Accepted by your auditor or your money back.

HIPAA Training: Health Compliance

Required by the HHS Office for Civil Rights under 45 CFR 164.530(b)(1): documented workforce training on protecting PHI for covered entities and business associates.

100% onlineInstant signed certificate

Medical front-office coordinator protecting PHI at the reception desk

Meets 45 CFR 164.530(b)(1)

Signed certificate included

Course Overview

Purpose-built HIPAA Privacy, Security, and Breach Notification Rule training for every workforce member who creates, receives, maintains, or transmits PHI.

Privacy & Security together

Map each lesson to 45 CFR 164.308, 164.310, and 164.530 training requirements.

Policy toolkit included

Downloadable acknowledgement log, risk analysis prompts, and breach notification timelines.

Manager-ready reporting

Assign seats, automate reminders, and export completion data for OCR requests.

OCR Enforcement

45 CFR 160.404

Civil money penalties, adjusted annually for inflation

HIPAA violations are enforced by the HHS Office for Civil Rights under 45 CFR Part 160, Subpart D.

Civil money penalties are set in tiers at 45 CFR 160.404 and adjusted annually for inflation, with separate breach-notification duties under 45 CFR 164.400–164.414. Documented workforce training under 45 CFR 164.530(b)(1) is a core safeguard.

Regulatory Basis

Every module maps to the exact regulation this course trains for. Each citation links to the official regulatory text.

  • 45 CFR 164.530(b)(1)

    Covered entities must train all workforce members on PHI policies and procedures as necessary and appropriate for their functions.

  • 45 CFR 164.530(b)(2)(ii)

    The covered entity must document that HIPAA training was provided.

  • 45 CFR Parts 160 & 164

    The HIPAA Privacy, Security, and Breach Notification Rules, including the security-awareness training standard at 164.308(a)(5) and breach notification at 164.400–164.414.

Who This Course Is For

HIPAA requires every workforce member with access to PHI to complete Privacy Rule training, including:

Clinic & practice administrators
Billing & revenue cycle teams
Health IT, product, and data teams handling PHI
Business associate account & implementation teams
Telehealth and patient support staff
Compliance, privacy, and security officers

Learning Objectives

1

Explain what qualifies as PHI, minimum necessary standards, and permitted disclosures across treatment, payment, and operations.

2

Apply administrative, physical, and technical safeguards from the HIPAA Security Rule—including access controls, device security, and encryption expectations.

3

Execute breach reporting, sanctions, and documentation requirements under 45 CFR 164.400-414 with clear timelines and escalation paths.

HIPAA Crosswalk & Certificate Preview

See how each module maps to HIPAA citations and what managers receive when learners complete the course.

  • Crosswalk references 45 CFR 164.308, 164.312, 164.530, and breach notification timelines.
  • Certificate includes learner attestation, role, quiz score, and completion timestamp.
  • Bonus toolkit includes acknowledgement logs, risk analysis prompts, and reporting deadlines.
HIPAA compliance certificate preview
HIPAA compliance training dashboard preview

Dashboard preview: assignments, reminders, and certificate exports in one place.

What’s Covered

Course modules across practical HIPAA privacy, security, and breach-response workflows.

Part 1 - Foundations & Privacy Rule

01HIPAA Foundations & Enforcement
02Identifying PHI & Minimum Necessary
03Privacy Rule Rights & Permitted Uses
04Administrative Safeguards & Workforce Management
05Technical Safeguards, Access Controls & Encryption

Part 2 - Security, Breach Response & Documentation

06Physical Safeguards, Workstations & Portable Devices
07Business Associates, BAAs & Vendor Oversight
08Incident Reporting & Breach Notification
09Documentation, Sanctions & Retention
10Role-Based Scenarios & Final Assessment

Get Your Team Started

Four steps to compliance. Most teams are up and running in under 10 minutes.

01

Purchase seats

Choose the number of covered-entity and business-associate seats you need today.

02

Assign to your team

Upload a roster or send invites from the dashboard and tag departments for reporting.

03

Monitor completion

Employees complete Privacy & Security modules, quizzes, and attestations at their pace.

04

Capture certificates

Certificates and acknowledgement logs are stored with exportable audit trails.

This is easy and exactly what our team needed to finish our HIPAA training.
Texas-based medical clinic chain

Frequently Asked Questions

Who is required to take HIPAA training?

Covered entities must train all workforce members on their PHI policies and procedures under 45 CFR 164.530(b)(1), and business associates have parallel obligations under the Security Rule. This includes clinical, billing, IT, and administrative staff who can access protected health information.

Under which regulation, and who enforces it?

The HIPAA Privacy, Security, and Breach Notification Rules at 45 CFR Parts 160 and 164, enforced by the U.S. HHS Office for Civil Rights (OCR). The workforce-training mandate is 164.530(b)(1); security-awareness training is addressed at 164.308(a)(5).

How often must HIPAA training be renewed?

HIPAA sets no fixed interval, but 45 CFR 164.530(b)(2)(i)(C) requires retraining of affected staff within a reasonable time after a material change in policies or procedures; OCR guidance treats periodic (commonly annual) refreshers as reasonable and appropriate.

Does HIPAA training need to be documented?

Yes. 45 CFR 164.530(b)(2)(ii) requires the covered entity to document that training was provided. This course issues a completion certificate and attestation for that record.

Is online HIPAA training accepted?

Yes; HIPAA specifies that workforce training be appropriate to job functions (164.530(b)(1)), not a delivery method, so documented online training satisfies the rule. This course is 100% online and self-paced.

What are the penalties for a HIPAA violation?

OCR imposes civil money penalties under 45 CFR Part 160, Subpart D (160.404), in tiers based on culpability, with amounts adjusted annually for inflation; separate breach-notification duties apply under 164.400–164.414.

How long does the course take, and who does NOT need it?

About 2 hours. Workers with no access to PHI and no role in privacy/security duties fall outside the workforce-training mandate, but most staff at a covered entity or business associate are in scope under 164.530(b)(1).

Which course do I need?

Related courses — here's who each one is for.

Best for
For anyone who touches hazmat shipments — the 1–2 hour baseline
Renewal
Every 3 years
Duration
1–2 hrs
View course
Best for
For drivers, loaders, and shipping staff who perform regulated tasks
Renewal
Every 3 years
Duration
6–8 hrs
View course
Best for
For anyone who prepares or handles dangerous goods that will fly
Renewal
Every 24 months for air work
Duration
4–5 hrs
View course
Best for
For generator-site staff and EHS teams who manage hazardous waste
Renewal
Annual review for LQG personnel
Duration
3–4 hrs
View course
HIPAA ComplianceThis course
Best for
For staff who work with patient information or healthcare data
Renewal
Change-triggered; commonly annual
Duration
2 hrs
Best for
For supervisors who decide when a CDL driver must be tested
Renewal
Once; no federal recurrence
Duration
2 hrs (60 + 60)
View course
Best for
For frontline leads and staff who need awareness, not authority
Renewal
None federally required
Duration
60–75 min
View course
Best for
For the named DER and HR or compliance staff who support them
Renewal
None federally fixed
Duration
2–3 hrs
View course

Pricing is shown on each course page and confirmed at checkout. Renewal intervals reflect the cited federal regulations.

Keep your workforce HIPAA-ready

Equip clinicians, revenue cycle, and health-tech teams with practical privacy safeguards, breach response workflows, and audit-ready documentation.

HIPAA Training — coming soon
Get notified