What actually counts as HIPAA training

There are two separate training requirements, not one, and the certificate you bought probably satisfies neither. What the rules require, what OCR expects to see, and how to run training at RBT hiring speed.

Last verified: 2026-07-12

Ask a clinic owner about HIPAA training and you will usually be shown a certificate. Somebody bought a course, staff watched a video, everyone passed a quiz, and there is a PDF in a folder with a date on it.

That certificate is not worthless. It is also not what either of the two rules asked for, and most clinics do not know there are two.

There are two requirements, not one

Privacy training (45 CFR 164.530(b)). Train each member of your workforce on the policies and procedures with respect to protected health information that are necessary and appropriate for them to carry out their function. Note what that says: your policies. Not HIPAA in the abstract.

The rule also sets deadlines, which most clinics miss entirely:

  • Each new workforce member is trained within a reasonable period of time after joining.
  • Each workforce member affected by a material change to your policies or procedures is retrained within a reasonable period of time after the change takes effect.
  • And you must document that the training was provided (45 CFR 164.530(j)).

There is no “annual” in that text. There is a hiring trigger and a change trigger. An annual cadence is a reasonable practice on top of them, not a substitute for them.

Security awareness and training (45 CFR 164.308(a)(5)). Implement a security awareness and training program for all members of the workforce, including management. Four addressable specifications name what the program should be reaching for: periodic security reminders, protection from malicious software, log-in monitoring, and password management.

Read the word program. It is not a session; it is an ongoing thing with a pulse. And “including management” is in the regulation because OCR knows exactly who skips it.

Why the certificate does not do it

A generic course teaches the HIPAA rules. Your requirement is to train people on your policies: your rule about session recordings, your BYOD policy, your incident procedure, your portal invite process, your rule about tablets in cars.

No purchased course knows any of that, because it does not know your clinic. Which means the generic training and the required training are two different objects, and the certificate proves you completed the one the rule did not ask for.

That is not an argument against buying a course. Baseline HIPAA literacy is worth having, and a good course delivers it efficiently. It is an argument about what it does and does not discharge. A certificate proves someone watched a video. Training is what changes what a person does at 4pm in a living room, and only one of those two things is what the rule asked for.

What OCR expects to be able to see

Nothing exotic. In an investigation, the training questions are administrative: who is in your workforce, what were they trained on, when, and can you show it.

“A certificate proves someone watched a video. Training is what changes what a person does at 4pm in a living room, and only one of those two things is what the rule asked for”

So the deliverable is a record, and it has four columns: who (every workforce member, including volunteers, trainees, and contractors under your control, per 45 CFR 160.103), when, on what (which policies, which version), and evidence (an acknowledgment, a signature, a completion record). Keep it for six years (45 CFR 164.316(b)(2)(i); 45 CFR 164.530(j)).

Undocumented training is indistinguishable from no training. That is not a rhetorical flourish; it is the practical position you occupy when an investigator asks and you have a memory instead of a list.

Training at RBT speed

Here is the ABA-specific problem, and it is the reason most clinics fall out of compliance without any bad intent: your training obligation runs on your hiring rate.

An RBT starts on Monday. The privacy rule wants them trained within a reasonable time after joining, before they are alone in a family’s home with a tablet full of PHI. If your clinic hires twice a month and trains once a year, you have a structural gap, not an incident. The person who has been in homes for six months untrained is not an oversight; they are the predictable output of the system you built.

What works in this field:

Day-one onboarding module. Short. Non-negotiable. Delivered before the first solo session, not before the ninety-day review. It covers the six things a field clinician actually decides: screens, devices, photos, conversations, reporting an incident, and who to call.

Role-specific content. The rule says train on what is necessary and appropriate for the person’s function. Your billing coordinator does not need the living room module and your RBT does not need the claims module. Two short trainings beat one long irrelevant one, and the rule prefers them.

Reminders with a pulse. The addressable specifications ask for periodic security reminders, and a five-minute item in a monthly team meeting satisfies that better than an annual sixty-minute video that everyone plays at double speed with the sound off. Phishing is where most healthcare intrusions begin; make it the recurring topic.

Retraining when policy changes. New data platform, new BYOD rule, new AI tool banned or approved. That is a material change, and the rule wants the affected people retrained after it takes effect. Wire it into the change itself: policy updated, training pushed, acknowledgments collected, record updated.

Acknowledgments that mean something. A signature stating “I have read the in-home policy and I understand that clinical photos never go in my camera roll” is worth more than a completion certificate, because it names the behavior. It also matters if you ever have to apply your sanction policy (45 CFR 164.308(a)(1)(ii)(C)): sanctioning someone for violating a rule you cannot prove you taught them is a losing position, for you and unfair to them.

The honest summary

You need two things. A record showing every workforce member was trained on your policies, at hire and after material changes. And an ongoing security awareness program with a pulse, that reaches management too.

The purchased course can carry the baseline. It cannot carry either requirement on its own, and the gap between the certificate in your folder and the obligation in the regulation is where almost every clinic in this field currently sits. Closing it costs an afternoon of writing and a spreadsheet, which is a very low price for removing an entire category of finding.

The short version

  • There are two requirements: privacy training under 164.530(b) and a security awareness and training program under 164.308(a)(5). They are different obligations.
  • The privacy rule sets deadlines: train each new workforce member within a reasonable time after they join, and retrain everyone affected by a material policy change.
  • The security requirement is a program, not an event: periodic reminders, malware, log-in monitoring, and password practices are the named topics.
  • Generic off-the-shelf training cannot teach your policies, and your policies are what the rule requires people to be trained on.
  • Document it: who, when, on what. Undocumented training is indistinguishable from no training.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Trained on your policies, on the record.

Who was trained, when, on what version of which policy, and who is overdue. WiseUpHIPAA runs the training record from your actual roster and shows you honestly where the gaps are.