HIPAA training requirements
Who must be trained under HIPAA, on what, how often, and how to document it — and what the rule does not actually require.
HIPAA training requirements at a glance
HIPAA requires covered entities to train every workforce member on their privacy policies and procedures — at hire, within a reasonable time, and again after any material policy change — and to document that training (45 CFR 164.530(b)). The Security Rule separately requires a security awareness and training program for all staff, including management (164.308(a)(5)). The regulation does not say training must be annual, but periodic refreshers are the norm.
| Rules | 45 CFR 164.530(b) (Privacy Rule) and 164.308(a)(5) (Security Rule) |
|---|---|
| Who | All workforce members — employees, volunteers, trainees, management |
| When | Within a reasonable time after joining, and after material changes to policies |
| Annual? | Not stated in the rule; periodic security reminders are expected and yearly refreshers are common practice |
| Content | Your organization's own policies, plus security awareness: malware, log-ins, passwords |
| Document it | Keep training records for six years |
Two separate obligations
Privacy Rule training (164.530(b)). A covered entity must train all workforce members on its policies and procedures for protected health information, as needed for their jobs:
- every member by the entity’s compliance date;
- each new member within a reasonable period after joining;
- members whose functions are affected by a material change to policies, within a reasonable period after the change;
- and it must document that the training was provided.
Security awareness and training (164.308(a)(5)). Covered entities and business associates must run a security awareness and training program for all workforce members, including management. The addressable implementation specifications cover:
- periodic security reminders;
- protection from malicious software;
- log-in monitoring;
- password management.
What “training” has to mean in practice
The rule ties training to your own policies. A generic online course covers HIPAA fundamentals, but staff also need to know how your practice handles email, records requests, devices and incidents. The usual approach is a general course plus a short walkthrough of your policies, with a signed acknowledgment.
How often
The regulation does not use the word “annual”. It requires training at onboarding and after material changes, and an ongoing security awareness program. Most organizations run a yearly refresher, because it is the simplest way to show the program is ongoing.
Keeping records
Record who was trained, on what, and when. HIPAA documentation must be kept for six years (164.316(b)).
Tools and services where this matters
Guides
- HIPAA certification →Is there an official HIPAA certification? What employers mean when they ask for one, what a certificate actually proves, and how to get one.
- HIPAA compliance →What HIPAA compliance actually means for a small practice or health tech company, what it consists of, and what it is not.
- HIPAA compliance certification for organizations →Can an organization or product be HIPAA certified? What the rule requires instead, what third-party assessments prove, and how to read a vendor's "HIPAA certified" badge.
- HIPAA training →What HIPAA training has to cover, who needs it, how to structure a program for a small practice, and how to judge an online course.
Related requirements
Frequently asked questions
Is annual HIPAA training required?
The regulation does not specify annual training. It requires training for new workforce members within a reasonable period, after material policy changes, and an ongoing security awareness program with periodic reminders. Many organizations train yearly to meet those obligations and show diligence.
Does HIPAA training have to come from an accredited provider?
No. HHS does not accredit or certify HIPAA training. What matters is that training covers your organization's policies and the security topics in 164.308(a)(5), and that you document it.
Do business associates need HIPAA training?
Yes. The Security Rule's security awareness and training standard applies to business associates as well as covered entities.