HIPAA training requirements for small practices
HIPAA requires every practice to train its workforce, and to be able to prove it. The rules are short and flexible, which is why small practices often under do it, or over buy it.
Free preview before you pay. Editable Word files. 14 day refund.
What the rules say
- Privacy Rule, 45 CFR 164.530(b). Train every workforce member on your privacy policies and procedures, as needed for their role. New people must be trained within a reasonable time after joining, and everyone affected must be retrained within a reasonable time after a material policy change.
- Security Rule, 45 CFR 164.308(a)(5). Run a security awareness and training program for all workforce members, including management, covering security reminders, protection from malicious software, log in monitoring, and password management.
- Documentation. Record that training happened, and keep the records for six years.
Who counts as workforce
Employees, volunteers, trainees, and anyone else whose work is under the direct control of the practice, paid or not. Front desk staff, billing staff, and the clinician who owns the practice all count.
How often
HIPAA does not set a fixed interval. It requires training at onboarding and after material changes, and a security program that is ongoing. In practice, auditors expect to see training at least once a year, and yearly training with short reminders in between is a sensible default for a small office.
What to cover
- What protected health information is, with examples from your own office
- Your privacy policies: who may see what, minimum necessary, and verifying identity before sharing
- Patient rights, and how to route requests to the Privacy Officer
- Phishing, passwords, multifactor authentication, and locking screens
- Using email, texting, and personal phones with patient information
- How to report a suspected breach, and that nobody is punished for reporting in good faith
- Sanctions for breaking the policies
What to record
There is no official HIPAA certificate for individuals, and HHS does not certify training. A certificate from a training vendor is a useful record, not a credential.
- The date and the topics covered
- Who attended, with each person signing
- Who delivered the training
- The materials used, kept with the record
Questions
Is annual HIPAA training required?
HIPAA does not state an annual requirement in those words, but it requires ongoing security awareness training and retraining after policy changes. Yearly training is the common expectation and the safest default.
Does the practice owner need HIPAA training?
Yes. Everyone in the workforce, including management and owners who handle patient information, should be trained and recorded.
What does the kit include for training?
A workforce confidentiality agreement, a training log, and an access checklist, alongside the policies your training should cover.
Full HIPAA Policy Kit, $129
- Notice of Privacy Practices, updated for the 2026 rules, plus the acknowledgment form
- 22 Privacy policies and procedures
- 19 Security policies mapped to the Security Rule
- Breach Notification policy with a risk assessment form and log
- Business Associate Agreement for your vendors
- Workforce confidentiality agreement, training log, and access checklist
- Security Risk Analysis worksheet, pre filled from your answers
- Patient request forms, plus a California addendum for California practices
More guides
- HIPAA compliance for dental offices: what auditors actually check
- HIPAA compliance checklist for small medical practices in California
- The HIPAA security risk assessment, explained for small practices
- Notice of Privacy Practices template, updated for 2026
- HIPAA policies for chiropractic offices
- HIPAA policies for physical therapy practices
- HIPAA policies for mental health and behavioral health practices
- HIPAA policies for optometry practices
- HIPAA for med spas and aesthetics practices
- HIPAA policies and procedures for small medical practices
- HIPAA business associate agreement: what it must include
- HIPAA compliance checklist for small practices, 2026
- HIPAA breach notification deadline calculator
- Free HIPAA policy templates: where to get them, and what they leave out
- HIPAA policies for podiatry practices
- HIPAA policies for dermatology practices
- HIPAA policies for pediatric practices
- HIPAA for acupuncture practices
- HIPAA policies for speech therapy practices
Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.