization.

The package includes three parts: Facilitator’s Guide, Presentation, and Exercise Handouts. Please find the additional parts below.

Best Practices

Malicious Software Data Breach Presentation

This Malicious Software Data Breach Scenario is an interactive exercise designed to provide participants with the opportunity to experience firsthand the process and pitfalls of responding to a data breach at the organizational level. Over the course of one to two hours, participants explore the scenario of a malicious ransomware incident affecting student information as well as other personally identifiable information (PII) from their organization.

The package includes three parts: Facilitator’s Guide, Presentation, and Exercise Handouts. Please find the additional parts below.

Best Practices

Malicious Software Data Breach Handouts

This Malicious Software Data Breach Scenario is an interactive exercise designed to provide participants with the opportunity to experience firsthand the process and pitfalls of responding to a data breach at the organizational level. Over the course of one to two hours, participants explore the scenario of a malicious ransomware incident affecting student information as well as other personally identifiable information (PII) from their organization.

The package includes three parts: Facilitator’s Guide, Presentation, and Exercise Handouts. Please find the additional parts below.

Best Practices

Data Breach Scenario Trainings

The Data Breach Scenario Trainings are a series of packaged trainings developed by the Privacy Technical Assistance Center, designed to help educational organizations at all levels conduct internal staff development on data breaches. Each scenario has been developed into a training package, providing ready-to-use resources for the scenario leader(s) and participants.

Guidance

Joint Guidance on the Application of FERPA and HIPAA to Student Health Records

The U.S. Department of Education and the Office for Civil Rights at the U.S. Department of Health and Human Services released updated joint guidance addressing the application of the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule to records maintained on students.