FERPA-Compliant LMS Migration & Hosting
For school administrators and healthcare training managers who need the technical work done right — and documented well enough to hand to an auditor.
The regulation, plainly
What FERPA actually requires of an LMS vendor
FERPA never mentions learning management systems. It was written in 1974, before the first email crossed a campus network. What it regulates is the disclosure of education records — and the moment an outside company hosts, migrates, or maintains your Moodle™ site, a disclosure is happening.
The lawful path for that disclosure is the school-official exception, 34 CFR § 99.31(a)(1)(i)(B). It lets an institution share education records with a contractor without individual consent only when three things are true:
- The vendor performs a service the school would otherwise use its own employees for.
- The vendor is under the direct control of the school with respect to the use and maintenance of the records.
- The vendor uses the records only for the authorized purpose and does not re-disclose them.
"Direct control" is the load-bearing phrase. A vendor you cannot audit, cannot instruct, and cannot compel to delete your data is not under your direct control — no matter what their marketing page claims. In practice, direct control means one thing: a written data processing agreement that spells out who touches the data, for what purpose, and when it gets destroyed.
The other requirement people gloss over is data minimization. A migration engineer needs mdl_user, the grade tables, and your course content. They do not need Social Security numbers — and Moodle shouldn't be storing those anyway. If your legacy site has them stuffed into custom profile fields (we've seen it), the migration is exactly the right moment to purge them rather than copy them forward.
There is no FERPA certification. Anyone selling you one is selling you a badge.
Book a free compliance-aware migration review
20 minutes, no pitch deck. We reply within 1 business hour.
K-12 and under-13 learners
What changes when learners are minors
If your learners are under 13, COPPA sits on top of FERPA — and the FTC's 2025 amendments to the COPPA Rule (effective June 23, 2025) raised the bar in three ways that matter for an LMS:
- Documented, verifiable consent. Consent has to exist as a record you can produce, and disclosing children's data to third parties now requires its own separate opt-in — it can't ride along inside a general terms-of-service checkbox.
- A written retention policy. Indefinite retention is explicitly off the table. You need a stated window for how long children's data is kept and a process that actually deletes it.
- Agreements with every vendor in the chain. Not just the LMS company. The hosting provider underneath them. The plugin that sends analytics somewhere. All of it.
"Every vendor in the chain" is the part districts miss, because in a Moodle site the chain is invisible until you look. A free plugin that loads assets from an external CDN or phones telemetry home is a vendor. On K-12 engagements we inventory every installed plugin's outbound connections and hand you the list, so your DPA coverage matches what the software actually does — not what you assumed it does.
This is tedious work. That's why most shops skip it.
Our process
What we do differently on regulated migrations
Every LMS migration we run carries a zero-data-loss guarantee with byte-for-byte row-count verification. On FERPA- and COPPA-scoped projects, we add the controls an auditor will ask about.
- ✓Signed DPA before we touch anything. Our data processing agreement template is ready for your counsel to mark up — deletion schedule, breach notification, sub-processor terms, the school-official language.
- ✓Named-personnel-only access. The engineers on your project are listed in the DPA by name. Nobody else gets credentials. No offshore queue, no "the team."
- ✓Encrypted transfer, end to end. Database dumps move over SSH only. Never email, never a shared drive, never a thumb drive. Staging copies sit on encrypted volumes.
- ✓Access logging. Every session against your data is timestamped and logged, and the log ships with the final deliverable. If someone asks "who accessed student records in March," you have the answer in writing.
- ✓Defined retention window. Staging copies are destroyed 30 days after your acceptance sign-off — or on your schedule — and we confirm destruction in writing.
- ✓Grade history preserved, provably. Our verification report covers
mdl_grade_grades_historyandmdl_scorm_scoes_trackrow counts, not just course counts. If we miss anything, we fix it free.
Regulated migrations start at the same published prices as everything else: from $1,200 for small sites, $2,500–$4,500 mid-size. The compliance controls above aren't an upsell — they're how we work. See full pricing.
Book a free compliance-aware migration review
We reply within 1 business hour — or call (615) 396-7139.
Healthcare training
Your SCORM completion data is your Joint Commission evidence
When a surveyor asks you to prove a nurse completed restraint training in 2023, the proof is not the course. It's the attempt data: rows in mdl_scorm_scoes_track recording cmi.core.lesson_status, the score, and the timestamp. HIPAA's documentation rule (45 CFR 164.316(b)(2)) expects records like these kept for six years.
Here's the failure mode we get called in to fix: a vendor migrates the LMS by re-importing the SCORM packages and rebuilding enrollments. The courses look fine. The completion history is gone — because carrying attempt data across a migration means remapping SCO identifiers between Moodle versions, and that's fiddly, unglamorous work. The site launches, everyone celebrates, and eighteen months later a survey turns up a hole where three years of training evidence used to be.
We migrate attempt data as a first-class deliverable and verify it row for row. And if your tracking is already broken — completions not recording, statuses stuck at "incomplete" — that's a separate, cheaper fix: SCORM tracking repair is $350 flat per package, diagnosed and verified in SCORM Cloud.
One more thing worth knowing: if you're still on Moodle 4.1 or 4.4, both fell out of security support on December 8, 2025. Unpatched software holding six years of workforce training records is not a position you want to explain to a compliance officer. Moodle 4.5 LTS is supported into October 2027 — that's where we move regulated sites, and our managed hosting (from $79/mo) keeps the patching off your plate.
Honest boundaries
We are engineers, not lawyers
We implement; your counsel approves. We will not tell you whether your consent workflow satisfies COPPA or whether your DPA language holds up in your state — that's a legal judgment, and pretending otherwise would be malpractice with extra steps. What we do: build the technical controls, document them, and hand your attorney a DPA template with the engineering facts already filled in. It's a division of labor that works, and it's cheaper than having a law firm learn what mdl_grade_grades_history is.
If you want ongoing compliance attention rather than a one-time migration, our Premium care plan ($599/mo) includes a standing FERPA review alongside five monthly dev hours. And if you just want to talk through where you stand, the free review below is genuinely free — plenty of people take the checklist and do the work themselves. That's fine with us.
Common questions
FERPA-compliant LMS: questions we actually get
Is Moodle FERPA compliant?
Moodle is software; FERPA compliance is a property of the whole arrangement — who hosts it, how it's configured, and what your contract says. A self-hosted or properly managed Moodle site can absolutely sit inside a compliant setup, and Moodle's granular roles and logging actually make the technical side easier than most commercial platforms. But no platform is compliant out of the box, and no platform can be "certified."
Do we really need a DPA with a small vendor like you?
Yes — arguably especially with a small vendor. The school-official exception requires you to have direct control over how we use and maintain your records, and the only way to demonstrate that is a written agreement. We'd be suspicious of any vendor who shrugs this off. Our template is ready for your counsel on day one.
What happens to our data after the migration is done?
Staging copies are destroyed 30 days after your acceptance sign-off (or a window your policy dictates), and we confirm the destruction in writing. Nothing is retained for "reference." The access log covering the entire engagement ships with your final deliverable.
Does FERPA require our student data to stay in the US?
FERPA itself is silent on data location — but many state student-privacy laws and most district procurement policies are not. Our staging infrastructure is US-based and the named engineers on regulated projects are US-based, so the question doesn't come up. If your policy requires it in writing, it goes in the DPA.
Can you sign a BAA for HIPAA?
Usually you don't need one: records of workforce HIPAA training — who completed which module, when, with what score — are training records, not protected health information. If your LMS stores actual PHI (some patient-education setups do), tell us up front; that changes the scope, and we'll assess honestly whether a BAA applies rather than signing paper that doesn't fit the facts.
Twenty minutes, and you'll know where you stand
Bring whoever owns compliance — we'll walk your current setup, flag the gaps (plugin data flows, retention, attempt-data risk), and tell you plainly whether you need us or an afternoon of your own admin's time. Migrations from $1,200 with the zero-data-loss guarantee and 30 days of post-move support.
Book a free compliance-aware migration review
We reply within 1 business hour. Sternfast is based in Nashville and works with schools and healthcare teams US-wide.