HIPAA security awareness training requirements
Last 30 days
Who this applies to
Covered entities and business associates — including any vendor touching electronic protected health information. Solo practices are in scope exactly as much as health systems.
The controls
Implement a security awareness and training program for all members of the workforce, explicitly including management. The rule draws no distinction between clinical and administrative roles, or between full-time employees and part-time contractors.
Security reminders, protection from malicious software, log-in monitoring, and password management. "Addressable" does not mean optional — you implement it, implement an equivalent alternative, or document why it is not reasonable and appropriate along with what you did instead.
How often you have to train
Periodic and ongoing. The rule does not name an interval, but a one-time orientation or a single annual email does not satisfy it — "security reminders" is an explicit specification.
What an assessor will ask to see
- Workforce-wide training records including management and contractors
- Evidence of recurring security reminders, not a single annual event
- Documentation of any addressable specification handled by an alternative, and why
- Records retained for six years — OCR audits can sample that far back
The detail that fails most assessments
The six-year documentation retention requirement catches organizations that switched platforms. If a previous vendor holds the records and you no longer have access, you cannot evidence the earlier period.
How Hook Security fits
Recurring simulations and micro-training satisfy the security reminders specification as a continuous program rather than an annual event, and every record is exportable so it survives a platform change.
Hook Security does not guarantee a passing assessment, and no platform can — compliance depends on your full control environment, your documentation and your assessor. Controls cited as published and last verified 2026-09-09. This is a reference, not legal advice.
The same records answer a cyber insurance questionnaire — see what underwriters ask for.
Show us your HIPAA scope. We will tell you what we cover.
Thirty minutes, a live account, and an honest answer about the gaps.