hipaa.systems
General provisions · 45 CFR 164.530(b), 164.308(a)(5)

HIPAA training requirements

Who must be trained under HIPAA, on what, how often, and how to document it — and what the rule does not actually require.

Checked 2026-10-06Sources 3

HIPAA training requirements at a glance

HIPAA requires covered entities to train every workforce member on their privacy policies and procedures — at hire, within a reasonable time, and again after any material policy change — and to document that training (45 CFR 164.530(b)). The Security Rule separately requires a security awareness and training program for all staff, including management (164.308(a)(5)). The regulation does not say training must be annual, but periodic refreshers are the norm.

Rules45 CFR 164.530(b) (Privacy Rule) and 164.308(a)(5) (Security Rule)
WhoAll workforce members — employees, volunteers, trainees, management
WhenWithin a reasonable time after joining, and after material changes to policies
Annual?Not stated in the rule; periodic security reminders are expected and yearly refreshers are common practice
ContentYour organization's own policies, plus security awareness: malware, log-ins, passwords
Document itKeep training records for six years

Two separate obligations

Privacy Rule training (164.530(b)). A covered entity must train all workforce members on its policies and procedures for protected health information, as needed for their jobs:

  • every member by the entity’s compliance date;
  • each new member within a reasonable period after joining;
  • members whose functions are affected by a material change to policies, within a reasonable period after the change;
  • and it must document that the training was provided.

Security awareness and training (164.308(a)(5)). Covered entities and business associates must run a security awareness and training program for all workforce members, including management. The addressable implementation specifications cover:

  • periodic security reminders;
  • protection from malicious software;
  • log-in monitoring;
  • password management.

What “training” has to mean in practice

The rule ties training to your own policies. A generic online course covers HIPAA fundamentals, but staff also need to know how your practice handles email, records requests, devices and incidents. The usual approach is a general course plus a short walkthrough of your policies, with a signed acknowledgment.

How often

The regulation does not use the word “annual”. It requires training at onboarding and after material changes, and an ongoing security awareness program. Most organizations run a yearly refresher, because it is the simplest way to show the program is ongoing.

Keeping records

Record who was trained, on what, and when. HIPAA documentation must be kept for six years (164.316(b)).

Tools and services where this matters

Guides

Frequently asked questions

Is annual HIPAA training required?

The regulation does not specify annual training. It requires training for new workforce members within a reasonable period, after material policy changes, and an ongoing security awareness program with periodic reminders. Many organizations train yearly to meet those obligations and show diligence.

Does HIPAA training have to come from an accredited provider?

No. HHS does not accredit or certify HIPAA training. What matters is that training covers your organization's policies and the security topics in 164.308(a)(5), and that you document it.

Do business associates need HIPAA training?

Yes. The Security Rule's security awareness and training standard applies to business associates as well as covered entities.