Three HIPAA Training Modules for Your Team
Three focused training modules built for small healthcare teams. Each covers a distinct compliance area your workforce needs to understand, with knowledge checks and completion tracking.
What Your Team Will See
Your team completes training through our portal. Each module tracks progress, includes knowledge checks, and records completion automatically.
HIPAA 101 Training
Introduction to HIPAA
What HIPAA is, who it applies to, and why it matters for every role in your organization.
- Covered entities and business associates
- Privacy Rule overview
- Security Rule overview
Protected Health Information
How to identify, handle, and safeguard PHI in daily workflows.
- 18 PHI identifiers
- Minimum necessary standard
- Permitted uses and disclosures
Breach Notification
What constitutes a breach and the reporting obligations under federal law.
- Breach identification
- Notification timelines
- Documentation requirements
Cybersecurity Awareness
Common Threats
The attack types most frequently targeting healthcare organizations.
- Phishing and spear phishing
- Ransomware
- Social engineering
Password and Access Security
Practical habits that prevent unauthorized access to systems and data.
- Strong password practices
- Multi-factor authentication
- Screen lock and session management
Incident Response
What to do when something looks wrong and how to report it.
- Recognizing suspicious activity
- Internal reporting procedures
- Containment basics
Policy Attestation
Policy Review
Walk through your organization's specific HIPAA policies and procedures.
- Privacy policies
- Security policies
- Acceptable use policies
PHI Handling Procedures
Role-specific guidance on proper handling, storage, and transmission of PHI.
- Physical safeguards
- Electronic safeguards
- Disposal procedures
Acknowledgement and Sign-Off
Document that each team member has reviewed and understood their obligations.
- Digital attestation
- Completion tracking
- Audit-ready records
Training Completion Documentation
Every training engagement produces audit-ready documentation. These records are what OCR asks for during compliance reviews and breach investigations.
Individual Completion Records
Employee name, training date, module completed, and facilitator name. One record per person, per session.
Signed Acknowledgment Forms
Each employee signs a form confirming they received the training and understand their compliance obligations.
Training Log
Master log with training dates, topics covered, attendee names, and facilitator for each session. Maintained as a running record.
Knowledge Check Results
Quiz and assessment scores demonstrating comprehension. Documents that training went beyond attendance to actual understanding.
Attestation Statements
Ties each employee's training completion to the specific policy versions in effect at the time of training.
45 CFR 164.530(j) requires covered entities to retain all training documentation for a minimum of six years from the date of creation or the date it was last in effect, whichever is later. Our records are structured for long-term retention and retrieval.
When Training Must Be Delivered
Before First PHI Access
New hires must complete HIPAA training before they access any protected health information. This is a regulatory requirement under 45 CFR 164.530(b)(1), not a best practice suggestion.
Annual Refresher
At least once per year, based on HHS's interpretation of "periodic" training. Annual refreshers keep compliance current and reinforce key concepts that drift over time.
After Material Policy Changes
When policies or procedures change in ways that affect how workforce members handle PHI, affected staff must be retrained on the specific changes. Waiting for the next annual cycle is not sufficient.
After a Security Incident
When an incident reveals a training gap, focused retraining on the specific issue should follow. This closes the gap and demonstrates a corrective response if OCR reviews the incident.
For a detailed breakdown of training frequency requirements, see our training frequency guide for small practices.
Training Documentation FAQ
Audit-ready proof typically includes individual completion records, signed acknowledgment forms, a master training log, and knowledge check results. These documents together demonstrate that training was delivered, received, and understood. Under 45 CFR 164.530(j), covered entities must retain this documentation for at least six years.
Six years minimum. Under 45 CFR 164.530(j), covered entities must retain training documentation for six years from the date of creation or the date it was last in effect, whichever is later. Many organizations retain records longer as a practical safeguard against delayed investigations.
HIPAA requires that all workforce members receive training. If an employee refuses, the organization must apply its sanction policy under 45 CFR 164.308(a)(1)(ii)(C). Document the refusal, the steps taken to address it, and any sanctions applied. An untrained workforce member with access to PHI represents a compliance gap.
Training must be completed before the new hire accesses PHI, not necessarily before their first day. If their first day includes PHI access, then yes, training must come first. Many practices schedule training as part of orientation before granting system access.
No. HIPAA does not specify a minimum number of training hours. The standard requires training that is "necessary and appropriate" for each workforce member's job functions. Content depth and relevance matter more than seat time. Our modules are designed to be thorough without being unnecessarily long.
Yes. HIPAA does not mandate a specific delivery format. Online, in-person, or hybrid training all satisfy the requirement as long as the content is role-appropriate, completion is tracked, and documentation is maintained. The critical element is proving that each person completed the training and understood the material.
Ready to Train Your Team?
Book a short intro and we will match the right training modules to your team size and compliance needs.
Book Your Free HIPAA Compliance Review