Practice administrator reviewing HIPAA security training records at a medical office workstation

Staff Training Is the HIPAA Requirement Most Practices Skip

October 02, 2026

A front-desk coordinator at a dental practice in Coral Gables called me last spring after three members of her staff clicked a phishing email that mimicked the practice's patient portal login page. The attackers had access to the scheduling system for 48 hours before anyone noticed. I sat with her for an hour going through what happened, and when I asked about their security training, she said every new hire watches a 15-minute onboarding video. That was the full program. Nobody had touched it in three years.

This is a pattern I see across South Florida medical and dental practices. Staff get a one-time orientation video, and the practice checks a mental compliance box. The HIPAA Security Rule doesn't work that way. Under 45 CFR §164.308(a)(5), covered entities must implement a security awareness and training program for every member of the workforce, documented, tracked per individual, and updated when your systems, operations, or threats change.

Skipping it is not a gray area. OCR's audit protocol asks for training records, attendance logs, and program documentation. If your answer is a three-year-old onboarding video with no written records, that's a finding. In breach investigations, OCR has cited inadequate workforce training as a contributing factor in enforcement actions, including a $1.04 million settlement with Lifespan Health System in 2021 where a stolen unencrypted laptop and missing workforce training policies were both named in the resolution agreement.

Key Takeaways

  • HIPAA §164.308(a)(5) requires security awareness training for every workforce member, including contractors and part-time staff, documented by name, date, and content covered.
  • Training records must be retained for six years under the documentation requirement at §164.316(b)(2).
  • OCR resolution agreements regularly cite inadequate workforce training as a deficiency, including in cases that started with a single phishing click.
  • A compliant program covers phishing recognition, password policies, incident reporting, physical security, and the minimum necessary principle, updated when your environment changes.
  • You don't need a full-time IT department to run a compliant program. You need a documented plan, a named person accountable for it, and records that survive an audit.

What the HIPAA Security Rule Requires for Workforce Training

The Four Components OCR Checks

The Security Rule lists workforce security awareness and training as an addressable implementation specification under §164.308(a)(5)(ii). "Addressable" doesn't mean optional. It means you either implement it or document in writing why a reasonable alternative achieves the same protection. For staff training, no alternative exists in practice because the threat the rule guards against is human error at the point of access to protected health information.

The four components OCR checks against are:

  • Security reminders: periodic communications about current threats, policy changes, and security expectations
  • Protection from malicious software: training staff to recognize and report suspicious emails, attachments, and links
  • Log-in monitoring: training staff to notice and report unauthorized or unexpected system access
  • Password management: policies and training on creating, storing, and changing passwords

None of these is a one-time event. A phishing attack today looks different from one three years ago. If your training hasn't been updated since your EHR switch or since you added telehealth visits, it doesn't cover your current threat surface. The four components need to stay current with how your practice runs.

Contractors and Part-Time Staff Count

One of the most common gaps is a practice that trains full-time clinical staff but skips the part-time receptionist, the billing contractor who accesses the EHR remotely, or the medical records company that stores paper charts off-site. Under HIPAA, "workforce" includes employees, volunteers, trainees, and other persons whose conduct is under the direct control of the covered entity, whether or not they're on payroll. If a contractor accesses patient data, they're workforce for training purposes.

Business associates have their own HIPAA obligations under the Security Rule and need their own training program on your end. For a small practice, that means your business associate agreement should confirm in writing that the associate has a compliant workforce training program and knows what to do if a breach occurs involving your data.

Actionable tip: Pull your current staff roster, including part-time and contracted roles that touch patient data, and map each person to the date and content of their last security training. If anyone is more than 12 months out, schedule their refresher this week before the next incident makes it urgent.

What OCR Looks for When It Audits Your Training Records

The Documentation Standard

OCR's audit protocol includes direct requests for workforce training policies, training logs by employee name and date, and records of training content. Verbal confirmation that staff "know what to do" is not a record. A shared folder with a training video link and no completion log is not a record. To hold up under audit, your documentation needs:

  • The training date for each individual
  • The content covered, either by course name, curriculum summary, or the training materials themselves
  • A signature or electronic confirmation from the trainee
  • Retention for at least six years from the date of creation or the date it was last in effect, whichever is later

When OCR investigates a breach, one of its first document requests is your workforce training history. In the Lifespan case and in other resolution agreements over the past five years, the pattern is consistent: a breach occurs, OCR investigates, and among the findings is that workforce training records were either absent or didn't reflect actual coverage of all workforce members.

When You Must Update Training

The Security Rule requires training updates "as necessary." OCR has interpreted this to include any material change to your environment: adding a new EHR, migrating to a cloud-based system, shifting staff to remote access, adding a patient portal, or experiencing a security incident. If your last training was before your telehealth platform went live, you have a gap. Staff who access your telehealth system need training on how that platform handles electronic protected health information and what they should and shouldn't do in it.

Your HIPAA compliance program should include a trigger list: events that automatically queue a training review. EHR upgrade, new remote access tool, security incident, annual review, regulatory change. Each trigger means a training review within 30 days and documented updates to content if the review finds a gap.

The access control requirements in the Security Rule connect directly to training here. If you've updated who has access to which systems, you need a corresponding training update that covers the new access scope and any new responsibilities that come with it.

Actionable tip: Set a calendar reminder for the first week of each quarter to review your training program against any system or policy changes from the prior three months. If nothing changed, document that review anyway. A dated note saying "reviewed, no updates required" is still a record.

What a Compliant Training Program Covers

Phishing and Social Engineering

Phishing is the entry point in the majority of healthcare breaches. Your training doesn't need to be a graduate cybersecurity course, but it needs to cover what a phishing email looks like, what staff should do when they receive one, and what they should not do. That means: don't click links in unexpected emails asking for credentials, don't open attachments from unknown senders, call the sender through a number you already have if you're uncertain, and report it to whoever handles IT at your practice.

Specific scenarios with real examples work better than abstract warnings. Show staff an example of a spoofed email that looks like it came from their EHR vendor or their email provider. Walk through what the red flags are. Many practices also run simulated phishing tests, sending fake phishing emails to staff and tracking who clicks. You're not required to do this under HIPAA, but it identifies who needs additional training based on actual behavior rather than a completion certificate.

Password and Access Management

HIPAA's access control requirements make clear that each workforce member needs a unique user ID and that sharing login credentials is prohibited. Staff sharing logins is among the most common findings in OCR investigations of small practices. Training must address this directly: why shared credentials create liability, how to request access to a shared resource through your IT provider, and what to do when a colleague needs temporary access to a system.

Password management training should cover your current password policy: minimum length, when passwords expire, and what a password manager is. Vague guidance like "use a strong password" with no definition doesn't hold up when OCR asks what the training specifically covered. Put the policy in writing and train staff on the written version, not a verbal summary of it.

Incident Reporting

Staff can't report what they don't recognize as a problem. Your training must cover what constitutes a security incident, including things staff might not think to report: an email they clicked before noticing it looked suspicious, a device they left unattended in a waiting room, or a call from someone claiming to be IT support who asked for their login. Each of these is a reportable event under your Security Rule policies, and the sooner it's reported, the sooner containment can start.

Walk staff through the exact reporting process: who to call, what to say, what to preserve. Document that process in your HIPAA policy manual and make sure every staff member knows where to find it. A one-page reference card at each workstation, covering the IT contact number and what information to have ready, removes the friction that causes staff to delay reporting.

Actionable tip: Post a one-page incident reporting reference card at each workstation covering the IT contact number, the three questions to answer when reporting (what happened, when you noticed, what systems were involved), and a note that partial information is still worth reporting immediately. The goal is to lower the barrier to picking up the phone.

If you're not sure your current training program would hold up to OCR scrutiny, a free HIPAA security assessment from Gradient Data Solutions identifies exactly where your program has gaps and what to fix before your next renewal or audit cycle.

Building the Program When You Don't Have an IT Team

Assign One Person to Own It

For practices without dedicated IT staff, the most common failure mode is no one owns the training program. The practice administrator assumes the billing manager handles it; the billing manager assumes HR covered it at onboarding. Assign one person, by name and title in your HIPAA policies, to manage workforce security training. That person doesn't need a technical background. They need to schedule training, track completion, file records, and flag when updates are needed.

If you work with a managed IT provider, ask what they provide for workforce training. A good provider includes security awareness training in their service, delivers it on a schedule, and gives you completion logs to keep in your compliance file. If they don't, that's a conversation worth having before your next cyber insurance renewal asks for proof of training.

Delivery Options That Work for Small Practices

You have several options: a live session run by your IT provider or a HIPAA consultant, a security awareness training platform like KnowBe4 or Proofpoint (both widely used in healthcare), a video-based course from a HIPAA training vendor, or a structured internal program you build from published OCR guidance. A platform subscription automates scheduling, tracks completion, and produces the records you need for audit. For most small practices, it's the most defensible and least burdensome option.

Whatever you use, keep completion records for every participant for six years. If you run a live session, a sign-in sheet with the date, trainer name, and a one-paragraph content summary is a valid record. If you use a platform, export completion reports quarterly and store them in your compliance folder. The format matters less than the habit of doing it consistently and storing what you produce.

Visit our healthcare IT page for more on what a compliance program looks like for small and mid-size practices in South Florida.

Frequently Asked Questions

Does HIPAA require annual training?

The Security Rule doesn't specify a frequency, but OCR's audit protocol and resolution agreements consistently treat annual training as the baseline for compliant practices. If you train less frequently than once a year, you need a documented rationale for why your environment doesn't warrant annual updates. That's a difficult case to make in healthcare, where phishing tactics and regulatory requirements change year over year.

Do I need to train staff who don't touch patient records?

If they're workforce under HIPAA, yes. A front-desk staff member who never opens the EHR still receives patient calls, handles paper documents, and can be targeted by social engineering. Training scope should match your actual operations, but the default is to include everyone with any access to the practice's systems or physical space where protected health information is stored or processed.

What if a staff member refuses to complete training?

Document the refusal in writing and apply your workforce sanctions policy. Under §164.308(a)(1), covered entities must have a sanctions policy for staff who fail to comply with security policies. Refusing to complete required training is a compliance violation. If you don't have a written sanctions policy that covers this, that's a separate gap worth closing now.

Is a HIPAA training certificate from an online course enough?

It depends on what the course covers and when it was completed. A general HIPAA overview certificate from two or three years ago doesn't address your current systems or the specific threats targeting healthcare practices today. Use it as a foundation, but supplement it with content specific to your environment: your EHR, your remote access setup, your incident reporting process, and any system changes since the certificate was issued.

Can we do training in a staff meeting instead of a formal course?

Yes, but document it the same way you would a formal course. Write an agenda covering what was addressed, keep a sign-in sheet, and file both. The format matters less than the documentation. OCR's question is whether you can prove the training happened, who attended, and what it covered.

Get Your Training Program Audit-Ready

The gap between "we did a video at onboarding" and a program that holds up under OCR scrutiny is smaller than most practices think. It takes a named owner, a documented schedule, records by individual, and content updated when your environment changes. If you haven't reviewed your program this year, or you're not sure what an audit would find, let's look at it together. A free HIPAA and security assessment takes about an hour and gives you a clear picture of what your program covers, what it's missing, and how to close the gap before your next insurance renewal or audit.

healthcarehipaacompliancestaff-trainingsecurity
Back to Blog

Get Your Questions Answered

We're happy to help. Call us at (786) 386-1092 or send us a message.