HIPAA training is something every healthcare organization has to get right. Over the years, we have worked with leadership teams on what effective training really looks like in practice. This post walks through the current requirements and what they mean for executives.
Table of contents
- Why HIPAA Training Is More Complicated Than It Appears
- What are the Current HIPAA Training Requirements under the HIPAA Privacy Rule?
- What are the Current HIPAA Training Requirements under the HIPAA Security Rule?
- Why is HIPAA Training so Problematic for Covered Entities?
- How do Covered Entities Educate Members of the Workforce?
- What additional HIPAA Training Requirements are being planned?
- Why HIPAA Training Failures Lead to Real-World Breaches
Why HIPAA Training Is More Complicated Than It Appears
One of the thornier problems facing managers of HIPAA-covered entities and business associates is workforce training. Specifically, it involves developing and implementing an effective HIPAA training program. Why is this thorny, you ask? Several reasons:
- The Health Insurance Portability and Accountability Act (HIPAA) is long, and the HIPAA regulations are even longer. Workforce training programs are required by both the HIPAA Privacy Rule and the HIPAA Security Rule.
- The widespread adoption of electronic health records means many more workforce members have access to electronic protected health information (ePHI). And this information is available through devices that are vulnerable because they are often connected to the internet.
- We all have a certain level of curiosity, and some of us are better than others at ensuring we do not scratch that itch in ways that violate others’ privacy rights to their health information.
- HIPAA training tends to be repetitive over time, both at a person’s current employer and in new healthcare organizations a person joins. So there is a tendency to think we know it already.
- Finally, like all education, we have differing levels of comprehension and retention of the educational materials to which we are exposed. And healthcare workers are exposed to a lot of educational materials!
But despite these thorns, HIPAA training requirements still exist, and are likely to increase in the future, so it behooves us to understand the whys and wherefores of the requirements.
What are the Current HIPAA Training Requirements under the HIPAA Privacy Rule?
The HIPAA training requirements of the Privacy Rule are contained in 45 CFR 165.130, the Administrative Requirements of the Privacy Rule. This section lays out a Standard for training and the implementation specifications for HIPAA compliance training.
In summary, the implementation specifications include:
| Workforce Members Who Must Receive Training | Members of the workforce include employees, volunteers, contracted employees, trainees, and all persons whose conduct is under the direct control of the entity, whether or not they are paid by the entity. For entities like hospitals and long-term care facilities, this includes members of the medical staff. |
| Required Training Content | Training for a covered entity’s workforce must cover the entity’s Privacy policies and procedures. It must also be necessary and appropriate to enable them to carry out their functions. |
| Timing of Required Training | HIPAA training must take place within a reasonable period of time after a person joins the workforce. Covered entities must provide HIPAA training after a material change in policies and procedures. |
| Training Documentation Requirements | All HIPAA Privacy Rule training must be documented. |
What are the Current HIPAA Training Requirements under the HIPAA Security Rule?
The HIPAA security awareness training requirements of the Security Rule are contained in 45 CFR 164.308, the Administrative Requirements of the Security Rule. This Standard covers Security Awareness and Training to help protect ePHI. Besides the general requirement for a security awareness and training program, it has four addressable implementation specifications.
Note: “addressable” does not mean “optional”! It means that a covered entity may analyze its operations and utilize an alternative method to accomplish the goal of the specification.
| Security Reminders | This specification includes focused reminders on security protections for avoiding instances of unauthorized disclosure of ePHI. It also includes periodic security updates and retraining when indicated by major changes in systems or applications. |
| Protection from Malicious Software | This includes training on procedures for guarding against, detecting, and reporting malicious software such as trojans or worms. Given how many breaches occur because of email phishing attacks, this type of training is more than “addressable”! |
| Log-in Monitoring | Covered entities and business associates are expected to be monitoring login attempts. Multiple log-in attempts can be the result of forgetful employees or they can be an indicator of hacking attempts. |
| Password Management | Covered entities creating and maintaining ePHI should have procedures for creating, changing, and safeguarding passwords. And the use of just a password for electronic health record access is giving way to the requirement for two-factor authentication for users. |
Of course, these are only the HIPAA compliance training requirements in the HIPAA Security Rule. The HIPAA employee training required by the Privacy Rule also applies to anyone receiving HIPAA training required by the Security Rule.
Why is HIPAA Training so Problematic for Covered Entities?
These lists of HIPAA training requirements are really not that long or complicated. So why is HIPAA compliance training so problematic? Naturally, the devil is in the details, particularly the details of the Privacy Rule.
HIPAA compliance training might be simple if members of the workforce only had to remember not to discuss PHI with anyone else.
But employees must continuously evaluate when, with whom, and where to discuss PHI at work or not at work. Employees make decisions every day on disclosures for treatment, payment, or healthcare operations. They must also negotiate disclosures for public interest or benefit activities.
For instance, disclosures to law enforcement, public health authorities, judicial and administrative proceedings, and serious threats to health or safety are all categories of disclosure under the HIPAA rules. Many of these requests can be handled by health information department staff, but front-line employees are faced with disclosures to relatives and friends, too.
Educating members of the workforce on the many nuances of these situations is not easy!
How do Covered Entities Educate Members of the Workforce?
Many covered entities utilize video training programs that can be accessed individually by the covered entity’s workforce for annual HIPAA training requirements. Most of these programs we have seen are well done and go a long way to explaining the basics of the HIPAA regulations. They also cover things like HIPAA violations and general HIPAA policies. However, they are not usually tailored to individual healthcare provider organizations or business associates.
The topic of HIPAA compliance training almost always requires additional HIPAA security training and information on the specific policies and procedures of the covered entity. For instance:
The list of examples of topics for additional employee training is very long. But much of it can be covered initially in small group meetings, and reinforced in annual training. Training by managers and supervisors can be particularly effective since most employees will pay attention to what their immediate supervisor is emphasizing. Security awareness training via newsletter articles is also a method to reinforce basic HIPAA rules.
What additional HIPAA Training Requirements are being planned?
The current HIPAA training requirements are also part of an updated Rule proposed by the Health and Human Services Department at the end of 2024. This proposed Rule will change and update many of the current provisions of the HIPAA Security Rule.
HIPAA training requirements can be expected to continue to increase. While the government is pushing hard due to the massive security breaches of the past few years, it is also very much in the interest of covered entities and business associates to increase HIPAA training to avoid the high costs and loss of reputation when a major breach happens.
Why HIPAA Training Failures Lead to Real-World Breaches
As Privacy Officers at several healthcare clients over the past 10 years, we have seen breaches large and small.
Some were very personal breaches of privacy based on personal initiatives that ranged from almost comical to deadly serious.
Like the volunteer who admitted she only volunteered at the hospital so she could tell her husband about the patient information she gained. Or an employee who told a gang member in another country about the baby his girlfriend gave birth to when her status was supposedly private. Or the employee who snooped for information about a child’s medical records to utilize in a divorce proceeding involving her new boyfriend’s ex-wife.
These types of events go a long way to saying there can never be too much HIPAA training in our healthcare organizations!
