Skip to main content
compliance

HIPAA Training Requirements: Who Needs It, What to Cover, and How Often

, Director of Growth
HIPAA Training Requirements: Who Needs It, What to Cover, and How Often

If your organization touches patient health information, HIPAA training is not optional. The law requires covered entities and their business associates to train every member of their workforce, and to be able to prove it. The good news: the requirements are shorter and more practical than most people expect.

This guide covers what HIPAA actually requires, who needs training, how often, what it should cover, and what changed in 2026. It is written for the people who have to make training happen: practice managers, compliance leads, IT teams, and the MSPs who support healthcare clients.

The short answer: HIPAA requires covered entities and business associates to train all workforce members on their privacy and security policies, train new hires within a reasonable time, retrain when policies materially change, and keep documentation for six years. The law does not set a frequency, but annual refresher training is the accepted standard.

What is HIPAA?

HIPAA is the Health Insurance Portability and Accountability Act of 1996, a federal law that sets national standards for protecting health information. For training purposes, four sets of rules matter most:

  • The Privacy Rule governs how protected health information (PHI) can be used and disclosed, in any form: paper, spoken, or electronic.
  • The Security Rule requires administrative, physical, and technical safeguards for electronic PHI (ePHI).
  • The Breach Notification Rule requires notifying patients, HHS, and in larger breaches the media, when unsecured PHI is compromised.
  • The HITECH Act (2009) and the Omnibus Rule (2013) strengthened enforcement and made business associates directly liable for complying with the Security Rule.

What does HIPAA require for training?

Two rules contain the training requirements, and they work together.

Privacy Rule training (45 CFR 164.530(b))

Covered entities must train all workforce members on their policies and procedures for PHI, as necessary and appropriate for each person’s role. New workforce members must be trained within a reasonable period after they start, and anyone affected by a material change in policy must be retrained within a reasonable period after the change.

Security Rule training (45 CFR 164.308(a)(5))

Covered entities and business associates must run a security awareness and training program for all workforce members, including management. The rule lists four topics to address:

  • Security reminders: periodic updates, not a one-time course.
  • Protection from malicious software: including phishing and malicious attachments.
  • Log-in monitoring: recognizing and reporting unusual access attempts.
  • Password management: creating, changing, and protecting passwords.

Documentation

Training has to be documented. Keep records of who was trained, on what, and when, for six years. If you are ever audited or investigated by the HHS Office for Civil Rights, those records are your proof. HHS publishes free HIPAA training materials for professionals if you want the regulator’s own framing.

Who needs HIPAA training?

HIPAA applies to two groups of organizations, and training applies to everyone in their workforce: employees, volunteers, trainees, and anyone else whose work is under the organization’s direct control.

Covered entities

  • Health care providers that transmit health information electronically: hospitals, clinics, physicians, dentists, chiropractors, psychologists, nursing homes, and pharmacies.
  • Health plans: health insurers, HMOs, company health plans, and government programs like Medicare and Medicaid.
  • Health care clearinghouses that process health information between providers and payers, like billing services.

Business associates

A business associate is any person or company that creates, receives, maintains, or transmits PHI on behalf of a covered entity. That includes billing companies, cloud and data storage providers, transcription services, law and accounting firms, and IT providers and MSPs that can access a client’s systems containing ePHI. Subcontractors of business associates are business associates too.

Business associates sign a business associate agreement with the covered entity and are directly liable for Security Rule compliance, which includes the security awareness and training requirement.

How often is HIPAA training required?

The law sets three triggers and no fixed schedule:

  • At onboarding: within a reasonable period after someone joins.
  • After material changes: when policies or procedures that affect someone’s job change.
  • On an ongoing basis: the Security Rule’s security reminders are continuous by design.

In practice, annual refresher training is what auditors, cyber insurers, and business associate agreements expect, and it is the easiest standard to defend. Many organizations pair the annual course with short monthly security reminders, which covers both rules at once.

What should HIPAA training cover?

HIPAA does not prescribe a curriculum, so build it around your policies and each person’s exposure to PHI. A solid program covers:

  • What PHI and ePHI are: names, dates, record numbers, diagnoses, payment details, and anything else that identifies a patient and relates to their health or care.
  • Uses and disclosures: PHI can be used for treatment, payment, and health care operations. Many other uses and disclosures need the patient’s written authorization. Disclosures are only required in two cases: to the patient under their right of access, and to HHS during an investigation.
  • The minimum necessary standard: use and share only the PHI needed for the task.
  • Patient rights: access to and copies of their records, amendments, an accounting of disclosures, and restrictions on some uses.
  • Safeguards in daily work: screen locks, clean desks, secure messaging, encrypted devices, and conversations that cannot be overheard.
  • Phishing and social engineering: the most common way attackers reach health data. Training should show what a real attack looks like, not just define the term.
  • Incident and breach reporting: who to tell, how fast, and why reporting a mistake early is always the right call.
  • Sanctions: your organization’s consequences for violating policy, which HIPAA requires you to have and apply.

Role-based training works best. A front-desk coordinator, a nurse, and a systems administrator face different risks with the same patient data, and generic training teaches none of them what their day actually looks like.

Breach notification basics

Everyone should know that a breach has deadlines attached. Under the Breach Notification Rule, affected individuals must be notified without unreasonable delay and no later than 60 days after the breach is discovered. Breaches affecting 500 or more people must also be reported to HHS within that window, and to prominent media outlets when more than 500 residents of a single state or jurisdiction are affected. Smaller breaches are logged and reported to HHS annually. Fast internal reporting is what makes those deadlines possible.

HIPAA penalties in 2026

Civil penalties are tiered by how culpable the organization was, from not knowing about a violation to willful neglect that went uncorrected. After HHS’s January 2026 inflation adjustment, they start at $145 per violation and reach more than $2.19 million per calendar year for the most serious tier. Criminal penalties apply when PHI is obtained or disclosed knowingly and wrongfully, and can include fines and up to 10 years in prison.

Documented, ongoing training matters here: it is one of the clearest signals that an organization was acting in good faith rather than neglecting its obligations.

What’s changing: the proposed HIPAA Security Rule update

HHS proposed the first major overhaul of the Security Rule in January 2025. It would make safeguards like multi-factor authentication and encryption required rather than “addressable,” and would add requirements for asset inventories, annual compliance audits, and faster incident response. As of September 2026, the rule has not been finalized.

Do not wait for it. Multi-factor authentication, phishing awareness, and documented training are already expected as part of reasonable risk management, and most cyber insurers require them today.

Is there an official HIPAA certification?

No. HHS does not endorse or recognize any private HIPAA “certification” for people or organizations. A certificate of completion from a training course is still valuable, because it documents that someone was trained, but it is evidence of training, not a government credential.

How to make HIPAA training stick

  • Keep it short and frequent. A long annual course is forgotten by spring. Short modules plus regular reminders hold up far better.
  • Make it about real situations. The hallway conversation, the misdirected fax, the urgent email from the “CEO.” People remember stories, not statute numbers.
  • Match training to roles. Clinical staff, administrative staff, and IT leadership need different depth on the same rules.
  • Practice with phishing simulations. Safe, realistic practice builds the reflex to pause and report.
  • Track completion automatically. If proving training takes a spreadsheet hunt, it will not survive an audit.

For MSPs: HIPAA training is part of the job

If you manage IT for a medical practice, dental office, or any other covered entity, you are almost certainly a business associate. That means your own team needs security awareness training, and your healthcare clients need a way to train and document their staff.

It is also an opportunity. Healthcare clients know they need HIPAA training and rarely have time to run it. Delivering it as part of your security stack makes you more valuable at renewal and gives you documentation to bring to every QBR.

HIPAA training from Hook Security

Hook Security’s HIPAA courses are built the same way as all of our training: short, story-driven, and designed to be watched, not skipped. The library includes:

Every plan includes compliance training alongside security awareness training, phishing simulations, and automated, client-ready reporting. Book a demo to see the HIPAA courses in action. For how Hook maps to HIPAA requirements, see our HIPAA compliance page.

Frequently asked questions

Is HIPAA training required by law?

Yes. The Privacy Rule requires covered entities to train their workforce on PHI policies and procedures, and the Security Rule requires covered entities and business associates to run a security awareness and training program for all workforce members, including management.

How often do employees need HIPAA training?

HIPAA requires training at onboarding, after material policy changes, and ongoing security reminders. It does not set an exact frequency, but annual refresher training is the accepted standard and what most auditors and insurers expect.

How long does HIPAA training take?

There is no required length. Core HIPAA courses typically take 30 to 60 minutes, and role-based modules often take 15 to 20. Hook’s core HIPAA course takes about 30 minutes, with 16-minute role-based courses for clinical, administrative, and IT teams.

Do business associates need HIPAA training?

Yes. Business associates are directly liable for complying with the HIPAA Security Rule, which includes a security awareness and training program for their workforce. Many business associate agreements also require it explicitly.

Do MSPs need to be HIPAA compliant?

An MSP that can access a covered entity’s systems containing ePHI is a business associate, so yes: it needs a business associate agreement, Security Rule safeguards, and security awareness training for its own team.

How long should HIPAA training records be kept?

Six years. HIPAA requires documentation of policies, procedures, and required activities, including training, to be retained for six years from creation or from when it was last in effect, whichever is later.

This guide is general information, not legal advice. For questions about your specific obligations, talk to your compliance officer or a healthcare attorney.

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.