Skip to main content
Trusted by Hundreds of MSPs

HIPAA security awareness training requirements

HIPAA Security Rule — 45 CFR 164.308(a)(5). What the controls say, how often you have to train, what an assessor will ask to see, and the detail that fails most assessments.

app.hooksecurity.co/dashboard
Security Overview

Last 30 days

↓ 73% risk reduction
1,247
Phishing Tests
+12%
94.2%
Pass Rate
+8%
3,892
Trained Users
+156
Recent Activity
Phishing simulation completed
Marketing Team
2m ago
Training module finished
john.doe@company.com
15m ago
Suspicious click detected
sarah.smith@company.com
1h ago

Who this applies to

Covered entities and business associates — including any vendor touching electronic protected health information. Solo practices are in scope exactly as much as health systems.

The controls

164.308(a)(5)(i)Security awareness and training (standard)

Implement a security awareness and training program for all members of the workforce, explicitly including management. The rule draws no distinction between clinical and administrative roles, or between full-time employees and part-time contractors.

164.308(a)(5)(ii)(A-D)Addressable implementation specifications

Security reminders, protection from malicious software, log-in monitoring, and password management. "Addressable" does not mean optional — you implement it, implement an equivalent alternative, or document why it is not reasonable and appropriate along with what you did instead.

How often you have to train

Periodic and ongoing. The rule does not name an interval, but a one-time orientation or a single annual email does not satisfy it — "security reminders" is an explicit specification.

What an assessor will ask to see

  • Workforce-wide training records including management and contractors
  • Evidence of recurring security reminders, not a single annual event
  • Documentation of any addressable specification handled by an alternative, and why
  • Records retained for six years — OCR audits can sample that far back

The detail that fails most assessments

The six-year documentation retention requirement catches organizations that switched platforms. If a previous vendor holds the records and you no longer have access, you cannot evidence the earlier period.

How Hook Security fits

Recurring simulations and micro-training satisfy the security reminders specification as a continuous program rather than an annual event, and every record is exportable so it survives a platform change.

Hook Security does not guarantee a passing assessment, and no platform can — compliance depends on your full control environment, your documentation and your assessor. Controls cited as published and last verified 2026-09-09. This is a reference, not legal advice.

The same records answer a cyber insurance questionnaire — see what underwriters ask for.

Show us your HIPAA scope. We will tell you what we cover.

Thirty minutes, a live account, and an honest answer about the gaps.