Security awareness training

Training, tracked per person and expiring on schedule

Every active member assigned, every assignment completed, and completions aging out on their annual or biennial window instead of counting forever.

A certificate proves someone watched a video once. The rule asks for a program, running continuously, covering your workforce, refreshed on a cadence. Those are different objects, and only one of them survives being asked about two years later.

The policy is composed from your clinic’s facts

Your training policy covers the program requirement at 164.308(a)(5)(i), a role-based curriculum reflecting how your clinic actually delivers care across home, telehealth, school, and field settings, and six-year retention. Your new-hire deadline and your recertification cadence render from your own recorded settings.

Conditional clauses fire on your facts: AI tooling pulls in a module on not pasting PHI into consumer tools without a BAA, session recording pulls in storage, access, and retention training, staff-owned devices pull in personal-device safeguards. Your recorded addressable decisions render directly into the document.

Non-completion opens a sanction review rather than triggering an automatic sanction, which is the correct reading of the rule and a distinction most templates get wrong.

What gets tracked after the policy exists

Nine requirements, the most measured control in the platform:

  • An active, adopted policy, reviewed within twelve months, with facts that have not drifted.
  • Every active or on-leave member has at least one live training assignment.
  • No assignment is pending or overdue.
  • No completion has aged past its window: annual training expires at 365 days, biennial at 730.
  • Security reminders have been issued and attested within the last three months.
  • Malware protection is attested within the last twelve months.
  • Your addressable decisions under 164.308(a)(5) are finalized, and every active specification in that set is answered.

The expiry check is the one that separates this from a certificate folder. A completion from eighteen months ago on annual training does not count, and the control says so rather than letting an old completion sit green forever.

What this is, and what it is not

Completion means the assignment was marked completed. The system does not test comprehension or watch anyone take the training. Security reminders and malware protection are officer attestations with freshness windows, not readings of what is actually deployed on your machines.

What it does measure honestly is coverage and currency: who is assigned, who has finished, and whose completion has gone stale, per person.

What an investigator gets

A per-member assignment record with completion dates. An expiry window that ages old completions out instead of counting them forever. Attested and dated security reminders. A finalized set of addressable decisions under 164.308(a)(5). Not a folder of certificates, a program with a clock on it.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.