At a glance
- Who it applies to
- Covered entities: health plans, clearinghouses and health care providers that send health information electronically. The security training standard also covers their business associates2, 3.
- Who is trained
- The whole workforce: employees, volunteers, trainees and others under your direct control, paid or not, management included2, 3.
- When
- Privacy training for new workforce members within a reasonable period after they join, and again for those affected when policies materially change1.
- How often
- No fixed interval in the current rules. A 2025 proposal would require security training every 12 months, but it isn't final8, 9, 10.
Who must be trained
HIPAA's training rules apply to covered entities: health plans, health care clearinghouses, and health care providers that send health information electronically in standard transactions2. The Security Rule's training standard applies to covered entities and their business associates alike3.
Training covers the whole workforce: employees, volunteers, trainees and anyone else whose work is under your direct control, whether or not you pay them2. The Security Rule adds that management is included3.
Privacy Rule training
A covered entity must train all members of its workforce on its policies and procedures for protected health information, including breach notification, as necessary and appropriate for their jobs1. The rule sets three moments1:
- everyone, by the organization's compliance date;
- each new workforce member, within a reasonable period after they join;
- each person whose job is affected by a material change in the policies, within a reasonable period after the change takes effect.
The rule doesn't set a number of days. When HHS adopted it, it said retraining isn't required every three years, only after material changes to the policies7.
Group health plans that provide benefits only through an insurance company or HMO, and handle no protected health information beyond summary or enrollment information, are exempt from this training rule1.
Security Rule training
Covered entities and business associates must run a security awareness and training program for all workforce members, management included3. The rule lists four parts3:
- security reminders: periodic security updates;
- protection from malicious software: guarding against it, detecting it and reporting it;
- log-in monitoring: watching log-in attempts and reporting discrepancies;
- password management: creating, changing and safeguarding passwords.
All four are "addressable", which doesn't mean optional6. You assess whether each is reasonable and appropriate for you; if one isn't, you document why and put an equivalent alternative in place if that is reasonable and appropriate4.
The rule sets no interval. When HHS adopted it, it said each organization should decide the amount and timing of training, as an ongoing process that responds to changes affecting the security of electronic health information8.
Content, length and format
HIPAA leaves the content and method of training to you, matched to your policies and each person's job7. HHS says the rules are flexible and scalable, so no single standardized program could train the employees of every organization11.
Records to keep
Document that the training was provided, as a written or electronic record, and keep the documentation for six years from when it was created or when it was last in effect, whichever is later1, 5.
The proposed Security Rule update
In January 2025, HHS proposed updating the Security Rule. The proposal would require security awareness training for every workforce member at least once every 12 months, for new workforce members within 30 days of first getting access to the relevant systems, and within 30 days of a material change in the policies9.
It isn't final. HHS says the current Security Rule remains in effect while the rulemaking continues10. If it's finalized, organizations would generally have 180 days after it takes effect to comply9.
Enforcement
HHS's Office for Civil Rights has cited missing training in its enforcement. In 2024 it proposed a $548,265 civil money penalty against a children's hospital, $100,000 of it for failing to train all its workforce, including nursing students on clinical rotation, in violation of the Privacy Rule's training standard13.
How MyWorkAcademy helps
MyWorkAcademy runs the training and keeps the records around it:
- Turn your own privacy and security policies into a course with the course builder, so the training matches your policies and people's jobs.
- Assign it to each new workforce member with a deadline counted from their start date, and to groups such as clinical staff or billing.
- Repeat it on the schedule you choose, such as every year, counted from each person's last completion, with reminders before each deadline and follow-ups after it.
- When a policy changes, publish a new version of the course and assign it to the people it affects. Past completions keep the version each person took.
- Keep a locked record of every completion, with the exact course version, the date, the score and the acknowledgment. Records are permanent in your academy, and you can download them at any time, including after a paid plan ends.
MyWorkAcademy doesn't decide whether a course meets a law's content or length rules. Use your own training, turn your policy into a course, or start from our library, and have your legal adviser confirm the content meets the law.
Questions employers ask
How often is HIPAA training required?
Is there HIPAA-certified training?
Do volunteers and students need HIPAA training?
How long do we keep HIPAA training records?
Do business associates have to train their staff?
Sources
- 45 CFR 164.530, Privacy Rule administrative requirementseCFR
- 45 CFR 160.103, DefinitionseCFR
- 45 CFR 164.308, Security Rule administrative safeguardseCFR
- 45 CFR 164.306, Security standards: general ruleseCFR
- 45 CFR 164.316, Policies and procedures and documentation requirementseCFR
- Summary of the HIPAA Security RuleU.S. Department of Health and Human Services
- Standards for Privacy of Individually Identifiable Health Information, final rule (December 28, 2000)Federal Register
- Health Insurance Reform: Security Standards, final rule (February 20, 2003)Federal Register
- HIPAA Security Rule proposed rule (January 6, 2025)Federal Register
- HIPAA Security Rule NPRMU.S. Department of Health and Human Services
- Training materialsU.S. Department of Health and Human Services
- Be aware of misleading marketing claimsU.S. Department of Health and Human Services
- Children's Hospital Colorado: notice of proposed determination (June 11, 2024)U.S. Department of Health and Human Services