Guide

HIPAA Training Requirements

Who must be trained, how often, what counts as a record, and why annual video completion is not enough on its own.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Who must be trained, how often, what counts as a record, and why annual video completion is not enough on its own.

The requirement

Security awareness and training is an administrative safeguard standard. The Privacy Rule separately requires training on policies and procedures relevant to each workforce member’s function.

Two distinct legal bases, which matters because satisfying one does not satisfy the other. The Security Rule standard, §164.308(a)(5), requires a security awareness and training programme for the entire workforce — including management, a phrase the rule includes because organisations reliably exempt exactly the people with the broadest access. Its addressable implementation specifications name the floor topics: security reminders, protection from malicious software, log-in monitoring, and password management. The Privacy Rule requirement, §164.530(b), is function-specific: each workforce member trained on the privacy policies and procedures relevant to their role — the front-desk team on verification and minimum necessary, the billing team on permitted disclosures, and so on. A generic security video cannot carry the Privacy Rule load, and a privacy induction cannot carry the security one.

“Workforce” is also broader than “employees”: it covers anyone whose conduct is under your direct control, paid or not — which pulls in the topics below under Records.

Frequency

At hire, on material policy change, and periodically thereafter. Annual is the accepted practical baseline; high-risk roles warrant more.

The rule prescribes no interval; the defensible convention has three triggers. At hire means before meaningful access to PHI, not “within ninety days” — an untrained employee with production access is a documented risk you created. On material change means a policy rewrite, a new system, or a new threat pattern re-triggers training for affected roles, scoped to the change rather than repeating the full curriculum. Periodic means annual for everyone, with high-exposure roles — engineers with production access, anyone handling access requests, executives, and admins — warranting more frequent, more specific attention. The addressable “security reminders” specification is usefully read as permission to drip: short monthly touches (a phishing note, a real anonymised incident, a policy nudge) outperform the annual hour on every measure that matters, and each one is a dated record.

Role-based content

A billing clerk, a nurse, and a backend engineer need different training. Generic training generates completion records and very little behaviour change.

The tell of a compliance-theatre programme is a single course, identical for all roles, renewed annually by clicking through slides. It produces records — and records matter — but the behaviour that prevents incidents is role-specific. The engineer needs to know that ePHI in logs and test databases is still ePHI, and what the approved channels are for sharing it with a vendor. The clinician needs verification procedures and minimum necessary at the point of care. The billing clerk needs the difference between a permitted payment disclosure and one needing authorisation. Everyone needs the universal core: how to recognise phishing, how to report a suspected incident (and that reporting is praised, not punished — your incident response programme depends on this), what the sanction policy says, and where the policies live. A practical structure is a common core plus a role module, which is exactly how our free training template is organised.

Records

Per-person, per-course, per-date, retained six years. Include contractors and temporary staff — they are workforce members if they act under your direct control.

Under HIPAA’s documentation logic, untracked training is untrained: if OCR or an enterprise customer asks for evidence and none exists, the answer is functionally no. The record that holds up captures who, which course, which content version, completion date, and — increasingly expected — an assessment result rather than bare attendance. Content versioning is the subtle one: “completed security training 2024” means little if nobody can say what the 2024 course contained; keep the deck or curriculum for each version alongside the completion data, all within the six-year retention of §164.316. The other place programmes leak is population coverage — contractors, temps, interns, and the offshore support team are workforce members when they act under your direct control, and the completion report should reconcile against the full roster, not the payroll. A 100% completion rate over the wrong denominator is a finding wearing a green dashboard.

Making it stick

Three habits separate training programmes that change behaviour from those that generate records. Tie content to your actual policies and incidents — training on the policies people acknowledged, illustrated by things that really happened here or to peers, lands differently from stock scenarios. Test lightly but honestly — a short quiz with a pass threshold turns exposure into evidence of comprehension. And close the loop with enforcement: the sanction policy applied consistently, and near-misses fed back into next quarter’s reminder. Training is the cheapest administrative safeguard per finding prevented, and the first one to decay when nobody owns the calendar — which is an ownership problem before it is a content problem.

Questions teams actually ask

Can we buy off-the-shelf training and be done? Purchased content can carry the common core competently — phishing, PHI basics, reporting. What it cannot carry is the function-specific Privacy Rule layer or your own policies, channels, and sanction terms. The workable pattern is bought core plus a short internal module naming your systems, your Security Officer, and your reporting path; the internal module is usually the part that changes behaviour.

Do board members and executives really need it? If they access PHI or direct the people who do, yes — and §164.308(a)(5) says “including management” precisely because seniority correlates with access breadth and with exemption requests. An executive completion record also sets the tone the rest of the roster follows.

What about the contractor who works two hours a month? If they act under your direct control and touch PHI, they are workforce. Scale the content to the role — a scoped fifteen-minute module is defensible where the full curriculum would be theatre — but the record must exist.

Is there a required pass mark? No. The rule prescribes neither quizzes nor thresholds. But an assessment with a documented pass standard converts “was shown slides” into “demonstrated comprehension”, which is the version enterprise customers and investigators find persuasive.

How does training interact with sanctions? Directly: you cannot fairly sanction someone for violating a policy they were never trained on, and investigators check the sequence. Training records dated before the violation are what make your sanction policy enforceable rather than decorative. The same sequencing logic applies to acknowledgements — train, acknowledge, then grant access, in that order, and let the records show it.

Where SuperHIPAA fits

Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is this legal advice?

No. It is operational guidance from practitioners who build HIPAA programs. Regulatory interpretation for your specific situation should come from counsel.

Can we become HIPAA certified?

No. HHS operates no certification program and no private body can confer one. What exists is an independent third-party assessment, which is what customers and insurers actually accept.

How current is this page?

Last reviewed 2026-08-04. We review every guide quarterly and after any HHS rulemaking or significant enforcement action.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo