How is AI and performance technology being used in college athletics?
It is already in routine use, mostly to support training and health decisions rather than to replace them. NCAA guidance on performance technologies describes tools such as wearables, cameras, sensors, and apps or software that collect biometric and performance data, and asks institutions to consider privacy, mental health, informed consent, and data security when they use them.[1]
In December 2025, the NCAA Committee on Competitive Safeguards and Medical Aspects of Sports approved guidance recommending that institutions maintain a written plan for responsible performance-technology use, covering education, data management and protection, purchasing and implementation, and continuous improvement.[2] The practical signal in that list is ordinary operations. A written plan, a purchasing process, and a review cycle are operating documents, not technical ones.
Layered on top of the collection tools are analytics and AI systems that turn raw measurements into something easier to act on: a readiness figure, a load recommendation, an injury-risk flag, a comparison against a normative range. That translation step is where most of the unanswered questions live, because an inference is a new piece of information about the athlete that no one explicitly agreed to create.
What kinds of athlete data can these systems collect?
More categories than a single office usually tracks. In a typical department, athlete information can include academic and eligibility records, athletic training and treatment notes, physician or hospital records, wearable and sensor output, video and tracking data, self-reported wellness responses, communications inside an athlete-management platform, and any derived score or flag a vendor system produces.[1]
These categories are not interchangeable. They were created by different people, for different purposes, under different agreements, and they may be governed by different rules. Treating them as one undifferentiated pool of athlete data is the most common source of confusion when someone finally asks who can see what.
Is a college athlete’s health information always protected by HIPAA?
Not automatically. Federal guidance indicates that most records held by a postsecondary student health clinic fall under FERPA rather than HIPAA, depending on the context, and that treatment records carry a specific FERPA definition.[4] Separately, patient records created by a university hospital may be HIPAA-covered when the hospital’s services are not provided on behalf of the educational institution.[5]
The operating consequence is that two records about the same athlete, describing the same injury, can sit under different frameworks depending on who created them and in what capacity. Staff cannot resolve that from memory in the middle of a season. It has to be written down in advance, with the categories named and a person identified for each one. Which framework applies to a specific record is a legal determination for counsel, not a judgment call for a coach or an analyst.
What can happen to education records when an athlete transfers?
FERPA permits a school to disclose education records to another school where the student seeks or intends to enroll, subject to conditions.[6] Permitted is not the same as automatic, and it does not extend to every category of information a department holds. A permission that applies to education records says nothing about a wearable vendor’s database or a third-party analytics platform.
So the honest answer to the title question is that ownership is the wrong first question. The useful questions are narrower: which record is this, who created it, what agreement governs it, who is authorized to send it, what does the receiving institution actually need, and what stays behind.
Why can an athlete’s information be spread across multiple systems?
Because systems arrive one purchase at a time. A wearable is adopted by strength and conditioning. An athlete-management platform is bought by sports medicine. An academic system belongs to the institution. A analytics contract is signed by a single sport. Each was a reasonable decision on its own, and none of them was a decision about the whole picture.
The result is that no one person can answer a simple question, and the answer changes when a vendor contract is renewed or replaced. This is an operating-structure problem before it is a technology problem, which is why the NCAA guidance pairs data management and protection with purchasing and implementation rather than treating them separately.[2]
What has the NCAA said about transfer-related medical-information sharing?
In February 2026, CSMAS discussed an increasing burden on sports medicine staffs related to transfer student-athletes and the sharing of medical information, and noted that it is considering transfer-athlete education and updates to consent to share private information, with HIPAA and FERPA in mind.[3]
That is a discussion of workload and consent mechanics rather than a finished rule, and it should not be read as one. Its value to an institution is confirmation that the friction is real and structural: the people absorbing it are clinical staff, and the fix involves consent language, athlete education, and a documented procedure.
Why do women athletes require careful evidence and validation?
Because a model or normative range is only as applicable as the population it was built on. Stanford’s FASTR program explicitly identifies females as underrepresented in current sports-science research and exists to address that gap.[7]
That supports a readiness question rather than a conclusion: does the evidence base behind this technology adequately represent the athletes it is being applied to? At Resilience Ventures LLC we ask that deliberately, including who may be missed when a system is built on incomplete evidence, whether that is women, athletes of color, or athletes in resource-constrained environments. That is an evidence and validation question to put to a vendor, not a claimed research finding about any particular product.
What questions should institutions ask before collecting or expanding athlete data?
We use one sequence to review an athlete-data system end to end. It follows the information rather than the org chart, which is what makes the gaps visible. It is an operational review framework, not a legal-compliance framework, and it does not certify compliance with any law, regulation, or association rule.
Collect → Access → Infer → Decide → Share → Retain → Transfer → Delete
- Collect
- What information is gathered, by which system, and for what stated purpose?
- Access
- Who can see it, in what role, and how is that access reviewed?
- Infer
- What score, flag, or recommendation is produced from the raw data?
- Decide
- Which decisions use that output, and who is the named human reviewer?
- Share
- Who receives it outside the original system, and under what agreement?
- Retain
- How long is it kept, on whose authority, and where is that written down?
- Transfer
- What happens to each category when an athlete moves, or when a vendor contract changes?
- Delete
- What is actually removed, from every copy, and who confirms it?
What does responsible athlete-data readiness look like?
It looks unglamorous. A written inventory of systems and the categories each one holds. A purpose stated for every category. Access defined by role and reviewed on a date. A named human reviewer for any output that informs a decision about an athlete’s health, playing time, or opportunity. Plain-language explanation to athletes of what is collected and what choices they have. Retention periods someone owns. A transfer procedure that names each category rather than referring to athlete data as a single thing. And a vendor-change procedure, because contracts end.[2]
None of that requires a new platform. It requires decisions to be written down, assigned, and reviewed, which is the work departments most often postpone because no single role owns it.
General information boundary
This brief is general information. Resilience Ventures LLC does not provide legal, medical, privacy, cybersecurity, NCAA compliance, or return-to-play advice, and does not certify compliance with any law, regulation, or association rule. Those decisions remain with qualified professionals and authorized institutional staff. Cited sources are summarized as published; readers should consult them directly.
Frequently asked questions
- Does HIPAA always protect college athlete health records?
- No. Coverage depends on context. Federal guidance indicates that most postsecondary student health clinic records fall under FERPA rather than HIPAA, while records created by a university hospital may be HIPAA-covered when those services are not provided on behalf of the educational institution. The correct answer for a specific record depends on who created it and in what capacity.
- Does all athlete data automatically transfer to a new school?
- No. There is no single automatic rule that moves every category of athlete data to a new institution. FERPA permits a school to disclose education records to another school where a student seeks or intends to enroll, subject to conditions, and performance or vendor-held information is governed separately by contracts and system design.
- Who owns an AI-generated athlete readiness score?
- There is no universal answer. Ownership, access, and control can depend on the vendor contract, the type of record, institutional policy, applicable law, and how the system was designed. Institutions should read the contract terms and obtain determinations from qualified counsel and their authorized staff rather than assume a default.
- Can colleges use AI and performance technology with athletes?
- Yes. NCAA performance technology guidance addresses responsible use rather than prohibition, and points to a written plan covering education, data management and protection, purchasing and implementation, and continuous improvement.
- What should an athletic department document before expanding athlete-data collection?
- The purpose of each data category, the systems holding it, who may access it, which outputs require a named human reviewer, what athletes are told, retention periods, and the procedure that applies when an athlete transfers or a vendor changes.
Sources
1. NCAA, Performance Technologies Guidelines
Performance technologies can collect biometric and performance data. Examples include wearables, cameras, sensors, and apps or software. Responsible use should consider privacy, mental health, informed consent, and data security.
2. NCAA, performance technology guidance approved by CSMAS (December 11, 2025)
Recommends a written plan for responsible performance-technology use covering education, data management and protection, purchasing and implementation, and continuous improvement.
3. NCAA, prevention and harm reduction advisory group charter approved by CSMAS (February 24, 2026)
CSMAS discussed an increasing burden on sports medicine staffs related to transfer student-athletes and the sharing of medical information, and is considering transfer-athlete education and updates to consent to share private information with HIPAA and FERPA in mind.
4. U.S. Department of Health and Human Services, FERPA and HIPAA at campus health clinics
Most postsecondary student health clinic records fall under FERPA rather than HIPAA, depending on context, and treatment records have a specific FERPA definition.
5. U.S. Department of Health and Human Services, FERPA and HIPAA at a university hospital
University hospital patient records may be HIPAA-covered when hospital services are not provided on behalf of the educational institution, so records can be treated differently depending on context.
6. U.S. Department of Education, FERPA disclosure to another school
FERPA permits a school to disclose education records to another school where a student seeks or intends to enroll, subject to conditions.
7. Stanford FASTR (Female Athlete Science and Translational Research)
Females are underrepresented in current sports-science research, and the program exists to address that gap.
About the author
Tamara C. Kelley
Founder and Principal of Resilience Ventures LLC, based in Atlanta, Georgia. She works on organizational readiness, responsible AI adoption, workforce training, and operational implementation, including women’s athletics organizations building new programs and partnerships. More about Tamara C. Kelley