HIPAA workforce training: what the rule requires and what actually works
HIPAA requires workforce training on security policies. What the rule says, what Office for Civil Rights (OCR) has cited in settlements, and what it looks like in a small practice.
By CoreFolio
7-minute read
HIPAA requires every covered entity to run a security awareness and training program for all workforce members, including management (45 CFR § 164.308(a)(5)).1 The rule sets no fixed curriculum, format, or frequency, but the Office for Civil Rights (OCR) treats undocumented training as no training — so a small practice needs dated records of who was trained, when, and on what, refreshed at least annually and whenever policies change.
Workforce training is an administrative safeguard under 45 CFR § 164.308(a)(5). Like most HIPAA requirements, the rule is intentionally general — it requires covered entities to implement a training program appropriate for their size and complexity, without prescribing a specific curriculum, format, or duration.
That flexibility is both a feature and a problem. It means there is no universally accepted "enough." It also means that when OCR asks to see your training documentation and you cannot produce it, the requirement is treated as unmet.
What the rule actually requires
45 CFR § 164.308(a)(5)(i) requires covered entities to "[i]mplement a security awareness and training program for all members of its workforce (including management)."1
The training-program standard itself is required — every covered entity must have one. Beneath that standard sit four implementation specifications, and under the current rule all four are addressable, not required:
- Security reminders — periodic security updates
- Protection from malicious software — guarding against, detecting, and reporting malicious software
- Log-in monitoring — monitoring log-in attempts and reporting discrepancies
- Password management — creating, changing, and safeguarding passwords
"Addressable" does not mean optional. It means you assess whether each specification is reasonable and appropriate for your environment, implement it if it is, and document the decision either way. The proposed Security Rule update — a Notice of Proposed Rulemaking, or NPRM (90 Fed. Reg. 898) — would remove the addressable/required distinction and make nearly every specification mandatory, but that is still a proposal, not yet law.2
The documentation requirement (45 CFR § 164.316(b)(1)) means you have to maintain written evidence that training happened, when, who attended, and what was covered.3 Verbal training with no record is treated as no training.
What OCR has cited in settlement agreements
Resolution agreements involving workforce training failures follow a pattern:
- The practice had some form of onboarding orientation that included a mention of HIPAA
- No annual training was documented
- No records showed which specific employees had completed training
- When a breach occurred (or OCR investigated), the workforce had no documented understanding of the relevant policies
The finding is typically: "the covered entity failed to implement a security awareness and training program for all members of its workforce."
Note the phrase "all members." A practice where the dentist and office manager received training but the medical assistants and front desk staff did not is non-compliant. Everyone with access to systems that touch electronic protected health information (ePHI) needs to be documented as trained.
What "security awareness training" covers
The regulation does not prescribe a curriculum. Based on OCR guidance and the common findings in resolution agreements, effective security awareness training for a small practice covers:
Phishing recognition. Hacking and information-technology (IT) incidents — which frequently begin with a phishing email — are the largest category of large healthcare breaches reported to OCR.4 A staff member clicks a link, enters credentials, and an attacker gains access to the electronic health record (EHR) or email account. Because so many incidents start this way, teaching staff to recognize and report phishing emails is a high-value, low-cost security step.
Password management. Unique passwords for each account, no sharing of credentials, requirements to change passwords when a staff member leaves or when there is reason to believe a password is compromised.
Device security. What to do when a work laptop is lost or stolen; whether patient data can be accessed from personal devices; how to lock a workstation when stepping away.
Incident reporting. How a workforce member reports a suspected security incident — a clicked phishing link, a lost device, unauthorized access to a record. The practice needs a clear reporting path.
Policies. Where your security policies are documented and where workforce members can find them. The policies do not need to be memorized, but staff should know they exist.
What documentation you need
For each training event, you need documentation of:
- The date training occurred
- The topic(s) covered
- Who attended (by name or employee role)
- Confirmation of completion (a sign-in sheet, a completion certificate, an electronic attestation)
The format does not matter. A sign-in sheet with names and dates works. An electronic completion record from a training platform works. A shared spreadsheet with employee names, training dates, and topics works.
What does not work: an undated certificate from an online training vendor with no record of which employees completed it.
How often training must occur
The rule does not specify a frequency. The required implementation specification for "security reminders" implies ongoing communication, not a single annual event. Resolution agreements consistently treat annual training (at minimum) as the floor.
In practice, this means:
- Comprehensive initial training for all new workforce members (before or very shortly after they begin handling ePHI)
- Annual refresher training for all existing workforce members
- Ad hoc training when a relevant policy changes, when a new system is introduced, or when a security incident reveals a gap
"Annual" in enforcement practice means within 12 months. A practice whose last documented training was 14 months ago is in a gap.
Practical formats for a small practice
Online training platforms. Many HIPAA training vendors offer short (15–30 minute) online modules with built-in completion tracking. Some are free; most cost $10–30 per person per year. The tracking is the main advantage — the platform generates a certificate or completion record automatically.
In-person sessions. A 30–45 minute staff meeting covering the topics above, with a sign-in sheet and an agenda on file, satisfies the requirement. This works well for new employee onboarding and for annual refreshers in a practice small enough to gather everyone.
Written attestations. Giving staff a copy of your security policies and having them sign that they have read and understood them is one component of training. It is not sufficient on its own, but it is valuable documentation to have alongside the training record.
The sanctions policy requirement
Separate from training, 45 CFR § 164.308(a)(1)(ii)(C) requires covered entities to implement a sanctions policy — a documented policy for workforce members who violate security policies.
The sanctions policy does not need to be punitive. It needs to exist, be documented, and be communicated to the workforce. "Staff who violate our HIPAA security policies will be subject to disciplinary action up to and including termination" covers the requirement. Including it in your training materials addresses both requirements at once.
What to do if you have no current training documentation
If your last documented training was more than 12 months ago, or if you have no training records at all:
- Schedule training within the next 30 days
- Use a format that generates a completion record for each participant
- File the records in your compliance documentation
- Schedule the next annual training for 12 months from today
- Write down the date you restarted the cycle, so both the gap and its closure are on the record
Starting from scratch is not ideal, but it is recoverable. The training records are the evidence the rule asks for, kept in written or electronic form and retained six years under 45 CFR § 164.316(b).3 The plan to close the gap belongs somewhere else — in the risk management documentation HIPAA requires under 45 CFR § 164.308(a)(1)(ii)(B), which is where a known shortfall and the steps to fix it get tracked.5
Sources
Footnotes
-
45 CFR § 164.308 (administrative safeguards) — § 164.308(a)(5) (security awareness and training program; the four addressable implementation specifications) and § 164.308(a)(1)(ii)(C) (sanction policy). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308 ↩ ↩2
-
HHS, HIPAA Security Rule Notice of Proposed Rulemaking (90 Fed. Reg. 898, published January 6, 2025). A proposal, not final law. https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html ↩
-
45 CFR § 164.316(b)(1) (documentation) and § 164.316(b)(2)(i) (six-year retention). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316 ↩ ↩2
-
HHS, Office for Civil Rights, Breach Portal (Breaches Affecting 500 or More Individuals), where hacking/IT incidents are the largest reported breach category. https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf ↩
-
45 CFR § 164.308(a)(1)(ii)(B) (risk management — implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308 ↩