HIPAA Training Programs
What are the HIPAA Training Requirements for New Hires?
The HIPAA training requirements for new hires are that “a covered entity must provide training […] to each new member…
Do your Staff need Training on HIPAA in Emergency Situations?
Emergencies in healthcare are not limited to extreme weather, wildfires, or other natural disasters. Today’s most disruptive incidents are just…
HIPAA Awareness Training
HIPAA awareness training is a practical, organization wide program that helps every workforce member recognize Protected Health Information, avoid common…
What is HIPAA Safe Harbor and how does Cybersecurity Training help?
The HIPAA Safe Harbor Law, as integrated into the proposed HIPAA Security Rule update, potentially benefits organizations that can prove…
HIPAA Refresher Training
HIPAA Refresher Training is an annual course designed for staff who have already completed full HIPAA training and need their…
HIPAA and Privacy Act Training
When a federal agency provides healthcare services, there may be circumstances in which members of the federal agency’s workforce and…
5 Reasons Why HIPAA Training is Important
HIPAA training is important beyond “ticking the box” of HIPAA compliance. In this article, we explain how a fully trained…
42 CFR Part 2 Training
42 CFR Part 2 training is a functional requirement for workforces of healthcare facilities that provide substance use disorder services because it is impossible for workforces to comply with the…
Why Covered Entities Should Provide HIPAA Training to All Members of the Workforce
The provision of HIPAA training is not only a regulatory requirement. It is also an investment. Effective HIPAA training reduces…
HIPAA Security Awareness Training must Focus on Protecting Medical Records
HIPAA cybersecurity awareness training is a required, organization-wide program that teaches every workforce member what protected health information is, how…
Why AI Tools are Problem for HIPAA Compliance and How Training can Help
AI tools create new privacy and security risks because they can receive, transform, and produce information about patients in ways…
What is Cybersecurity Training for Healthcare Employees?
The HIPAA security awareness and training requirement is outlined in the HIPAA Security Rule under 45 CFR § 164.308(a)(5) that…
How Long Does HIPAA Training Take?
HIPAA training for employees typically takes about 90 minutes to 3 hours depending on the specific needs and roles of…
HIPAA Compliance Training Programs
HIPAA compliance training programs are foundational training courses that ensure every member of the workforce understands basic HIPAA provisions to…
HB300 Training
HB300 training is similar to HIPAA training inasmuch as employees of entities covered by the Texas Medical Privacy Act are…
HIPAA Onboarding Training
HIPAA Onboarding Training is the first, comprehensive HIPAA course that every new workforce member receives when they join a HIPAA…
HIPAA Remediation Training
HIPAA Remediation Training is comprehensive HIPAA training given after a HIPAA violation or breach has occurred, with particular emphasis on…
Is HIPAA Training Required Annually?
Yes, HIPAA training is required annually because it is a best practice to schedule HIPAA annual refresher training. This is…
Would your HIPAA training survive an OCR investigation?
When the Office for Civil Rights (OCR) reviews your HIPAA training during an investigation into a HIPAA violation, it is…
Is HIPAA Training a Federal Requirement?
Yes, HIPAA training is mandated by the Health Insurance Portability and Accountability Act (HIPAA) and is a federal requirement for…
How Often Should Healthcare Employees Receive Security Awareness Training?
Security awareness training is a requirement of HIPAA, but how often should healthcare employees receive security awareness training? Recent Phishing…
HIPAA Training for Organizations
HIPAA Training for Medical Spas
Medical spas that qualify as HIPAA-Covered Entities should provide all members of their workforce with HIPAA training that covers foundational…
Why Healthcare Staff Need HIPAA Training for Social Media
Avoiding social media violations by staff.
Compliance Training for Medical Staff
Compliance training for medical staff will most often include HIPAA compliance training, OSHA compliance training, and training on any other…
HIPAA Training for Pharmacy Staff
HIPAA training for pharmacy staff is required because pharmacies routinely create, access, and share protected health information through prescriptions, insurance…
HIPAA Training for Medical Billing Employees
HIPAA training for medical billing employees is essential because billing teams routinely handle Protected Health Information across claims, denials, authorizations,…
HIPAA Training for Dental Offices
HIPAA training for dental offices consists of the same Privacy Rule and Security Rule training as required by other healthcare…
HIPAA Training for Mental Health Centers
HIPAA training for mental health centers not only fulfills mandatory requirements to train workforce members on the HIPAA privacy and…
HIPAA Training for Medical Offices
HIPAA training for medical offices must consist of practical, risk-focused education for workforce members that is applicable to the real-world…
HIPAA Training for Rehab Centers
HIPAA training for rehab centers provides a baseline privacy framework that can help workforce members better understand, absorb, and comply with the more rigid confidentiality standards that apply to Part 2…
HIPAA Training for Fire Department Staff
Fire departments must comply with HIPAA when they perform HIPAA‑regulated health care functions. This most often occurs when the department…
HIPAA Training for Clearinghouse Staff
HIPAA training for clearinghouse staff is mandatory workforce training on the HIPAA Privacy Rule, HIPAA Security Rule, HIPAA Breach Notification…
Recommendations for Staff HIPAA Social Media Training
HIPAA social media training should start by explaining how the HIPAA Privacy Rule applies to anything staff share online. Training…
HIPAA Training for Emergency Medical Services (EMS)
HIPAA training for Emergency Medical Services (EMS) is the same comprehensive workforce training required of all HIPAA-covered entities and business…
HIPAA Training for Individuals
What is HIPAA Certification?
HIPAA certification is the process in which an independent third party organization audits a medical organization or practice to certify…
HIPAA Certification for Medical Couriers
HIPAA certification for medical couriers is an industry-standard training credential that demonstrates a driver understands how to handle protected health…
HIPAA Training for Physical Therapists
Physical therapists must receive documented HIPAA training that covers the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification…
HIPAA Training for Receptionists
HIPAA training for receptionists is mandatory workforce training on the HIPAA Privacy Rule, HIPAA Security Rule, HIPAA Breach Notification Rule,…
HIPAA Training for IT Professionals
HIPAA training for IT professionals is required for IT workforce members who support systems that create, receive, maintain, or transmit…
HIPAA Training for Students
HIPAA training for healthcare students ensures that they understand and adhere to HIPAA guidelines regarding the handling and protection of…
HIPAA Training for Nurses
HIPAA training for nurses and nursing assistants must be designed to prepare frontline caregivers for the moments in daily patient…
HIPAA Training for Health Services Managers
HIPAA training for health services managers supports HIPAA compliance by preparing managers to protect protected health information (PHI) while overseeing…
HIPAA Training for First Responders
HIPAA training for first responders is mandatory when first responders work for a HIPAA covered entity or an organization that…
HIPAA Training for Medical Assistants
HIPAA training for medical assistants helps healthcare organizations comply with HIPAA by preparing medical assistants to protect protected health information…
HIPAA Training for Social Workers
HIPAA training for social workers is required when social workers are part of a HIPAA Covered Entity or Business Associate…
HIPAA Training for Paramedics
Paramedics that work for HIPAA covered entities need the same HIPAA training as other healthcare staff but also additional HIPAA…
HIPAA Certification For Individuals
HIPAA certification refers to completing a structured training course and passing an assessment. For HIPAA certification for individuals, this type…
HIPAA Training for Individuals
IPAA training for individuals is a practical way to learn how to protect patient information, understand legal responsibilities, and demonstrate…
HIPAA Training for Medical Secretaries
HIPAA training for medical secretaries helps organizations maintain HIPAA compliance by preparing staff to protect protected health information (PHI) while…
HIPAA Certification for Mental Health Professionals
HIPAA certification for mental health professionals is a practical way to prove you understand how to protect Protected Health Information…
HIPAA Training for Physicians
Physicians must receive documented HIPAA training that covers the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule,…
HIPAA Training for Business Associates
HIPAA Training for Business Associates
HIPAA compliance training for business associates should include Security Rule security awareness training, applicable Privacy Rule training, Breach Notification Rule…
HIPAA Certification for Business Associates
HIPAA certification for HIPAA Business Associates is documented evidence that employees have completed training on HIPAA Privacy Rule, HIPAA Security…
HIPAA Training for Call Center Staff
HIPAA training for call center staff is role-based staff training that explains how agents, supervisors, quality reviewers, schedulers, billing support…
Why Medical Couriers Are Always Classified as HIPAA Business Associates
Other than when they are directly employed by a covered entity, medical couriers are always classified as a HIPAA business…
HIPAA Privacy Rule Training for Business Associates
HIPAA Privacy Rule training for business associates should explain how employees may use, disclose, access, protect, amend, restrict, and report…
Why HIPAA Business Associates Should Provide HIPAA Training for their Entire Staff
In any organization that qualifies as a HIPAA Business Associate, every member of the workforce is part of the environment…
Why HIPAA Business Associate Staff need Additional Targeted HIPAA Training
HIPAA training is a legal and ethical requirement for any organization that handles protected health information (PHI), but for Business…
HIPAA Training for Medical Laboratory Technicians
HIPAA training for medical laboratory technicians supports HIPAA compliance by preparing laboratory personnel to protect protected health information (PHI) while…
News Updates
HIPAA updates and news, plus the latest data breaches and fines.
HIPAA Training by Practice Type
Guidance on HIPAA compliance training across different medical specialties.
- HIPAA Training for Employees
- HIPAA Training for Business Associates
- HIPAA Certification for Individuals
- HIPAA Training for Pharmacies
- HIPAA Training for Medical Billing
- HIPAA Training for Dental Offices
- HIPAA Training for Mental Health Centers
- HIPAA Training for Medical Offices
- HIPAA Training for Fire Departments
- HIPAA Training for Clearinghouses
- HIPAA Training for Emergency Medical Services (EMS)
Top Article
HIPAA Training Buyer's Guide
Choosing HIPAA training for employees should be about compliance outcomes, not simply checking the box for mandatory training...
HIPAA Breaches & Penalties
Memorial Healthcare Services Settles Pixel Litigation
Memorial Healthcare Services, a nonprofit healthcare provider serving patients in Southern California, has agreed to settle a class action lawsuit…
Serviceaide Pays $1.8 Million to Settle Data Breach Litigation
Serviceaide, Inc., a provider of AI-powered solutions to boost productivity and enhance service delivery, has agreed to pay $1.8 million…
Allina Health System to Pay $12.5 Million to Settle Pixel Litigation
Allina Health System, a nonprofit health system based in Minneapolis, Minnesota, that serves patients in Minnesota and Western Wisconsin, has…
Spencer Gifts Pays $450,000 Penalty to Resolve HIPAA Failures
The national retail company Spencer Gifts LLC has agreed to a $450,000 settlement to resolve alleged violations of the HIPAA…
Delta Dental Fined $2.25 Million Over 2023 MOVEit Transfer Hack
Delta Dental Insurance and Delta Dental of New York (Delta Dental) have agreed to pay a fine of $2.25 million…
South Texas Oncology and Hematology Pays $1.1M to Settle Data Breach Lawsuit
South Texas Oncology and Hematology, a San Antonio, TX-based provider of leading-edge cancer treatment and other medical services, has settled…
OCR Fines Four Regulated Entities for HIPAA Violations That Led to Ransomware Attacks
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced four financial penalties to…
Ransomware Attack on Hospital Caribbean Medical Center Affects 92,000 Individuals
A ransomware attack on Hospital Caribbean Medical Center in Puerto Rico has affected up to 92,000 individuals. Data breaches have…
Illinois Bone and Joint Institute Settles Class Action Data Breach Lawsuit for $4M
Illinois Bone and Joint Institute (IBJI), one of the largest orthopedic group practices in Illinois, has agreed to settle a…
Anne Arundel Dermatology Pays $2.4M to Settle Data Breach Lawsuit
Anne Arundel Dermatology has agreed to pay $2,400,000 to settle a consolidated class action lawsuit stemming from a cybersecurity incident…
Cardiovascular Consultants Pays $3.85M to Settle Data Breach Litigation
Cardiovascular Consultants in Arizona has settled a class action lawsuit stemming from a 2023 data breach involving the protected health…
Excelsior Orthopaedics; Buffalo Surgery Center Pay $2.4 Million to Settle Data Breach Lawsuit
A settlement has been reached to resolve class action data breach litigation against Excelsior Orthopaedics and Buffalo Surgery Center. The…
Top of the World Ranch Treatment Center Settles Alleged Risk Analysis HIPAA Violation
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its first financial penalty of…
New York Attorney General Fines Capital Region Orthopedic Practice $500K for 2023 Data Breach
Orthopedics NY LLP (aka OrthoNY; OrthopedicsNY), a New York orthopedic medicine practice, has been fined $500,000 by the New York…
AccuCare Home Health Services Pays $20,000 Fine for Employing Excluded Individual
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has agreed to a $20,000 settlement with AccuCare…
Delaware Rehab Facilities Settle Social Media and Breach Notification HIPAA Violations
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
Two Disability Service Providers Announce Data Breaches Affecting 8,100 Patients
Two providers of disability services have announced security incidents. The cyberattacks on Reimagine Network in California and the Center for…
FTC Imposes $1.9 Million Penalty on Evoke Wellness for Deceptive Marketing Campaign
The Federal Trade Commission (FTC) has proposed a $1.9 million settlement to resolve claims that Evoke Wellness, a Florida-based substance…
Phishing Attack and Late Breach Notifications Lead to $600K HIPAA Fine for PIH Health
The HHS’ Office for Civil Rights (OCR) has announced its 6th financial penalty of the year to resolve alleged violations…
HHS-OIG Fines Two Healthcare Providers for EMTALA Violations
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has entered into settlement agreements with two healthcare…
Oregon Health & Science University Pays $200,000 Penalty for HIPAA Right of Access Failure
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed its second financial penalty…
Examples of Avoidable HIPAA Violations by Employers
Examples of HIPAA violations by employers are easy to find because almost every avoidable HIPAA violation is indirectly attributable to…
OCR Phishing Investigation Uncovers HIPAA Training Failure; Children’s Hospital Colorado Fined $548,265
The HHS’ Office for Civil Rights (OCR) has announced another civil monetary penalty for a HIPAA-regulated entity to address non-compliance…
Failure to Terminate Access Rights Results in $1.19 Million HIPAA Fine
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $1.19 million civil…
HIPAA Training
for Business Associates
Our HIPAA training for business associates provides employees with a clear and practical understanding of what to do and why in real-world HIPAA scenarios.
The Gold Standard in HIPAA Training
by The HIPAA Journal Team
Spencer Gifts Pays $450,000 Penalty to Resolve HIPAA Failures
The national retail company Spencer Gifts LLC has agreed to a $450,000 settlement to resolve alleged violations of the HIPAA…
Delta Dental Fined $2.25 Million Over 2023 MOVEit Transfer Hack
Delta Dental Insurance and Delta Dental of New York (Delta Dental) have agreed to pay a fine of $2.25 million…
South Texas Oncology and Hematology Pays $1.1M to Settle Data Breach Lawsuit
South Texas Oncology and Hematology, a San Antonio, TX-based provider of leading-edge cancer treatment and other medical services, has settled…
OCR Fines Four Regulated Entities for HIPAA Violations That Led to Ransomware Attacks
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced four financial penalties to…
Ransomware Attack on Hospital Caribbean Medical Center Affects 92,000 Individuals
A ransomware attack on Hospital Caribbean Medical Center in Puerto Rico has affected up to 92,000 individuals. Data breaches have…
Illinois Bone and Joint Institute Settles Class Action Data Breach Lawsuit for $4M
Illinois Bone and Joint Institute (IBJI), one of the largest orthopedic group practices in Illinois, has agreed to settle a…
Anne Arundel Dermatology Pays $2.4M to Settle Data Breach Lawsuit
Anne Arundel Dermatology has agreed to pay $2,400,000 to settle a consolidated class action lawsuit stemming from a cybersecurity incident…
Cardiovascular Consultants Pays $3.85M to Settle Data Breach Litigation
Cardiovascular Consultants in Arizona has settled a class action lawsuit stemming from a 2023 data breach involving the protected health…
Excelsior Orthopaedics; Buffalo Surgery Center Pay $2.4 Million to Settle Data Breach Lawsuit
A settlement has been reached to resolve class action data breach litigation against Excelsior Orthopaedics and Buffalo Surgery Center. The…
Top of the World Ranch Treatment Center Settles Alleged Risk Analysis HIPAA Violation
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its first financial penalty of…
New York Attorney General Fines Capital Region Orthopedic Practice $500K for 2023 Data Breach
Orthopedics NY LLP (aka OrthoNY; OrthopedicsNY), a New York orthopedic medicine practice, has been fined $500,000 by the New York…
AccuCare Home Health Services Pays $20,000 Fine for Employing Excluded Individual
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has agreed to a $20,000 settlement with AccuCare…
Delaware Rehab Facilities Settle Social Media and Breach Notification HIPAA Violations
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
Two Disability Service Providers Announce Data Breaches Affecting 8,100 Patients
Two providers of disability services have announced security incidents. The cyberattacks on Reimagine Network in California and the Center for…
FTC Imposes $1.9 Million Penalty on Evoke Wellness for Deceptive Marketing Campaign
The Federal Trade Commission (FTC) has proposed a $1.9 million settlement to resolve claims that Evoke Wellness, a Florida-based substance…
Phishing Attack and Late Breach Notifications Lead to $600K HIPAA Fine for PIH Health
The HHS’ Office for Civil Rights (OCR) has announced its 6th financial penalty of the year to resolve alleged violations…
HHS-OIG Fines Two Healthcare Providers for EMTALA Violations
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has entered into settlement agreements with two healthcare…
Oregon Health & Science University Pays $200,000 Penalty for HIPAA Right of Access Failure
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed its second financial penalty…
Examples of Avoidable HIPAA Violations by Employers
Examples of HIPAA violations by employers are easy to find because almost every avoidable HIPAA violation is indirectly attributable to…
OCR Phishing Investigation Uncovers HIPAA Training Failure; Children’s Hospital Colorado Fined $548,265
The HHS’ Office for Civil Rights (OCR) has announced another civil monetary penalty for a HIPAA-regulated entity to address non-compliance…
Failure to Terminate Access Rights Results in $1.19 Million HIPAA Fine
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $1.19 million civil…
Californian Mental Health Center Fined $100,000 for HIPAA Violation
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $100,000 civil monetary penalty…
$500,000 HIPAA Penalty for South Dakota Plastic Surgery Practice
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle an investigation of…
OCR Imposes $240,000 HIPAA Fine on Californian Healthcare Provider
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $240,000 civil monetary penalty…
American Medical Response Pays $115K Civil Monetary Penalty for HIPAA Violation
American Medical Response (AMR), a private ambulance company, has paid a $115,200 civil monetary penalty to the HHS’ Office for…
OSHA Proposes $163K Fine for Home Health Agency After Murder of Home Health Worker
The Occupational Safety and Health Administration (OSHA) has proposed a $163, 627 fine for a home healthcare provider that the…
FTC Fines Mental Health Company Cerebral $7.1 Million for Consumer Privacy Violations
The Federal Trade Commission (FTC) has fined the mental health startup Cerebral $7.1 million for consumer privacy violations and deceptive…
Refuah Health Center Pays $450K HIPAA Fine; Agrees to $1.2 Million Cybersecurity Investment
New York Attorney General Letitia James has announced that an agreement has been reached with Refuah Health Center Inc. to…
St. Joseph’s Medical Center Pays $80,000 HIPAA Fine for PHI Disclosure to a Reporter
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 11th HIPAA penalty of…
OCR Fines Arkansas Business Associate $350,000 for Impermissibly Disclosing ePHI
The HHS’ Office for Civil Rights (OCR) has agreed to settle a HIPAA investigation of an Arkansas business associate that…
Pittsburgh Counselor Fined $15,000 for HIPAA Right of Access Violation
The HHS’ Office for Civil Rights has announced its 44th enforcement action under its HIPAA Right of Access initiative with…
OCR Fines California Dental Practice for PHI Disclosures on Yelp
The HHS’ Office for Civil Rights (OCR) has announced a settlement has been reached with a Californian dental practice to…
3 Dental Practices Fined for HIPAA Right of Access Violations
The HHS’ Office for Civil Rights (OCR) has agreed to settle three HIPAA investigations of potential HIPAA Right of Access…
New Jersey Fines Hackensack Healthcare Providers for PHI Breach and HIPAA Violations
The New Jersey Division of Consumer Affairs has agreed to settle a data breach investigation that uncovered violations of the…
Adventist Health Physicians Network Fined $40,000 for Privacy Breach
Adventist Health Physicians Network in Simi Valley, California has been ordered to pay $40,000 in civil momentary penalties by the…

