HIPAA training
What HIPAA training has to cover, who needs it, how to structure a program for a small practice, and how to judge an online course.
HIPAA training at a glance
HIPAA training teaches staff how to handle protected health information under their organization's policies and the HIPAA Privacy and Security Rules. Covered entities must train their workforce on their privacy policies, and both covered entities and business associates must run security awareness training; there is no official or government-approved course. A good program combines a general HIPAA course, role-specific content, the organization's own policies, and records of completion kept for six years.
| Required by | 45 CFR 164.530(b) and 164.308(a)(5) |
|---|---|
| Official course? | None — HHS does not approve or accredit HIPAA training |
| Typical length | About 30–90 minutes for general staff |
| Typical price | About $15–50 per learner for online courses |
| Must include | Your own policies, privacy basics, security awareness |
| Records | Who, what, when — kept six years |
HIPAA training is a legal requirement for covered entities and business associates, but the law does not prescribe a course, a length or a provider. It prescribes outcomes: people know your policies, understand security risks, and you can prove they were trained. The HIPAA training requirements page covers the rule itself; this page is about building a program that works.
A program that works for a small practice
- A general HIPAA course for everyone — the fundamentals of privacy and security.
- Role-specific content — front desk (identity checks, records requests), clinicians (notes, messaging, telehealth), anyone with admin access (accounts, devices, incidents).
- Your own policies — a short walkthrough and a signed acknowledgment.
- Security reminders through the year — a phishing example, a password reminder, a note after an incident.
- Records — completion certificates, acknowledgments and dates, kept six years.
Topics to cover
- What counts as PHI, and when it can be used or shared without permission.
- Patients’ rights: access to records, authorizations, the Notice of Privacy Practices.
- Minimum necessary — sharing only what the task needs.
- Email, texting, telehealth and AI tools: what’s allowed and how.
- Passwords, MFA, phishing and malware; lost or stolen devices.
- How to recognize and report an incident, and why speed matters.
How to judge an online course
| Question | Why it matters |
|---|---|
| Does it cover both Privacy and Security Rule topics? | The rule requires both |
| Is there role-specific content? | Front desk and clinicians face different risks |
| Does it issue a dated certificate? | You need proof of training |
| Can an owner see who completed it? | Records are your evidence in an audit |
| When was it last updated? | Rules and guidance change |
| Does it leave room for your own policies? | Generic training alone doesn’t meet the rule |
Online courses typically cost around $15–50 per learner. Price matters less than whether you end up with documented, role-appropriate training on your own policies.
Next steps
- HIPAA for therapists in private practice →Scenario
- HIPAA training requirements →Requirement
- Access control and sign-in →Requirement
- Notifying patients of a breach →Requirement
Frequently asked questions
How long does HIPAA training take?
There is no required length. Online courses for general staff typically take 30 to 90 minutes; roles that handle more PHI or administer systems need more.
Is free HIPAA training good enough?
It can cover the basics. What a free course rarely covers is your organization's own policies and the records you need to keep, which the rule requires.
What topics should HIPAA training cover?
What PHI is and when it may be shared, patient rights, minimum necessary, safe use of email and messaging, passwords and MFA, phishing and malware, device security, how to report incidents, and your organization's specific policies.