Compliance question
Is ClassDojo HIPAA compliant?
ClassDojo does not say it is, and that is the answer. What it says instead is worth reading closely, because the statutes it does name are the ones people mistake for HIPAA.
What ClassDojo actually claims.
“We are fully compliant with COPPA and FERPA, as well as GDPR in Europe.”
Three statutes, named confidently, and none of them HIPAA. That is not an oversight on a page whose entire purpose is to enumerate compliance. A company that could certify HIPAA and wanted healthcare customers would say so in exactly this sentence, because it is the sentence where it belongs.
Why COPPA and FERPA are not near-misses.
They get treated as adjacent to HIPAA because all three involve sensitive information about children. They are not adjacent. They protect different things, held by different kinds of institution, and satisfying one tells you almost nothing about the others.
FERPA governs education records held by schools.
It attaches to educational agencies and institutions, and the thing it protects is the education record. Its whole architecture assumes a school, a student and a parent with inspection rights. It has nothing to say about a covered entity, a business associate, or a disclosure log, because those are not concepts it contains.
COPPA governs collecting data from children online.
It is a consumer-protection rule about verifiable parental consent before an online service collects personal information from a child under 13. It is a genuinely useful thing to comply with and it is orthogonal to clinical confidentiality. A service can satisfy COPPA perfectly while offering no lawful basis to hold a diagnosis.
GDPR is a European regime, and not a substitute either.
GDPR is a serious framework and compliance with it is a real signal about a company’s data practices. It is not HIPAA, it does not create a business associate relationship, and a US clinic’s obligations under HIPAA are not discharged by a vendor’s European posture.
HIPAA is the one that applies to you, and it needs a contract.
If your clinic bills a health plan for a prescribed treatment you are a covered entity, and a vendor that stores your parent messages is handling protected health information as a business associate. That relationship has to be papered. Strong security is not the same thing as a signed BAA, and only one of them is a legal requirement.
The design problem sitting underneath.
Even with paperwork, ClassDojo organises around a class: a group of children moving through a shared day, with one adult, on a routine that repeats. Your caseload is a stack of individual sessions, each a named child with a named technician for a bounded block, on a schedule that changes when somebody calls out.
The consequence a clinic feels first is scoping. In a classroom tool, posting to the room is the natural action; in a clinic, every update belongs to exactly one family and must reference no other child in any form. We worked through that mismatch, and what to look for in a tool that does sign a BAA, on classroom apps in an ABA clinic.
Questions clinics ask about this.
Is ClassDojo HIPAA compliant?
ClassDojo makes no HIPAA claim. Its privacy and security page states that it is fully compliant with COPPA and FERPA, as well as GDPR in Europe. Those are the frameworks for education records and for children’s online privacy, not for protected health information, and the absence of any HIPAA statement on a vendor’s own compliance page is the practical answer for a covered entity.
Does ClassDojo sign a business associate agreement?
We have found no offer of a BAA in ClassDojo’s published privacy and security documentation. What ClassDojo offers schools and districts is a student data privacy agreement, which is the education-sector equivalent and covers a different statute. Ask the vendor directly and get the answer in writing rather than relying on this page.
ClassDojo has SOC 2. Is that not enough?
SOC 2 is a real audit of security controls and it is worth having, but it is a security attestation rather than a healthcare one. It says a company operates the controls it claims to operate. It does not make the company willing to act as your business associate, and it does not create the contract HIPAA requires. Plenty of SOC 2 vendors will not touch PHI.
Our clinic runs a social-skills group that feels like a classroom. Does that change it?
No. The test is whether your organisation is a covered entity and whether the information is protected health information, not whether the activity resembles teaching. A social-skills group inside a clinic billing insurance is still a prescribed treatment, and a note about how a child managed it is still clinical content.
Is ClassDojo a bad product?
No, and this page is not an argument that it is. ClassDojo is well built for the job it was designed for, and its compliance statements are clear rather than evasive, which is more than can be said for parts of this category. The mismatch is that an ABA clinic is not a classroom, in law or in data model.
Related
Sources
Every claim about another product on this page is a quote from that product’s own documentation, linked below with the date we last read it there. Vendors revise these pages. If you find one of these out of date, tell us and we will correct it.
- [1] ClassDojo — Privacy and Security · checked August 26, 2026
Show us what you are using now.
Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.