hipaa.systems
Guide

HIPAA training

What HIPAA training has to cover, who needs it, how to structure a program for a small practice, and how to judge an online course.

HIPAA training at a glance

HIPAA training teaches staff how to handle protected health information under their organization's policies and the HIPAA Privacy and Security Rules. Covered entities must train their workforce on their privacy policies, and both covered entities and business associates must run security awareness training; there is no official or government-approved course. A good program combines a general HIPAA course, role-specific content, the organization's own policies, and records of completion kept for six years.

Required by45 CFR 164.530(b) and 164.308(a)(5)
Official course?None — HHS does not approve or accredit HIPAA training
Typical lengthAbout 30–90 minutes for general staff
Typical priceAbout $15–50 per learner for online courses
Must includeYour own policies, privacy basics, security awareness
RecordsWho, what, when — kept six years

HIPAA training is a legal requirement for covered entities and business associates, but the law does not prescribe a course, a length or a provider. It prescribes outcomes: people know your policies, understand security risks, and you can prove they were trained. The HIPAA training requirements page covers the rule itself; this page is about building a program that works.

A program that works for a small practice

  1. A general HIPAA course for everyone — the fundamentals of privacy and security.
  2. Role-specific content — front desk (identity checks, records requests), clinicians (notes, messaging, telehealth), anyone with admin access (accounts, devices, incidents).
  3. Your own policies — a short walkthrough and a signed acknowledgment.
  4. Security reminders through the year — a phishing example, a password reminder, a note after an incident.
  5. Records — completion certificates, acknowledgments and dates, kept six years.

Topics to cover

How to judge an online course

Question Why it matters
Does it cover both Privacy and Security Rule topics? The rule requires both
Is there role-specific content? Front desk and clinicians face different risks
Does it issue a dated certificate? You need proof of training
Can an owner see who completed it? Records are your evidence in an audit
When was it last updated? Rules and guidance change
Does it leave room for your own policies? Generic training alone doesn’t meet the rule

Online courses typically cost around $15–50 per learner. Price matters less than whether you end up with documented, role-appropriate training on your own policies.

Next steps

Frequently asked questions

How long does HIPAA training take?

There is no required length. Online courses for general staff typically take 30 to 90 minutes; roles that handle more PHI or administer systems need more.

Is free HIPAA training good enough?

It can cover the basics. What a free course rarely covers is your organization's own policies and the records you need to keep, which the rule requires.

What topics should HIPAA training cover?

What PHI is and when it may be shared, patient rights, minimum necessary, safe use of email and messaging, passwords and MFA, phishing and malware, device security, how to report incidents, and your organization's specific policies.