HIPAA Privacy & Security Training

HIPAA requires workforce training under both the Privacy Rule and the Security Rule — and requires you to keep the documentation for six years. This program covers privacy and security awareness for covered entities and business associates, in English and Spanish.

Skip to product grid

5 products

HIPAA training requirements

HIPAA training is not an OSHA requirement — it is enforced by the HHS Office for Civil Rights, and it sits in two separate rules:

  • The Privacy Rule requires covered entities to train all workforce members on their policies and procedures for protected health information (45 CFR 164.530(b)) — for new members within a reasonable time after hire, and again whenever a material change to policy affects their job
  • The Security Rule requires a security awareness and training program for the entire workforce, including management (45 CFR 164.308(a)(5)), covering security reminders, protection from malicious software, log-in monitoring and password management

Both rules require the employer to document that training took place and retain that documentation for six years. Business associates are covered too, not just healthcare providers — billing companies, IT vendors, transcription services and anyone handling PHI on a covered entity's behalf.

The program below delivers the awareness training and the records to prove it happened. Your own policies and procedures are what employees are ultimately trained against.

What's included

  • Training video in English and Spanish
  • PowerPoint presentation for classroom delivery
  • Compliance manual and training outline
  • Employee quiz and answer key
  • Completion certificates and wallet / ID cards
  • Attendance log and sign-in form — the record the six-year retention rule applies to
  • Supplemental printouts

Compare formats

Format Access Starting price Best for
Streaming 1-month or 1-year subscription, instant online access $85 for 1 month, $195 for 1 year Onboarding new workforce members as they start
MP4 download Annual license, tiered by employee count. Both English and Spanish files included. Varies by employee count Hosting on your own LMS, file server or SharePoint
USB or DVD One-time purchase, physical media, no internet required $225 All-staff in-service sessions

What the training covers

  • What counts as protected health information, and what does not
  • Permitted uses and disclosures, and the minimum necessary standard
  • Patient rights — access, amendment, accounting of disclosures, notice of privacy practices
  • Everyday privacy failures: hallway conversations, unattended screens, misdirected faxes and email, social media
  • Security safeguards — passwords, log-in monitoring, malicious software, device and media handling
  • Breach notification: what triggers it and who must be notified
  • Workforce sanctions, and the difference between civil and criminal penalties

HIPAA training questions

Who is required to take HIPAA training?

Anyone who may come into contact with protected health information as part of their job. That includes clinical staff, administrative and billing personnel, IT staff, and anyone else employed by a covered entity or a business associate who handles PHI. The Security Rule specifically extends the awareness training requirement to management as well.

Does HIPAA preempt state privacy laws?

When covered entities use or transmit protected health information, they must comply with both the HIPAA Privacy and Security Rules and any applicable state medical-records privacy laws. Where the two conflict, HIPAA generally preempts state law — unless the state law is more stringent, in which case the state law controls. Several states have stricter rules for mental health, HIV and substance use records in particular.

How often is HIPAA training required?

The Privacy Rule requires training for new workforce members within a reasonable time after they start, and retraining whenever a material change to your policies and procedures affects their job. The Security Rule's awareness program is expected to be ongoing rather than one-time. Most organizations run an annual refresher, which is the practical way to satisfy both.

Do business associates need HIPAA training?

Yes. Billing companies, IT and cloud vendors, transcription services, shredding companies and anyone else handling PHI on a covered entity's behalf are directly liable under the Security Rule and much of the Privacy Rule. A signed business associate agreement does not substitute for training your own staff.

How long do we have to keep the training records?

Six years. HIPAA requires documentation that training took place, retained for six years from the date of creation or the date it was last in effect, whichever is later. The attendance log, quiz results and completion certificates included with the program are what that documentation looks like in practice.

Reinforce the classroom session

HIPAA privacy and security awareness booklets in packs of 10 give each workforce member a reference to keep. The Notice of Privacy Act poster and a privacy awareness poster are available for staff areas.