1. The current Security Rule requires a workforce security-awareness program.
Under 45 CFR § 164.308(a)(5)(i), a regulated entity must implement a security awareness and training program for all members of its workforce, including management. HHS describes this as an administrative safeguard and identifies four implementation specifications: periodic security updates, protection from malicious software, log-in monitoring, and password management.
“Addressable” implementation specifications are not simply optional. A regulated entity evaluates whether a specification is reasonable and appropriate in its environment and implements it when it is. If it is not, the entity documents that decision and, when reasonable and appropriate, implements an equivalent alternative measure.
2. The Privacy Rule separately requires policy-and-procedure training.
Under 45 CFR § 164.530(b), a covered entity must train workforce members on the policies and procedures concerning protected health information that are necessary and appropriate for their functions. The rule addresses existing workforce members, new workforce members within a reasonable period after joining, and workforce members whose functions are affected by a material policy or procedure change.
This is why a general security course cannot replace the organization’s own privacy training. A third-party module can establish shared concepts and document completion, but it cannot teach a clinic’s permitted systems, privacy contacts, patient-request workflow, sanctions, incident channel, or role permissions unless those details are actually incorporated.
3. Does HIPAA require annual training?
The currently effective HIPAA Security Rule does not state one universal once-per-calendar-year training interval for every regulated entity. It requires a security-awareness and training program and includes periodic security updates. The Privacy Rule expressly addresses new workforce members and material changes affecting a workforce member’s functions.
Many organizations choose an annual baseline because it creates a predictable review cycle, supports periodic reminders, accommodates recurring contractual or insurer expectations, and produces an orderly evidence file. That can be a sensible program decision, but it should not be described as a universal annual interval written into the current HIPAA rule.
Organizations should also train or update people when risks, technology, duties, systems, policies, or procedures materially change—not merely wait for an anniversary date.
4. The proposed Security Rule changes are not the current rule.
HHS issued proposed modifications to the HIPAA Security Rule in December 2024. As of this guide’s September 1, 2026 review, HHS continues to identify those modifications as a proposed rule and states that the currently effective Security Rule remains in effect. Organizations should monitor the rulemaking, but should not present proposed provisions as current legal requirements.
5. What should the training program cover?
Coverage should follow the organization’s risks, systems, workforce functions, and policies. HHS audit material specifically examines the training strategy, current content, organization-wide delivery, security reminders, malicious-software procedures, log-in monitoring, password management, technology and practice changes, and documentation.
Access and authentication
Unique accounts, password practices, MFA, inappropriate sharing, and suspicious access.
Malware and phishing
Suspicious messages, files, software, impersonation, reporting, and safe verification.
PHI and ePHI handling
Approved systems, minimum necessary use, recipients, devices, paper, remote work, and disposal.
Incident response
What to report, how quickly, where to report, which details help, and why employees should not investigate alone.
Organization policy
Actual privacy and security procedures, contacts, role boundaries, sanctions, downtime, and escalation.
Changes and reminders
New hires, changed functions, new systems, policy changes, threat changes, and periodic reinforcement.
6. What evidence should an organization retain?
A useful evidence file connects the requirement to its implementation. Depending on the organization’s policies and qualified guidance, that can include the approved training policy or plan, intended audience, course material and version, assignment date, learner roster, completion dates, assessment result, sign-off or acknowledgment, exceptions and follow-up, and periodic content reviews.
HHS states that documentation required by the Security Rule must generally be maintained for six years from creation or from when it last was in effect, whichever is later. The Privacy Rule also contains documentation requirements. Organizations should determine which training artifacts fall within their applicable documentation duties and retention policy rather than assuming a certificate alone is the complete file.
7. Where Wardably fits
Wardably provides a general healthcare security-awareness course, campaign controls, learner activity, assessment results, typed final sign-off, course version, certificate IDs, CSV export, and bulk certificate download. The organization remains responsible for its own policies, role-specific training, applicability decisions, risk analysis, safeguards, reporting channels, sanctions, retention, and legal conclusions.