Compliance guide · Federal · HIPAA

HIPAA training requirements: who must be trained, when, and what to keep

HIPAA requires covered entities to train their whole workforce on their privacy policies, and covered entities and business associates to run a security awareness and training program. Here is who counts as workforce, when training is due, what the rules leave to you, and the records to keep.

Last reviewed September 29, 2026 against the official sources listed below. A plain-language summary, not legal advice: confirm how the law applies to you with your legal adviser.

At a glance

Who it applies to
Covered entities: health plans, clearinghouses and health care providers that send health information electronically. The security training standard also covers their business associates2, 3.
Who is trained
The whole workforce: employees, volunteers, trainees and others under your direct control, paid or not, management included2, 3.
When
Privacy training for new workforce members within a reasonable period after they join, and again for those affected when policies materially change1.
How often
No fixed interval in the current rules. A 2025 proposal would require security training every 12 months, but it isn't final8, 9, 10.
Content and format
Up to you, based on your policies and people's jobs. HHS sets no length or format and certifies no courses7, 11, 12.
Records
Document the training and keep the records for six years1, 5.

Who must be trained

HIPAA's training rules apply to covered entities: health plans, health care clearinghouses, and health care providers that send health information electronically in standard transactions2. The Security Rule's training standard applies to covered entities and their business associates alike3.

Training covers the whole workforce: employees, volunteers, trainees and anyone else whose work is under your direct control, whether or not you pay them2. The Security Rule adds that management is included3.

Privacy Rule training

A covered entity must train all members of its workforce on its policies and procedures for protected health information, including breach notification, as necessary and appropriate for their jobs1. The rule sets three moments1:

  • everyone, by the organization's compliance date;
  • each new workforce member, within a reasonable period after they join;
  • each person whose job is affected by a material change in the policies, within a reasonable period after the change takes effect.

The rule doesn't set a number of days. When HHS adopted it, it said retraining isn't required every three years, only after material changes to the policies7.

Group health plans that provide benefits only through an insurance company or HMO, and handle no protected health information beyond summary or enrollment information, are exempt from this training rule1.

Security Rule training

Covered entities and business associates must run a security awareness and training program for all workforce members, management included3. The rule lists four parts3:

  • security reminders: periodic security updates;
  • protection from malicious software: guarding against it, detecting it and reporting it;
  • log-in monitoring: watching log-in attempts and reporting discrepancies;
  • password management: creating, changing and safeguarding passwords.

All four are "addressable", which doesn't mean optional6. You assess whether each is reasonable and appropriate for you; if one isn't, you document why and put an equivalent alternative in place if that is reasonable and appropriate4.

The rule sets no interval. When HHS adopted it, it said each organization should decide the amount and timing of training, as an ongoing process that responds to changes affecting the security of electronic health information8.

Content, length and format

HIPAA leaves the content and method of training to you, matched to your policies and each person's job7. HHS says the rules are flexible and scalable, so no single standardized program could train the employees of every organization11.

  • HHS doesn't endorse training providers or certify anyone or anything as "HIPAA compliant", and the Privacy Rule doesn't require any particular seminar12.
  • Employees don't have to sign for their training: HHS dropped a proposed signature requirement and kept only a duty to document the training7.

Records to keep

Document that the training was provided, as a written or electronic record, and keep the documentation for six years from when it was created or when it was last in effect, whichever is later1, 5.

The proposed Security Rule update

In January 2025, HHS proposed updating the Security Rule. The proposal would require security awareness training for every workforce member at least once every 12 months, for new workforce members within 30 days of first getting access to the relevant systems, and within 30 days of a material change in the policies9.

It isn't final. HHS says the current Security Rule remains in effect while the rulemaking continues10. If it's finalized, organizations would generally have 180 days after it takes effect to comply9.

Enforcement

HHS's Office for Civil Rights has cited missing training in its enforcement. In 2024 it proposed a $548,265 civil money penalty against a children's hospital, $100,000 of it for failing to train all its workforce, including nursing students on clinical rotation, in violation of the Privacy Rule's training standard13.

How MyWorkAcademy helps

MyWorkAcademy runs the training and keeps the records around it:

  • Turn your own privacy and security policies into a course with the course builder, so the training matches your policies and people's jobs.
  • Assign it to each new workforce member with a deadline counted from their start date, and to groups such as clinical staff or billing.
  • Repeat it on the schedule you choose, such as every year, counted from each person's last completion, with reminders before each deadline and follow-ups after it.
  • When a policy changes, publish a new version of the course and assign it to the people it affects. Past completions keep the version each person took.
  • Keep a locked record of every completion, with the exact course version, the date, the score and the acknowledgment. Records are permanent in your academy, and you can download them at any time, including after a paid plan ends.

MyWorkAcademy doesn't decide whether a course meets a law's content or length rules. Use your own training, turn your policy into a course, or start from our library, and have your legal adviser confirm the content meets the law.

Questions employers ask

How often is HIPAA training required?
The current rules set no fixed interval. Privacy Rule training is due for new workforce members within a reasonable period and again after material policy changes, and the Security Rule leaves timing to each organization1, 8. A 2025 proposal would require security training at least every 12 months, but it isn't final9, 10.
Is there HIPAA-certified training?
No. HHS doesn't certify any person or product as "HIPAA compliant" and doesn't endorse training providers12.
Do volunteers and students need HIPAA training?
Yes, if they're part of your workforce. HIPAA's workforce includes volunteers, trainees and others whose work is under your direct control, paid or not2.
How long do we keep HIPAA training records?
Six years from when the record was created or when it was last in effect, whichever is later1, 5.
Do business associates have to train their staff?
Yes. The Security Rule requires covered entities and business associates to run a security awareness and training program for their workforce3. The Privacy Rule's training standard is written for covered entities1.
Do employees have to sign an acknowledgment?
No. HHS removed a proposed signature requirement; the rule only requires you to document that the training was provided7, 1.

Sources

  1. 45 CFR 164.530, Privacy Rule administrative requirementseCFR
  2. 45 CFR 160.103, DefinitionseCFR
  3. 45 CFR 164.308, Security Rule administrative safeguardseCFR
  4. 45 CFR 164.306, Security standards: general ruleseCFR
  5. 45 CFR 164.316, Policies and procedures and documentation requirementseCFR
  6. Summary of the HIPAA Security RuleU.S. Department of Health and Human Services
  7. Standards for Privacy of Individually Identifiable Health Information, final rule (December 28, 2000)Federal Register
  8. Health Insurance Reform: Security Standards, final rule (February 20, 2003)Federal Register
  9. HIPAA Security Rule proposed rule (January 6, 2025)Federal Register
  10. HIPAA Security Rule NPRMU.S. Department of Health and Human Services
  11. Training materialsU.S. Department of Health and Human Services
  12. Be aware of misleading marketing claimsU.S. Department of Health and Human Services
  13. Children's Hospital Colorado: notice of proposed determination (June 11, 2024)U.S. Department of Health and Human Services

Train everyone on time, and keep the proof.

Assign the training once. MyWorkAcademy reminds people, repeats it on schedule and keeps every record ready to show.

See plans and start a free trial