Compliance Guide
Video Surveillance
Compliance Requirements
HIPAA, FERPA, cannabis state regulations, NDAA Section 889, FFIEC, and HOA privacy law — compliance requirements for cloud surveillance by industry.
Direct Answer
What compliance requirements apply to video surveillance?
Video surveillance compliance depends on your industry. Key frameworks: HIPAA (healthcare — access logs retained per your risk analysis — typically 3–6 years per 45 CFR §164.312), FERPA (schools — student footage is an education record), cannabis state regulations (30–90 day mandatory retention), and NDAA Section 889 (prohibits specific camera brands for federal contractors).
- ✓HIPAA: encryption + role-based access + BAA with VMS provider required
- ✓Cannabis: state-specific retention (30–90 days) + inspector access within 24–48 hours
- ✓NDAA §889: Hikvision and Dahua prohibited for federal use — not for private businesses
Compliance Requirements by Industry
HIPAA — Healthcare
- ✓AES-256 encryption in transit and at rest
- ✓Role-based access: only authorized staff can view footage
- ✓Audit log of all footage access events, retained per your risk analysis — typically 3–6 years per 45 CFR §164.312
- ✓Business Associate Agreement (BAA) with VMS provider
- ✓No footage of patients in treatment without policy safeguards
FERPA — Schools & Universities
- ✓Footage identifying students in disciplinary contexts = education record
- ✓Access limited to authorized school officials only
- ✓Law enforcement sharing requires court order or emergency exception
- ✓No student facial recognition without consent framework
- ✓Retention policies aligned to district student records policy
Cannabis — State Regulations
- ✓California DCC: 90-day minimum retention, HD coverage of all areas
- ✓Colorado MED: 40-day minimum, 24-hour inspector access
- ✓Oregon OLCC: 30-day minimum, all licensed premises covered
- ✓Nevada CRA: 30-day minimum, all points of sale covered
- ✓Footage must be available to regulators within 24–48 hours
NDAA Section 889 — Defense & Federal
- ✓Prohibits: Hikvision, Dahua, Hytera, Huawei, ZTE for federal use
- ✓Applies to: federal agencies and federal contractors/subcontractors
- ✓Does NOT apply to private businesses without federal contracts
- ✓iFovea platform is NDAA-compliant (software platform, not hardware)
- ✓For defense-adjacent deployments: audit camera brands against prohibited list
FFIEC — Banks & Financial Institutions
- ✓No federal mandate on surveillance retention duration for banks
- ✓FFIEC guidance: 90 days recommended for incident investigation
- ✓Teller-area and vault coverage expected for insurance and audit purposes
- ✓Access logs for who viewed surveillance footage — audit trail
- ✓Multi-branch cloud VMS allows centralized compliance documentation
HOA & Residential — Privacy Law
- ✓No federal surveillance law for HOAs — state law governs
- ✓Illinois BIPA: biometric data (facial recognition) requires written consent
- ✓California CCPA: residents may have right to know about footage use
- ✓Flock Safety law enforcement data sharing: a specific HOA governance concern
- ✓HOA boards: establish written surveillance policy and resident notice
Does iFovea meet your compliance requirements?
Talk to an iFovea specialist about your specific regulatory context — HIPAA BAA, audit log configuration, or cannabis retention setup.
Video Surveillance Compliance FAQ
Is video surveillance HIPAA compliant?
Video surveillance can be HIPAA compliant when configured correctly. Required controls: AES-256 encryption in transit and at rest, role-based access limiting footage access to authorized personnel only, audit logs of every access event retained for a period defined by your security risk analysis — typically 3–6 years per 45 CFR §164.312, and a signed Business Associate Agreement (BAA) with the VMS provider if the system captures any Protected Health Information. The VMS platform does not automatically confer HIPAA compliance — the configuration and BAA do.
What are the video surveillance requirements for cannabis dispensaries?
Cannabis dispensary surveillance requirements vary by state but share common elements: mandatory camera coverage of all sales areas, vault/storage rooms, point-of-sale, and entrances/exits; minimum retention of 30–90 days (California DCC requires 90 days; Colorado MED requires 40 days); footage must be accessible to state inspectors within 24–48 hours of request; and HD resolution requirements (typically 720p minimum). State-specific requirements from CA DCC, CO MED, OR OLCC, and NV CRA supersede general guidelines.
Does NDAA Section 889 prohibit Hikvision cameras?
NDAA Section 889 (National Defense Authorization Act) prohibits federal agencies and federal contractors from purchasing equipment from Hikvision, Dahua, Hytera, Hua Wei, and ZTE. The prohibition applies to federal government use and federal contractors — not to private businesses, unless you hold federal contracts. Private retail, healthcare, and commercial businesses are not restricted by NDAA Section 889 from using Hikvision or Dahua cameras.
What are FERPA requirements for school video surveillance?
FERPA (Family Educational Rights and Privacy Act) restricts disclosure of “education records” including video footage that identifies students. Key requirements: surveillance footage of students is generally an education record if used for disciplinary purposes; footage must be accessible only to authorized school officials; footage shared with law enforcement requires parental consent or a court order (except in health/safety emergencies). General campus surveillance footage that is not tied to specific student identity is not typically a FERPA education record.
What is the minimum video retention period for regulatory compliance?
Minimum retention periods by regulation: HIPAA access logs — 6 years. Cannabis (California DCC) — 90 days. Cannabis (Colorado MED) — 40 days. Cannabis (Oregon OLCC) — 30 days. Banking (FFIEC) — 90 days recommended for incident investigation. Schools — no federal minimum; local policy typically 30–60 days. HOA/residential — no federal requirement; state privacy law may limit maximum retention. Most businesses use 30-day retention as a general baseline.
Compliant Cloud Surveillance for Your Industry
iFovea supports HIPAA, FERPA, cannabis retention requirements, and NDAA-compliant camera configurations. Contact us to discuss your regulatory context before deployment.
