HIPAA Training: Health Compliance
Required by the HHS Office for Civil Rights under 45 CFR 164.530(b)(1): documented workforce training on protecting PHI for covered entities and business associates.
100% onlineInstant signed certificate

Meets 45 CFR 164.530(b)(1)
Signed certificate included
Course Overview
Purpose-built HIPAA Privacy, Security, and Breach Notification Rule training for every workforce member who creates, receives, maintains, or transmits PHI.
Privacy & Security together
Map each lesson to 45 CFR 164.308, 164.310, and 164.530 training requirements.
Policy toolkit included
Downloadable acknowledgement log, risk analysis prompts, and breach notification timelines.
Manager-ready reporting
Assign seats, automate reminders, and export completion data for OCR requests.
45 CFR 160.404
Civil money penalties, adjusted annually for inflation
HIPAA violations are enforced by the HHS Office for Civil Rights under 45 CFR Part 160, Subpart D.
Civil money penalties are set in tiers at 45 CFR 160.404 and adjusted annually for inflation, with separate breach-notification duties under 45 CFR 164.400–164.414. Documented workforce training under 45 CFR 164.530(b)(1) is a core safeguard.
Regulatory Basis
Every module maps to the exact regulation this course trains for. Each citation links to the official regulatory text.
- 45 CFR 164.530(b)(1)
Covered entities must train all workforce members on PHI policies and procedures as necessary and appropriate for their functions.
- 45 CFR 164.530(b)(2)(ii)
The covered entity must document that HIPAA training was provided.
- 45 CFR Parts 160 & 164
The HIPAA Privacy, Security, and Breach Notification Rules, including the security-awareness training standard at 164.308(a)(5) and breach notification at 164.400–164.414.
Who This Course Is For
HIPAA requires every workforce member with access to PHI to complete Privacy Rule training, including:
Learning Objectives
Explain what qualifies as PHI, minimum necessary standards, and permitted disclosures across treatment, payment, and operations.
Apply administrative, physical, and technical safeguards from the HIPAA Security Rule—including access controls, device security, and encryption expectations.
Execute breach reporting, sanctions, and documentation requirements under 45 CFR 164.400-414 with clear timelines and escalation paths.
HIPAA Crosswalk & Certificate Preview
See how each module maps to HIPAA citations and what managers receive when learners complete the course.
- Crosswalk references 45 CFR 164.308, 164.312, 164.530, and breach notification timelines.
- Certificate includes learner attestation, role, quiz score, and completion timestamp.
- Bonus toolkit includes acknowledgement logs, risk analysis prompts, and reporting deadlines.


Dashboard preview: assignments, reminders, and certificate exports in one place.
What’s Covered
Course modules across practical HIPAA privacy, security, and breach-response workflows.
Part 1 - Foundations & Privacy Rule
Part 2 - Security, Breach Response & Documentation
Get Your Team Started
Four steps to compliance. Most teams are up and running in under 10 minutes.
Purchase seats
Choose the number of covered-entity and business-associate seats you need today.
Assign to your team
Upload a roster or send invites from the dashboard and tag departments for reporting.
Monitor completion
Employees complete Privacy & Security modules, quizzes, and attestations at their pace.
Capture certificates
Certificates and acknowledgement logs are stored with exportable audit trails.
“This is easy and exactly what our team needed to finish our HIPAA training.”
Frequently Asked Questions
Who is required to take HIPAA training?
Covered entities must train all workforce members on their PHI policies and procedures under 45 CFR 164.530(b)(1), and business associates have parallel obligations under the Security Rule. This includes clinical, billing, IT, and administrative staff who can access protected health information.
Under which regulation, and who enforces it?
The HIPAA Privacy, Security, and Breach Notification Rules at 45 CFR Parts 160 and 164, enforced by the U.S. HHS Office for Civil Rights (OCR). The workforce-training mandate is 164.530(b)(1); security-awareness training is addressed at 164.308(a)(5).
How often must HIPAA training be renewed?
HIPAA sets no fixed interval, but 45 CFR 164.530(b)(2)(i)(C) requires retraining of affected staff within a reasonable time after a material change in policies or procedures; OCR guidance treats periodic (commonly annual) refreshers as reasonable and appropriate.
Does HIPAA training need to be documented?
Yes. 45 CFR 164.530(b)(2)(ii) requires the covered entity to document that training was provided. This course issues a completion certificate and attestation for that record.
Is online HIPAA training accepted?
Yes; HIPAA specifies that workforce training be appropriate to job functions (164.530(b)(1)), not a delivery method, so documented online training satisfies the rule. This course is 100% online and self-paced.
What are the penalties for a HIPAA violation?
OCR imposes civil money penalties under 45 CFR Part 160, Subpart D (160.404), in tiers based on culpability, with amounts adjusted annually for inflation; separate breach-notification duties apply under 164.400–164.414.
How long does the course take, and who does NOT need it?
About 2 hours. Workers with no access to PHI and no role in privacy/security duties fall outside the workforce-training mandate, but most staff at a covered entity or business associate are in scope under 164.530(b)(1).
Which course do I need?
Related courses — here's who each one is for.
- Best for
- For anyone who touches hazmat shipments — the 1–2 hour baseline
- Renewal
- Every 3 years
- Duration
- 1–2 hrs
- Best for
- For drivers, loaders, and shipping staff who perform regulated tasks
- Renewal
- Every 3 years
- Duration
- 6–8 hrs
- Best for
- For anyone who prepares or handles dangerous goods that will fly
- Renewal
- Every 24 months for air work
- Duration
- 4–5 hrs
- Best for
- For generator-site staff and EHS teams who manage hazardous waste
- Renewal
- Annual review for LQG personnel
- Duration
- 3–4 hrs
- Best for
- For staff who work with patient information or healthcare data
- Renewal
- Change-triggered; commonly annual
- Duration
- 2 hrs
- Best for
- For supervisors who decide when a CDL driver must be tested
- Renewal
- Once; no federal recurrence
- Duration
- 2 hrs (60 + 60)
- Best for
- For frontline leads and staff who need awareness, not authority
- Renewal
- None federally required
- Duration
- 60–75 min
- Best for
- For the named DER and HR or compliance staff who support them
- Renewal
- None federally fixed
- Duration
- 2–3 hrs
Pricing is shown on each course page and confirmed at checkout. Renewal intervals reflect the cited federal regulations.
Keep your workforce HIPAA-ready
Equip clinicians, revenue cycle, and health-tech teams with practical privacy safeguards, breach response workflows, and audit-ready documentation.