25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

PJ Murray

PJ Murray is the founder and publisher of The HIPAA Journal. He is dedicated to The HIPAA Journal’s mission of promoting a culture of HIPAA compliance and patient privacy by helping organizations and their staff understand both the regulations and the importance of protecting patient privacy and data security. Prior to working on The HIPAA Journal, PJ has a technical background in software development and an engineering degree and has a particular interest in the cybersecurity aspects of protecting the privacy of medical records.

How to Choose the Right HIPAA Training for Remote Workers?
Aug11

How to Choose the Right HIPAA Training for Remote Workers?

Choose HIPAA training for remote workers that comprehensive regarding HIPAA rules and regulations, but is also role based and scenario driven, covers remote specific risks like home workspace privacy, messaging, video calls, personal devices, and unapproved online tools, includes short knowledge checks, and produces clear completion and assessment records you can quickly provide during audits or investigations. Remote and hybrid work is now normal across healthcare, including billing, scheduling, utilization review, care coordination, coding, and some clinical services. That shift changes how Protected Health Information (PHI) and electronic PHI (ePHI) is accessed, discussed, stored, and transmitted. It also changes what effective HIPAA training needs to accomplish. The goal is not to check a box. Good training helps remote staff make the right choices in real conditions: distractions at home, shared spaces, multiple apps, and fast patient communications. Training that builds practical judgment and produces strong documentation helps reduce avoidable incidents and strengthens your...

Read More
Free Trial: Complete Your Annual HIPAA Risk Assessment
Apr12

Free Trial: Complete Your Annual HIPAA Risk Assessment

Your organization must conduct a HIPAA Risk Assessment. Conducting and documenting a risk analysis (often called a “HIPAA risk assessment”) is a statutory requirement under the HIPAA Security Rule for any covered entity or business associate that creates, receives, maintains, or transmits electronic Protected Health Information (ePHI). The Security Rule at 45 C.F.R. § 164.308(a)(1)(ii)(A) requires a risk analysis to assess the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. The risk assessment is not optional or “addressable”.  A HIPAA Risk Assessment is explicitly required. Consequences for Risk Assessment Failures Risk assessment failures, including missing and inadequate risk assessments, are routinely cited by the HHS Office for Civil Rights (OCR) in its enforcement actions and usually result in financial penalties. OCR currently has an enforcement initiative specifically targeting noncompliance with this Security Rule provision and has already imposed 10 financial penalties under that ongoing risk assessment initiative. An...

Read More
Would your HIPAA training survive an OCR investigation?
Feb26

Would your HIPAA training survive an OCR investigation?

When the Office for Civil Rights (OCR) reviews your HIPAA training during an investigation into a HIPAA violation, it is looking for proof that your workforce has been trained on all of the rules and regulations that apply to your operations, not just a high-level primer. At a minimum, OCR expects privacy training on the HIPAA Privacy Rule requirements, plus an organization-wide HIPAA security awareness and training program under the HIPAA Security Rule. OCR investigators will also check that employees understand the HIPAA Breach Notification Rule and how your organization meets its obligations when something goes wrong and there is a potential HIPAA violation. These are not soft expectations: the HIPAA Privacy Rule requires training “as necessary and appropriate” regarding protected health information, and the HIPAA Security Rule requires a security awareness and training program for all workforce members, including management. OCR Reviews Training Curriculum From the outset, OCR reviews whether the curriculum actually covers the rules in full and maps them to day-to-day employee...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist