-
Vendor:National Safety Compliance
HIPAA Privacy & Security Rules Training | Video & Program (English & Spanish)
Regular price From $85.00Regular priceSale price From $85.00 -
Vendor:National Safety Compliance
All Access Pass (English and Spanish)
Regular price $3,495.00Regular priceSale price $3,495.00 -
Vendor:National Safety Compliance
HIPAA - Privacy & Security Awareness Training Booklets (pkg of 10)
Regular price $15.00Regular priceSale price $15.00 -
Vendor:National Safety Compliance
HIPAA Notice of Privacy Act Safety Poster
Regular price $15.00Regular priceSale price $15.00 -
Vendor:National Safety Compliance
HIPAA Prevention is the Only Cure Poster
Regular price $15.00Regular priceSale price $15.00
HIPAA training requirements
HIPAA training is not an OSHA requirement — it is enforced by the HHS Office for Civil Rights, and it sits in two separate rules:
- The Privacy Rule requires covered entities to train all workforce members on their policies and procedures for protected health information (45 CFR 164.530(b)) — for new members within a reasonable time after hire, and again whenever a material change to policy affects their job
- The Security Rule requires a security awareness and training program for the entire workforce, including management (45 CFR 164.308(a)(5)), covering security reminders, protection from malicious software, log-in monitoring and password management
Both rules require the employer to document that training took place and retain that documentation for six years. Business associates are covered too, not just healthcare providers — billing companies, IT vendors, transcription services and anyone handling PHI on a covered entity's behalf.
The program below delivers the awareness training and the records to prove it happened. Your own policies and procedures are what employees are ultimately trained against.
What's included
- Training video in English and Spanish
- PowerPoint presentation for classroom delivery
- Compliance manual and training outline
- Employee quiz and answer key
- Completion certificates and wallet / ID cards
- Attendance log and sign-in form — the record the six-year retention rule applies to
- Supplemental printouts
Compare formats
| Format | Access | Starting price | Best for |
|---|---|---|---|
| Streaming | 1-month or 1-year subscription, instant online access | $85 for 1 month, $195 for 1 year | Onboarding new workforce members as they start |
| MP4 download | Annual license, tiered by employee count. Both English and Spanish files included. | Varies by employee count | Hosting on your own LMS, file server or SharePoint |
| USB or DVD | One-time purchase, physical media, no internet required | $225 | All-staff in-service sessions |
What the training covers
- What counts as protected health information, and what does not
- Permitted uses and disclosures, and the minimum necessary standard
- Patient rights — access, amendment, accounting of disclosures, notice of privacy practices
- Everyday privacy failures: hallway conversations, unattended screens, misdirected faxes and email, social media
- Security safeguards — passwords, log-in monitoring, malicious software, device and media handling
- Breach notification: what triggers it and who must be notified
- Workforce sanctions, and the difference between civil and criminal penalties
HIPAA training questions
Who is required to take HIPAA training?
Anyone who may come into contact with protected health information as part of their job. That includes clinical staff, administrative and billing personnel, IT staff, and anyone else employed by a covered entity or a business associate who handles PHI. The Security Rule specifically extends the awareness training requirement to management as well.
Does HIPAA preempt state privacy laws?
When covered entities use or transmit protected health information, they must comply with both the HIPAA Privacy and Security Rules and any applicable state medical-records privacy laws. Where the two conflict, HIPAA generally preempts state law — unless the state law is more stringent, in which case the state law controls. Several states have stricter rules for mental health, HIV and substance use records in particular.
How often is HIPAA training required?
The Privacy Rule requires training for new workforce members within a reasonable time after they start, and retraining whenever a material change to your policies and procedures affects their job. The Security Rule's awareness program is expected to be ongoing rather than one-time. Most organizations run an annual refresher, which is the practical way to satisfy both.
Do business associates need HIPAA training?
Yes. Billing companies, IT and cloud vendors, transcription services, shredding companies and anyone else handling PHI on a covered entity's behalf are directly liable under the Security Rule and much of the Privacy Rule. A signed business associate agreement does not substitute for training your own staff.
How long do we have to keep the training records?
Six years. HIPAA requires documentation that training took place, retained for six years from the date of creation or the date it was last in effect, whichever is later. The attendance log, quiz results and completion certificates included with the program are what that documentation looks like in practice.
Reinforce the classroom session
HIPAA privacy and security awareness booklets in packs of 10 give each workforce member a reference to keep. The Notice of Privacy Act poster and a privacy awareness poster are available for staff areas.