What training does HIPAA require for the workforce?
The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities to train all workforce members on their privacy policies for protected health information, at onboarding and after material policy changes, and to document it for six years. The HIPAA Security Rule separately requires covered entities and business associates to run a security awareness and training program for all workforce members, including management. Neither rule currently sets an annual training frequency.
By the Knowledge Foundry editorial team. How we write and check these pages
- Published
- Updated
- Reading time
- 8 min
- Jurisdiction
- United States (federal)
- Regulator
- Office for Civil Rights (OCR), US Department of Health and Human Services (HHS)
Key takeaways
- Two separate duties apply: Privacy Rule training at 45 CFR 164.530(b) for covered entities, and the Security Rule's security awareness and training standard at 45 CFR 164.308(a)(5) for covered entities and business associates.
- Privacy training is due for new workforce members within a reasonable period after they join and for anyone affected by a material policy change. The rule does not require annual refreshers.
- The workforce includes employees, volunteers, trainees and others under the entity's direct control, whether paid or not.
- Training documentation must be retained for six years from creation or the date it was last in effect, whichever is later.
- A January 2025 proposed rule would require security training at least every 12 months. As at September 2026 it has not been finalized and the current rule text is unchanged.
Who do HIPAA training requirements apply to?
HIPAA training requirements apply to covered entities and, for security training, to their business associates. Under 45 CFR 160.103, a covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a HIPAA transaction. A business associate is broadly a person or organization that handles protected health information on a covered entity's behalf, such as a billing, IT or cloud services provider.
For readers outside the United States: HIPAA is a 1996 federal statute. Its detailed requirements are in regulations issued by HHS in Title 45 of the Code of Federal Regulations (CFR), Parts 160 and 164. The Privacy Rule protects all protected health information in any form; the Security Rule protects electronic protected health information. HHS's Office for Civil Rights (OCR) enforces both. HIPAA is sector specific, so it does not cover all personal data the way a general data protection law such as the GDPR does.
The "workforce" that must be trained is defined widely: employees, volunteers, trainees and other persons whose work for the covered entity or business associate is under its direct control, whether or not they are paid. This page states the position as at September 2026, based on the eCFR text current at that date.
What does the Privacy Rule require for training?
The Privacy Rule requires a covered entity to train every workforce member on its privacy policies and procedures, to the extent needed for their role, at set trigger points. The standard in 45 CFR 164.530(b) states:
"A covered entity must train all members of its workforce on the policies and procedures with respect to protected health information required by this subpart and subpart D of this part, as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity."
Subpart D is the Breach Notification Rule, so privacy training also covers the entity's breach identification and reporting procedures. The implementation specifications set three timing points: each workforce member by the entity's original compliance date; each new workforce member "within a reasonable period of time" after joining; and each member whose functions are affected by a material change in policies or procedures, within a reasonable period after the change takes effect. The covered entity must document that the training was provided.
The same section requires a covered entity to apply appropriate sanctions against workforce members who fail to comply with its privacy policies (164.530(e)), which in practice depends on having trained people on what those policies say.
What does the Security Rule require for training?
The Security Rule requires covered entities and business associates to "implement a security awareness and training program for all members of its workforce (including management)." This is an administrative safeguard standard at 45 CFR 164.308(a)(5), with four implementation specifications, all currently marked "Addressable".
| Specification | Rule text | Typical training content |
|---|---|---|
| Security reminders | Periodic security updates. | Short, recurring updates on current threats and policy reminders. |
| Protection from malicious software | Procedures for guarding against, detecting, and reporting malicious software. | Recognizing phishing and malware, and how to report suspicious activity. |
| Log-in monitoring | Procedures for monitoring log-in attempts and reporting discrepancies. | Recognizing and reporting unusual account activity. |
| Password management | Procedures for creating, changing, and safeguarding passwords. | Password and credential handling, including not sharing credentials. |
"Addressable" does not mean optional. Under 45 CFR 164.306(d), the entity must assess whether each addressable specification is reasonable and appropriate in its environment and implement it if so, or document why not and implement an equivalent alternative where reasonable. The training standard itself is mandatory. The Security Rule also requires a sanction policy for workforce members who fail to comply with security policies, and periodic evaluation of the security program, which should include the training program.
Will HIPAA require annual security training?
Not yet. HHS proposed annual security training in a notice of proposed rulemaking (NPRM) published on January 6, 2025, but as at September 2026 no final rule has been published and the codified Security Rule text is unchanged. The NPRM, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, closed for comments on March 7, 2025.
The proposed rule would replace the current standard with a new security awareness training standard. Training would be required for each workforce member by the compliance date and "at least once every 12 months thereafter", for new workforce members no later than 30 days after they first have access to the entity's relevant electronic information systems, and within 30 days after a material policy change. It would also require ongoing reminders and threat notifications, and documentation of training. Separately, the NPRM proposes to remove the distinction between "addressable" and "required" implementation specifications.
Organizations do not need to wait for a final rule to adopt an annual cycle. Many already do, because an annual cycle makes it easier to show that the program is maintained. Anyone relying on this section should check the Federal Register for a final rule before treating the proposal as settled, since the content and dates may change.
What training records must be kept, and for how long?
Training documentation must be kept for six years from the date it was created or last in effect, whichever is later. For the Privacy Rule this comes from 164.530(j)(2); for the Security Rule, from 45 CFR 164.316(b)(2), which also requires documentation to be reviewed periodically and updated as needed.
- The current and past versions of the privacy and security policies each course was built on, with effective dates.
- A record of who was trained, on what, and when, including new starters and people affected by material policy changes.
- Evidence of security reminders and awareness updates issued, with dates.
- Any risk-based decision about addressable specifications, with the reasoning.
- Sanctions applied for non-compliance and any retraining that followed.
Keeping the policy version alongside the completion record matters because the training duty is tied to specific policies. For a method, see how to prepare training records for an audit and the audit trail definition.
What happens if HIPAA training is missing?
Missing or undocumented training is a violation of the relevant standard and can lead to civil money penalties. Under 45 CFR 160.404, penalty ranges rise with culpability, from violations the entity did not know about to willful neglect that is not corrected, with annual caps for identical violations. The amounts are adjusted for inflation each year and published in 45 CFR part 102.
OCR also resolves many cases through resolution agreements and corrective action plans, which commonly require updated policies and workforce training. State laws may add their own privacy training or breach requirements; these are outside the scope of this page.
How can organizations map HIPAA duties to learning outcomes and evidence?
Map each rule to a role-based outcome and the evidence OCR would expect to see. The table below is illustrative and should be tailored to each entity's own policies and systems.
| Requirement | Example learning outcome | Assessment evidence |
|---|---|---|
| 164.530(b) Privacy policies | Applies the minimum necessary standard when handling a records request in their role. | Scenario questions tied to the current policy version, with completion recorded within the entity's defined onboarding period. |
| 164.530(b) with subpart D Breach notification | Recognizes a potential breach and reports it through the internal procedure without delay. | Case-based assessment, plus records of reports made in practice. |
| 164.308(a)(5) Malicious software | Identifies a phishing message and reports it using the designated channel. | Simulated phishing results and report rates, retained with dates. |
| 164.308(a)(5) Password management | Creates and protects credentials in line with the entity's password procedure. | Policy attestation plus a short knowledge check. |
| 164.530(b)(2)(i)(C) Material change | Explains what changed in the updated policy and how it affects their tasks. | Targeted retraining assigned only to affected roles, recorded against the new policy version. |
For the wider method, see how to map training to compliance obligations and policy attestation. For a security awareness framework that complements the Security Rule, see NIST SP 800-50.
How does Knowledge Foundry approach this?
Knowledge Foundry links each HIPAA standard to the entity's own policy versions, the roles they apply to, and the learning outcomes and assessment points that evidence them. When a policy changes materially, the roles whose functions are affected can be identified from those links and assigned targeted retraining. See how this works for healthcare and life sciences organizations.
Frequently asked questions
Does HIPAA require annual training?
The current rules do not set an annual frequency. The Privacy Rule requires training for new workforce members and after material policy changes, and the Security Rule requires an ongoing security awareness program with periodic reminders. A January 2025 proposed rule would require security training at least every 12 months, but it had not been finalized as at September 2026.
Do business associates have to train their staff?
Yes, for security. Business associates must comply with the Security Rule, including the security awareness and training standard, for electronic protected health information. The Privacy Rule training standard in 164.530(b) is written for covered entities, but business associate agreements commonly require business associates to train their workforce on privacy obligations too.
Does HIPAA prescribe specific training content or hours?
No. HIPAA ties training to the entity's own policies and procedures and to what each workforce member needs for their role. It does not set hours, course formats or a curriculum. The Security Rule lists four implementation specifications (security reminders, malicious software, log-in monitoring and password management) that shape security content.
Do volunteers and students need HIPAA training?
Yes, if they fall within the workforce definition. The HIPAA workforce includes employees, volunteers, trainees and other persons whose conduct in performing work for the covered entity or business associate is under its direct control, whether or not they are paid.
Sources
- 45 CFR 164.530 Administrative requirements (Privacy Rule), Electronic Code of Federal Regulations
- 45 CFR 164.308 Administrative safeguards (Security Rule), Electronic Code of Federal Regulations
- 45 CFR 164.306 Security standards: General rules, Electronic Code of Federal Regulations
- 45 CFR 164.316 Policies and procedures and documentation requirements, Electronic Code of Federal Regulations
- 45 CFR 160.103 Definitions, Electronic Code of Federal Regulations
- 45 CFR 160.404 Amount of a civil money penalty, Electronic Code of Federal Regulations
- HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule, January 6, 2025), US Department of Health and Human Services, Federal Register
This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.