HIPAA training requirements for employees
Who has to be trained, when, how often, and — the part that actually gets asked about — what evidence proves it happened. Written for whoever in a small organization has ended up owning this.
Last reviewed .
The short version
- Training is required, for all workforce members, on your own policies and procedures.
- There is no statutory annual interval — but annual is the practice almost everyone follows, and it is defensible.
- New starters get trained within a reasonable period of joining; anyone affected by a material policy change gets retrained.
- The evidence is per person and dated. Keep it for six years.
- An individual can hold a certificate of completion. An organization cannot be 'HIPAA certified' — that designation does not exist.
Where the requirement comes from
Two separate rules land on training and people frequently conflate them. The Privacy Rule at 45 CFR 164.530(b) requires a covered entity to train all workforce members on the policies and procedures relevant to carrying out their functions. The Security Rule at 164.308(a)(5) separately requires a security awareness and training programme, including periodic security reminders, protection from malicious software, log-in monitoring and password management.
If you are a business associate rather than a covered entity, the Security Rule requirement applies to you directly, and your business associate agreements will typically commit you to training as well. Either way the practical answer is the same: train everyone, on your actual policies, and keep the records.
What good looks like
Role-relevant, not generic
The rule ties training to the workforce member's function. A billing specialist and a systems administrator do not need the same forty minutes, and a course that ignores that is weaker evidence as well as a worse use of everyone's time.
Delivered before access, not after
New starters should complete training within a reasonable period of joining — and ideally before they are granted access to patient information, because the completion date sitting after the access-grant date is exactly the kind of detail a reviewer notices.
Repeated when things change
A material change to your policies or procedures triggers retraining for anyone affected. New system, new workflow, a policy rewritten after an incident: each is a trigger, independent of your annual cycle.
Evidenced per person, with dates
The deliverable is not the course. It is the record: who, what, when, and what score if there was an assessment. That is what goes into an evidence pack and what a client's security questionnaire asks for.
Reinforced between sessions
The Security Rule contemplates ongoing security reminders as part of an awareness programme, not one annual event. Periodic reminders are cheap, and the records of having sent them cost nothing to keep.
Why “HIPAA certification” is not a thing
A great deal of training is sold on the promise of certification, and the distinction matters. An individual finishing a course can receive a certificate of completion — that is real, useful, and exactly what belongs in your evidence pack. An organization being “HIPAA certified” is not a thing: no such designation exists under the rules and no government body issues one.
HHS itself does not endorse or certify any private training. If a vendor implies their course makes your organization certified, that is a marketing claim about something that cannot be granted.
Training that chases people, so you do not have to
Record completions, let the reminders chase whoever falls behind, and get a dated certificate per person that drops straight into your evidence pack. Already run your own training? Record completions here and get the same certificates and renewal tracking.
Common questions
- How often is HIPAA training mandatory?
- Training itself is required — the Privacy Rule for all workforce members on your policies and procedures, the Security Rule for security awareness — but no fixed interval is named. New workforce members must be trained within a reasonable period, and again when a material change affects their job. Annual refreshers are the widely adopted practice because they are defensible and easy to evidence, not because a statute names twelve months.
- Is there free HIPAA training?
- Yes — HHS publishes free security awareness materials and the Medicare Learning Network offers free courses, and you can deliver training yourself. The catch is that the rules require training on your organization's own policies and procedures, which generic material cannot cover alone, and per-person dated records retained for six years. Free content plus no records fails the part that actually gets checked.
- What are the new HIPAA requirements for 2026?
- Nothing final has changed the training requirement itself. The Security Rule update proposed in January 2025 — which would make encryption, multi-factor authentication and asset inventories mandatory — had not been finalized as of our last review. The standing obligations are unchanged: train all workforce members including volunteers and trainees, retrain on material change, and keep dated per-person evidence.
Keep reading
- Vendor compliance checkerVerdicts on the tools small healthcare organizations actually run.
- HIPAA glossaryPlain-language definitions, each with its citation.
- HIPAA compliance checklistEvery requirement, in order, with the evidence that proves it.
- HIPAA compliance auditsThe three different things called an audit, and what each asks for.
- Practice management softwareHow to evaluate what a vendor is actually offering you.
- How we researchSourcing, review cadence and corrections policy.
- About the teamThe compliance officers, clinicians and security people behind the research.
Looking for the software rather than the explanation? Staff training and certificates.
Training is item 4 on the full compliance checklist →
A practical summary of published requirements, not legal advice. Citations are given so you can read the regulation directly. What is reasonable for your organization depends on its size and circumstances.