HIPAA Training Compliance Education for Healthcare
The HIPAA Security Rule requires a security awareness and training program for all members of the workforce, including management, at every organization that handles protected health information (PHI) as a covered entity or business associate. Petronella Technology Group, Inc. delivers practical, role-based HIPAA training programs that teach your team to protect patient data, recognize threats, and document compliance. Founded in 2002 in Raleigh, NC, and a Cyber AB Registered Provider Organization (#1449), we build training programs that map to federal requirements and focus on changing behavior, not just checking a box.
Why HIPAA Training Is Required
HIPAA training is not optional. Federal law mandates it for every covered entity and business associate, and the penalties for non-compliance are severe.
The Legal Requirement
- The HIPAA Security Rule (45 CFR 164.308(a)(5)) requires covered entities to implement a security awareness and training program for all workforce members, including management.
- The HIPAA Privacy Rule (45 CFR 164.530(b)) requires training on policies and procedures for workforce members who handle PHI, with training provided within a reasonable time of joining.
- Business associates must train their own workforce members under the HITECH Act's expanded requirements and the Omnibus Rule of 2013.
- State laws, including North Carolina's Identity Theft Protection Act, add breach notification duties for organizations that hold personal information, and staff who can recognize and report an incident support those duties.
Penalties for Non-Compliance
- Tier 1 - Did not know, and by exercising reasonable diligence would not have known: the lowest penalty range. Not knowing still carries a penalty.
- Tier 2 - Reasonable cause and not willful neglect: a higher penalty range than Tier 1.
- Tier 3 - Willful neglect, corrected within 30 days: a higher range again. HHS adjusts every tier's dollar amounts each year for inflation (45 CFR Part 102).
- Tier 4 - Willful neglect, not corrected within 30 days: the highest civil penalty range. Separately, knowing wrongful disclosures can carry criminal penalties under 42 U.S.C. 1320d-6.
During an OCR audit or breach investigation, investigators commonly request documentation of your HIPAA training program. Organizations that cannot produce training records, attendance logs, and curriculum documentation are in a weaker position, because they cannot show the program existed or who it reached. A well-documented training program is your organization's first line of defense against regulatory action, and Petronella Technology Group provides complete compliance documentation with every training engagement.
Where to get HIPAA training for your healthcare practice
Petronella Technology Group, Inc., a Raleigh, NC cybersecurity and compliance firm founded in 2002, sells self-paced HIPAA courses online through its Training Academy. Practices can pair a HIPAA course with annual security awareness training for every workforce member, bought per seat or as a team pack. To size a team order, call Penny at 919-348-4912.
- HIPAA Rescue Manual for Healthcare Practices: $999.
- HIPAA Compliance & Cybersecurity Mastery: $2,997.
- 2026 Security Awareness Training: $49 per learner, 90 minutes, covering AI phishing, deepfakes and MFA fatigue.
- Team packs for workforce training from $290 for 10 seats, one enrollment code.
- Every learner earns a certificate of completion, verifiable at /training/verify/.
What 45 CFR 164.308(a)(5) Actually Requires
Before comparing providers or prices, it helps to read what the HIPAA Security Rule says about training. Here is the requirement in plain language, with the citations a compliance officer would expect to see.
The Standard Itself
- 45 CFR 164.308(a)(5) requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management. That covers clinicians, billing staff, IT, volunteers, and owners alike.
- The Privacy Rule at 45 CFR 164.530(b)(1) adds training on your own policies and procedures, as necessary and appropriate for each person's job functions. That wording is why one identical deck for everyone falls short.
- For covered entities, new workforce members must be trained within a reasonable period of time after they join (45 CFR 164.530(b)(2)(i)(B)), and staff whose functions are affected by a material policy change must be retrained within a reasonable period after the change takes effect (45 CFR 164.530(b)(2)(i)(C)).
- Documentation must be retained for six years from the date it was created or the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)(i)).
The Four Addressable Specifications
- Security reminders: periodic security updates that keep current threats, such as phishing aimed at healthcare staff, in front of the workforce.
- Protection from malicious software: procedures for guarding against, detecting, and reporting malicious software.
- Log-in monitoring: procedures for monitoring log-ins and reporting discrepancies, which is where unusual access to patient records gets caught.
- Password management: procedures for creating, changing, and safeguarding passwords.
- Addressable does not mean optional. You either implement each specification, document why it is not reasonable and appropriate for your organization, or implement an equivalent alternative measure.
How assessors read it: 45 CFR 164.308(a)(5) sits inside the administrative safeguards, next to your sanctions policy at 45 CFR 164.308(a)(1)(ii)(C). The rule expects trained staff and documented consequences when policies are violated. A program with named completion dates, role-based curriculum, and a recurring annual cadence is straightforward to demonstrate; a program that cannot say who was trained, on what, and when, is not.
What this means when you buy: look for courses that issue a certificate of completion with a date, keep a roster you can export, and separate content by role. The HIPAA Rescue Manual for Healthcare Practices is an all-in-one compliance kit with editable templates, policies, risk assessments, and training materials, and every learner receives a certificate of completion.
Who Must Be Trained, and When
The training duty attaches to people, not job titles. If a person can reach protected health information while doing their job, they belong in the training plan.
HIPAA defines workforce broadly: employees, trainees, and volunteers whose conduct is under the direct control of the covered entity or business associate, whether or not they are paid. The Security Rule at 45 CFR 164.308(a)(5) names all members of the workforce, including management, so executives and practice owners are not exempt. Business associates carry the same duty for their own staff under the HITECH Act and the 2013 Omnibus Rule: a billing vendor, transcription service, IT provider, or cloud EHR host must train its own people.
When training is expected:
- Within a reasonable period of time after a new workforce member joins a covered entity (45 CFR 164.530(b)(2)(i)(B))
- When your policies or procedures change in a material way, for the staff whose functions those changes affect (45 CFR 164.530(b)(2)(i)(C))
- Periodically, as security reminders under 45 CFR 164.308(a)(5)(ii)(A). The rule does not set a fixed interval; many organizations choose an annual refresher because it is easy to schedule and evidence
- As a good practice, after an incident or a near miss, as part of a documented corrective action plan
Covered entities and business associates are accountable for the people they control, and vendor review is where the two worlds meet. When you evaluate a business associate, ask for evidence of their training program. Keep evidence of your own program for the staff you control, so both sides of the relationship can show their training.
For the annual refresher itself, the 2026 Security Awareness Training is a 90-minute course written for every non-technical employee, and it can be ordered as a team pack so the whole practice trains from a single enrollment code.
HIPAA Training Programs by Role
One-size-fits-all training does not satisfy HIPAA requirements. We deliver role-specific HIPAA training that addresses the unique risks and responsibilities each group faces in your organization.
Executives and Leadership
Board members, C-suite, and practice owners receive training focused on governance responsibilities, risk management oversight, breach liability, and the financial consequences of non-compliance. This module covers how leadership decisions directly impact HIPAA compliance posture, including vendor management, budget allocation for security controls, and fiduciary obligations under the Security Rule. Leaders learn to interpret risk assessment findings and make informed investment decisions to protect PHI.
IT Staff and Security Teams
Technical workforce members receive advanced HIPAA training covering access control implementation, audit log configuration, encryption standards for data at rest and in transit, incident response procedures, and technical safeguard requirements under 45 CFR 164.312. Training includes hands-on scenarios involving ePHI system configuration, backup and disaster recovery testing, and vulnerability remediation prioritization aligned with the HIPAA Security Rule specifications.
Clinical Staff and Providers
Physicians, nurses, medical assistants, and clinical support staff receive training tailored to their daily workflow with PHI. Modules cover minimum necessary access, secure communication of lab results and diagnoses, proper EHR usage, verbal disclosure safeguards in shared clinical spaces, secure disposal of paper records, and recognizing social engineering attempts that specifically target healthcare providers. Real-world scenarios use clinical contexts your team encounters daily.
Front Desk and Administrative
Receptionists, billing staff, scheduling coordinators, and office managers handle PHI constantly and face unique exposure risks. Training covers proper patient check-in procedures, secure phone communication, fax and email safeguards, clean desk policies, visitor management, proper destruction of paper PHI, handling records requests, and verification of patient identity before releasing information. These roles are the most targeted by social engineering attacks in healthcare settings.
What Our HIPAA Training Covers
Our HIPAA training curriculum addresses every regulatory domain required for workforce compliance, with practical examples drawn from real healthcare environments.
Privacy Rule Training
- Uses and disclosures of PHI including the minimum necessary standard and the 18 HIPAA identifiers
- Patient rights including access, amendment, restriction requests, and accounting of disclosures
- Notice of Privacy Practices (NPP) requirements and proper distribution procedures
- De-identification standards, research exceptions, and marketing restrictions under HIPAA
Security Rule Training
- Administrative safeguards: security management process, workforce security, information access management
- Physical safeguards: facility access controls, workstation use and security, device and media controls
- Technical safeguards: access controls, audit controls, integrity controls, transmission security
- Password policies, multi-factor authentication, session timeout, and encryption requirements for ePHI
Breach Notification Rule: Every training program includes comprehensive coverage of the Breach Notification Rule (45 CFR 164.400-414). Your workforce learns the definition of a breach, the four-factor risk assessment for determining notification requirements, the 60-day notification timeline, and the proper chain of reporting from initial discovery through OCR notification. We teach staff to recognize potential breach scenarios specific to their role, including lost devices, misdirected faxes, unauthorized EHR access, and improper disposal of records.
HITECH Act Requirements: Training covers the HITECH Act's impact on HIPAA enforcement, including increased penalties, mandatory breach notification for incidents affecting 500+ individuals, expanded business associate obligations, and the prohibition on selling PHI without patient authorization. Your team understands how HITECH strengthened HIPAA enforcement and why compliance is more critical now than when HIPAA was originally enacted.
HIPAA Training Delivery Options
We offer flexible training delivery to accommodate healthcare organizations of every size, from single-physician practices to multi-location health systems.
On-Site Instructor-Led
Our instructors, led by Craig Petronella (CMMC-RP), deliver hands-on HIPAA training at your facility. Includes role-specific breakout sessions, live phishing demonstrations, and interactive Q&A. Best for initial compliance programs, large teams, and organizations that need high engagement for audit documentation.
Virtual Live Sessions
Interactive video-conference training sessions led by our compliance specialists. Supports screen sharing, breakout rooms, polling, and real-time assessment. Ideal for multi-location practices, remote staff, and organizations that need flexible scheduling without sacrificing instructor interaction.
Self-Paced LMS
Our learning management system delivers on-demand HIPAA training modules with progress tracking, knowledge assessments, and completion certificates. Staff complete training on their schedule. The HIPAA Rescue Manual course provides comprehensive self-paced compliance education.
Compliance Tracking and Reporting
Complete documentation is as important as the training itself. We provide everything you need to demonstrate compliance during an OCR investigation or audit.
Training Records Management
Every training session generates detailed records including attendee names, dates, topics covered, duration, and assessment scores. We maintain records for the HIPAA-required six-year retention period and provide copies in formats compatible with your compliance management system. Digital records include timestamps and completion verification that withstand audit scrutiny.
Completion Certificates
Each participant receives individually issued certificates of completion with unique identifiers, training dates, curriculum version numbers, and instructor credentials. Certificates serve as auditable proof of compliance and can be presented during OCR investigations, accreditation reviews, and insurance renewals to demonstrate your HIPAA training program.
Knowledge Assessments
Pre- and post-training assessments measure knowledge gained and identify areas requiring additional attention. Results are documented per participant and aggregated to give leadership visibility into organizational HIPAA literacy. Assessment data helps target follow-up training and demonstrates the effectiveness of your program to auditors.
Compliance Gap Reports
After each training cycle, we deliver a compliance gap report identifying workforce members who have not completed training, areas of low assessment scores, and recommendations for policy updates. These reports give your HIPAA compliance officer actionable data for continuous improvement and provide documented evidence of ongoing compliance efforts.
What HIPAA Assessors Typically Ask to See
Whether the trigger is an OCR complaint investigation, a state audit, an accreditation survey, or a cyber insurance renewal, the evidence requested for training tends to overlap. Prepare these four artifacts and the conversation stays short.
Training Records With Completion Dates
A roster that names each workforce member, the course or session completed, and the date it was completed. Assessors typically sample names and ask you to produce the matching certificate or attendance record on the spot. Courses from the Training Academy generate certificates of completion, and buyers can export a roster CSV with completion dates, which turns this artifact into a download instead of a scramble.
Role Mapping
A simple document that connects each role in the practice to the curriculum that role received: what executives took, what clinicians took, what front-desk and billing staff took, and what IT took. Because 45 CFR 164.530(b)(1) ties training to each person's job functions, assessors use role mapping to see whether the training was appropriate for the duties rather than identical for everyone.
Curriculum and Policy Versions
The written training policy, the curriculum version used in each cycle, and the policies and procedures the training references. Six-year retention applies, so keep the version history: if a policy was updated last year, an assessor may ask what the staff were told before and after the change, and when the retraining happened.
Onboarding, Refresher, and Gap Evidence
Evidence that new hires were trained within a reasonable period after joining, that refresher training runs on a recurring cadence, and that people who missed a session were followed up and retrained. A compliance gap report that lists who has not completed training, with the corrective action taken, is the artifact that shows the program is managed rather than assumed.
If you buy training from an outside provider, make verification part of the purchase. Each certificate should carry a unique identifier, and a third party should be able to confirm it independently. Training Academy certificates can be verified at /training/verify/, and CMMC courses carry a 12-month expiry so the evidence trail also shows when a refresher is due.
How to Build an Annual HIPAA Training Plan
A training plan that survives an audit is a calendar with names on it. Six steps take a practice from occasional reminders to a documented annual program.
Inventory roles and PHI access
List every role in the practice and how each one touches protected health information: clinical, front desk, billing, IT, leadership, contractors, and volunteers. This inventory becomes the backbone of the whole plan.
Map curriculum to each role
Assign the training each role needs based on its duties and PHI access level. Executives need governance-level content, IT needs technical safeguards, and clinical and front-desk staff need workflow-level scenarios.
Set the onboarding trigger
Make training part of new-hire onboarding so it happens within a reasonable period of time after someone joins, before or as they receive access to PHI. Write the trigger into your HR checklist.
Fix the annual refresher date
Pick a month and make the refresher recurring. Order seats as a team pack with one enrollment code, and let the 12-month seat redemption window absorb new hires and schedule changes.
Attach retraining to policy changes
When a policy or procedure changes materially, identify the affected staff and schedule retraining within a reasonable period. Keep the curriculum version that documents what they were told.
Document, verify, and report
File the roster CSV with completion dates, keep the certificates, and hand a gap report to your compliance officer. The report lists who has not finished and what corrective action follows.
Annual Refresher Requirements
HIPAA does not set a fixed refresher interval. The Security Rule lists periodic security updates as an addressable specification, and the Privacy Rule requires retraining when policies change materially. An annual refresher is a common way to meet both, because it is easy to schedule and easy to evidence. Many HIPAA compliance programs build annual refresher training into their policy for that reason.
What annual HIPAA refresher training must include:
- Updates on new threats and attack techniques targeting healthcare organizations, including AI-powered phishing, ransomware, and business email compromise
- Policy and procedure changes enacted since the last training cycle, including any new technology deployments or workflow modifications
- Review of security incidents and near-misses from the past year, with lessons learned and corrective actions implemented
- Changes to federal and state regulations, OCR guidance documents, and enforcement trends that affect your organization
- Assessment results from the prior period, with targeted remediation for areas where workforce knowledge gaps persist
- Updates to your organization's HIPAA risk assessment findings and how they translate to workforce behavior requirements
Petronella sells self-paced courses and team packs that keep HIPAA awareness current year over year: the 2026 Security Awareness Training ($49 per learner, 90 minutes) is written for annual refresher cycles, and team packs come with seats redeemable for 12 months, so new hires can join the same order all year. Every learner receives a certificate of completion you can file with your training records.
Training Rules Beyond HIPAA: NIST 800-171, CMMC, and the FTC
Many healthcare organizations carry more than one training obligation. Companies in the defense supply chain answer to NIST SP 800-171 and CMMC Level 2, and businesses the FTC defines as financial institutions answer to the Safeguards Rule. The pattern is the same across all three: train the right people on the right risks, and keep the evidence.
NIST SP 800-171 Requirement 3.2 and CMMC Level 2
- Requirement 3.2.1 asks that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures. CMMC Level 2 assesses this as AT.L2-3.2.1.
- Requirement 3.2.2 asks that personnel are trained to carry out their assigned information security-related duties and responsibilities. CMMC Level 2 assesses this as AT.L2-3.2.2 (Role-Based Training).
- Requirement 3.2.3 asks for security awareness training on recognizing and reporting potential indicators of insider threat. CMMC Level 2 assesses this as AT.L2-3.2.3 (Insider Threat Awareness).
FTC Safeguards Rule, 16 CFR 314.4(e)
- Requires security awareness training for all personnel, not just security staff, updated as necessary to reflect risks identified by the risk assessment (16 CFR 314.4(e)(1)).
- Requires information security personnel to receive training sufficient to address the relevant security risks of their roles.
- Expects training to keep pace with changing threats, which means a recurring program rather than a one-time event.
- Applies to businesses the FTC defines as financial institutions. If your organization fits that definition, the training obligation sits alongside HIPAA, not instead of it.
Courses that map to the practices: the CMMC Level 2 Security Awareness Common Core is $49 per learner, runs about 63 minutes, and maps to AT.L2-3.2.1 and AT.L2-3.2.3. Role-Based Training is available as a General Users course ($59, about 30 minutes) and an Executives course ($149, about 30 minutes), both mapping to AT.L2-3.2.2. The Awareness and Training License bundles all three CMMC courses for $300 per user per year with one enrollment code for 1 to 500 users, and invoicing is available at 25 or more users. For FTC obligations, the FTC Compliance Mastery course covers the Safeguards Rule at $149.
Practices that also need a picture of CMMC readiness beyond training can start with the CMMC readiness assessment, and readers who want the individual practices explained in depth will find them at 3.2.1 security awareness training and 3.2.2 role-based security training. Insider threat awareness, the subject of requirement 3.2.3, pairs naturally with an insider threat program.
Built for Every Healthcare Role
How to Choose a HIPAA Training Provider
Price is the easiest thing to compare and the least useful. These five questions separate a training program that holds up in an audit from a PDF and a quiz.
Is the content role-based?
Ask to see the outlines for executive, IT, clinical, and front-desk tracks. Training that is necessary and appropriate for one role is rarely appropriate for another, and assessors look for that separation. If the provider shows you one identical deck for everyone, keep looking.
Can you prove completion?
Certificates should carry a unique identifier and a completion date, a third party should be able to verify them, and you should be able to export a roster CSV with completion dates for your records. Training Academy certificates are verifiable at /training/verify/.
Is pricing published and sized to your team?
Per-seat self-paced pricing should start low enough to train everyone: $49 per learner for a 90-minute annual awareness course, with team packs from $290 for 10 seats and one enrollment code. Published pricing you can calculate before a phone call is a good sign for everything that follows.
Does the provider understand more than HIPAA?
If your organization also answers to NIST SP 800-171, CMMC Level 2, or the FTC Safeguards Rule, ask which courses map to which practices. A provider that can point to AT.L2-3.2.1, AT.L2-3.2.2, and AT.L2-3.2.3 mappings saves you from running two disconnected programs.
Who stands behind the courses?
Look for a real company with a real record. Petronella Technology Group, Inc. is a Raleigh, NC cybersecurity and compliance firm founded in 2002, a Cyber AB Registered Provider Organization (#1449), with instructor Craig Petronella (CMMC-RP). Questions about sizing a team order go to Penny at 919-348-4912.
What happens after purchase?
Ask how learners are enrolled, whether the group gets one enrollment code, how long seats stay valid, and what documentation arrives at the end. Seats in the team packs are redeemable for 12 months, which absorbs new hires without a second order.
Common Mistakes in HIPAA Training Programs
Most training programs do not fail on content. They fail on record-keeping and cadence. Each of these mistakes has a simple, inexpensive fix.
Training once, then never again
A one-time orientation course with no refresher leaves a five-year hole in your evidence trail. Fix it by fixing an annual refresher date and treating it like payroll: it happens every year without debate.
One deck for every role
Training that is necessary and appropriate for a billing specialist is not what an executive or an IT administrator needs. Fix it by mapping curriculum to roles and keeping the mapping document with your training records.
Records without dates
A sign-in sheet that shows names but not dates, or a certificate that cannot be verified, answers nothing when an assessor samples your roster. Fix it by keeping completion records with individual dates, exported from the training system.
Forgetting business associates
Your vendors train their own people, but vendor review is where you confirm it. Fix it by adding training evidence to your vendor review checklist and to the business associate agreement conversation.
Skipping retraining after policy changes
When a policy changes materially and the affected staff are never retrained, the change itself becomes the gap. Fix it by attaching a retraining step to every policy revision in your document control process.
Treating new hires as an exception
Staff hired between annual cycles still need training within a reasonable period of joining. Fix it with an onboarding trigger and a standing order of seats that stay redeemable, so a mid-year hire never waits for the next cycle.
HIPAA Training Frequently Asked Questions
How often is HIPAA training required?
The Privacy Rule requires training within a reasonable period after a workforce member joins and when material policy changes affect a person's functions. The regulation does not specify an exact frequency for refresher training. The Security Rule calls for periodic security reminders, and many organizations adopt an annual refresher in their training policy because it keeps content current and produces dated records an investigator can review.
Does HIPAA training apply to business associates?
Yes. The HITECH Act and the 2013 Omnibus Rule extended HIPAA training requirements to business associates and their subcontractors. Any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity must train its workforce. Petronella provides business associate training programs that cover both covered entity and business associate training obligations. Learn more about HIPAA compliance requirements.
What documentation do I need for HIPAA training compliance?
HIPAA requires you to retain training documentation for six years from the date of creation or the date the policy was last in effect, whichever is later. Required documentation includes training policies and procedures, attendance records with dates and topics, copies of training materials, assessment results, and evidence of retraining when policies change. Petronella provides all documentation in audit-ready format.
What happens if an employee refuses HIPAA training?
An employee who refuses mandatory HIPAA training puts your entire organization at risk. HIPAA requires covered entities to apply appropriate sanctions against workforce members who violate policies. Most organizations include HIPAA training as a condition of employment. If a workforce member refuses training, you should document the refusal, apply your sanctions policy, and consider whether continued access to PHI is appropriate.
Can HIPAA training be done online?
Yes. HIPAA does not mandate a specific training delivery format. Online training, in-person training, and hybrid approaches are all acceptable as long as the content is appropriate, attendance is documented, and comprehension is verified. Petronella offers all three formats. Our HIPAA Rescue Manual provides comprehensive self-paced online training with built-in assessments.
How long does HIPAA training take?
Initial HIPAA training typically takes 2-4 hours depending on the role and depth of coverage required. Annual refresher training runs 1-2 hours. Executive and IT-focused modules may require additional time for advanced topics. Petronella designs training programs that are thorough without being unnecessarily long, focusing on practical application rather than rote memorization.
Does HIPAA training need to be role-specific?
While HIPAA does not explicitly require role-specific training, the regulation requires training to be "appropriate" for each workforce member's job functions. The OCR has consistently interpreted this to mean training content should be relevant to the individual's actual duties and PHI access level. Role-based training also produces better outcomes because it addresses the specific risks each group encounters in their daily work.
What is the cost of HIPAA training from Petronella?
HIPAA training pricing depends on the number of workforce members, delivery format, role complexity, and whether you need initial training or annual refresher training. Petronella offers per-person and organizational licensing models. For self-paced training, our HIPAA Rescue Manual for Healthcare Practices is available at $999. Contact us for a custom quote on instructor-led and enterprise training programs.
How do I prove HIPAA training compliance during an audit?
During an OCR investigation or audit, you need to produce written training policies, training materials, attendance records, completion certificates, assessment results, and evidence that training is updated when policies change. Petronella provides all of these materials in a compliance binder format that auditors recognize. Organizations that work with Petronella for ongoing compliance management have all documentation maintained and audit-ready at all times.
What does 45 CFR 164.308(a)(5) require?
It requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management. The standard carries four addressable implementation specifications: periodic security reminders, protection from malicious software, log-in monitoring, and password management. Addressable does not mean optional: you either implement each specification, document why it is not reasonable and appropriate for your organization, or implement an equivalent alternative measure.
Who counts as a workforce member for HIPAA training?
HIPAA defines workforce broadly: employees, trainees, and volunteers whose conduct is under the direct control of the covered entity or business associate, whether or not they are paid. If a person can reach protected health information while doing their job, they belong in the training plan. Management is named explicitly in the Security Rule, so executives and practice owners need training too, and business associates must train their own staff under the HITECH Act and the 2013 Omnibus Rule.
How long must HIPAA training records be kept?
Six years. 45 CFR 164.316(b)(2)(i) requires documentation to be retained for six years from the date of its creation or the date it was last in effect, whichever is later. Keep your training policy, curriculum versions, completion records with dates, and assessment results for the full period.
What do HIPAA assessors typically ask to see?
Assessors typically ask for a current roster of workforce members, the written training policy, the curriculum used for each role, completion records with dates, certificates for a sample of staff, evidence that new hires were trained within a reasonable period after joining, and evidence of recurring refresher training. Verifiable certificates and a roster CSV with completion dates make this straightforward to produce.
How much does HIPAA training cost per employee?
The 2026 Security Awareness Training is $49 per learner for a 90-minute course, and team packs start at $290 for 10 seats with one enrollment code. For practice-wide compliance education, the HIPAA Rescue Manual for Healthcare Practices is $999 and the HIPAA Compliance and Cybersecurity Mastery course is $2,997. Every learner receives a certificate of completion, and buyers can export a roster CSV with completion dates.
Does Petronella offer CMMC Level 2 awareness and training courses?
Yes. The CMMC Level 2 Security Awareness Common Core course is $49 per learner and runs about 63 minutes, mapping to AT.L2-3.2.1 and AT.L2-3.2.3. Role-Based Training is available for General Users at $59 and for Executives at $149, each about 30 minutes and mapping to AT.L2-3.2.2. The Awareness and Training License bundles all three courses for $300 per user per year with one enrollment code for 1 to 500 users.
How do I verify a training certificate?
Training Academy certificates of completion can be verified at /training/verify/. Buyers can also export a roster CSV that lists each learner with completion dates, and CMMC courses carry a 12-month expiry, so the record shows when a refresher is due.
Can I buy HIPAA training for a whole team at once?
Yes. Team packs start at $290 for 10 seats, with 25 seats at $625, 50 seats at $999, and 100 seats at $1,499. Seats are redeemable for 12 months and the group is enrolled with a single code. To size a larger order, call Penny at 919-348-4912.
What is the difference between the two HIPAA courses?
The HIPAA Rescue Manual for Healthcare Practices is a $999 all-in-one compliance kit with editable templates, policies, risk assessments, and training materials for practices. The HIPAA Compliance and Cybersecurity Mastery course is $2,997 and goes deeper for healthcare leaders and compliance officers, adding customizable policies, breach response, and a certificate of completion.
Does HIPAA training also cover CMMC requirements?
No. HIPAA and CMMC are separate frameworks with separate training practices. HIPAA training obligations come from the Security Rule at 45 CFR 164.308(a)(5) and the Privacy Rule at 45 CFR 164.530(b). CMMC Level 2 assesses awareness and training as AT.L2-3.2.1, AT.L2-3.2.2, and AT.L2-3.2.3. One security awareness program can be mapped to both: the Common Core course maps to AT.L2-3.2.1 and AT.L2-3.2.3, and the role-based courses map to AT.L2-3.2.2.
HIPAA Rescue Manual for Healthcare Practices
Our comprehensive self-paced HIPAA training course supports your compliance program with practical education for the whole team. Includes the Privacy Rule, Security Rule, Breach Notification, risk assessment requirements, and practical implementation guides. Complete at your own pace with built-in knowledge assessments and completion certificates.
More Courses from the Training Academy
Pair the HIPAA Rescue Manual with the advanced HIPAA course for compliance officers and the annual security awareness course for every employee. Every learner receives a certificate of completion you can file as training evidence. Browse the full catalog in the Training Academy.
HIPAA Compliance and Cybersecurity Mastery
Advanced HIPAA and cybersecurity training for healthcare leaders and compliance officers: customizable policies, breach response, and a certificate of completion.
2026 Security Awareness Training
Phishing, passwords, multi-factor authentication, social engineering, and how to report an incident fast. Written for every non-technical employee. Per-seat annual enrollment with a certificate of completion.
Browse the Training Academy
Digital forensics, AI tools, device security, and compliance courses. Enroll one seat online, or buy a team pack from $290 for 10 seats with one enrollment code and a roster.
Complete HIPAA Compliance Solutions
Train Your Team on HIPAA Compliance
Practical, role-based HIPAA training that maps to federal requirements, reduces breach risk, and supports a culture of compliance. Petronella Technology Group, Inc. has trained healthcare teams since 2002 from Raleigh, NC, and is a Cyber AB Registered Provider Organization (#1449).
Covered entities and business associates need regular HIPAA security risk assessment.