After a small practice reported a breach last year (a billing employee's email account was compromised through a phishing message and used to send fake invoices), the OCR investigator's document request had eleven items. Item seven was "documentation of workforce training on HIPAA policies and procedures, including dates, content and attendees, for the past six years." The practice sent 14 certificates from an online course titled "HIPAA Basics." The investigator wrote back asking what the course covered about phishing, because that was how the breach happened, and the practice could not say.

HIPAA training for medical office staff is one of the few compliance requirements every practice knows it has, and one of the few that most practices satisfy in form and not in substance. The rules require it. They do not describe it in detail, which means a practice can meet the letter with a generic 20-minute video and still have a front desk that reads results aloud in the waiting room and a billing office that clicks links in payer emails.

Here is what the rules actually require, what a training program for a small practice should contain by role, how often to run it, and what records to keep so that item seven has a good answer.

Key takeaways

  • The Privacy Rule requires training on the practice's own policies for every workforce member, new hires within a reasonable time, and after material changes; the Security Rule requires an ongoing security awareness program.
  • Neither rule sets a fixed interval, but annual training plus periodic reminders is the standard OCR expects to see, and the pending Security Rule update would make annual training explicit.
  • Training should be role-based: the front desk, the billing office and the clinical staff face different risks and need different scenarios.
  • Phishing, texting patients, minimum necessary and device handling are the four topics that account for most small-practice incidents.
  • Keep a training log with dates, content outline, attendees and assessment results for six years; certificates alone do not show what was taught.

What the rules require

Two provisions apply. The Privacy Rule (45 CFR 164.530(b)) requires a covered entity to train all members of its workforce on the policies and procedures with respect to protected health information (PHI) as necessary and appropriate for them to carry out their functions. New workforce members must be trained within a reasonable period after joining, and everyone must be retrained when a material change in policies affects their job. The Security Rule (45 CFR 164.308(a)(5)) requires a security awareness and training program for all workforce members, including management, with addressable specifications for security reminders, protection from malicious software, log-in monitoring and password management.

Notice what is not there: a required annual interval, a required number of hours, a required curriculum, a required vendor. "Workforce" is broad; it includes employees, volunteers, trainees and anyone else whose conduct is under the practice's direct control, paid or not, so the summer intern and the physician owner both count. Training on the practice's own policies is the requirement, which is why a generic course cannot satisfy it by itself: a course cannot teach staff where your fax machine is, who your privacy officer is or what your texting policy says.

The HIPAA Security Rule update that HHS proposed in January 2025 would, among many other things, require security training at least every 12 months and within a set period for new workforce members. As of this month the rule is still pending, as we have written before. We suggest practices act as if it were final on this point, because annual training is already what investigators expect to see.

HIPAA training for medical office staff: topics by role

A single all-staff session has its place for the common material: what PHI is, the minimum necessary standard (use or disclose only the PHI needed for the task), patient rights, how to recognize and report an incident internally, and the sanctions policy. After that, the useful training splits by role, because the risks do.

RoleHighest-risk situationsTraining contentScenario to use
Front desk and schedulingVerbal disclosures in the waiting room; releasing information to family members; sign-in sheets; texting and email with patients; identity verification on the phoneVerification script, what may be said at the window, the practice's texting and email policy, handling a request from a spouse or parent, the sign-in sheet ruleA caller says she is the patient's daughter and asks for test results
Billing and codingPhishing and business email compromise; payer portal credentials; sending PHI to the wrong payer or patient; statements to the wrong address; remote accessRecognizing phishing, verifying payment-change requests by phone, portal credential hygiene and MFA, secure transmission of records for appeals, address verification before statementsAn email from "the clearinghouse" asks the biller to log in through a link to fix a rejected file
Clinical staffPortable devices; screens visible to patients; discussing patients in shared spaces; photographs; personal phones for clinical textingDevice encryption and lock rules, screen positioning, photography policy, approved messaging tools, what to do when a device is lostA medical assistant photographs a wound with a personal phone to show the physician
Physicians and ownersCurbside consults by text; access to records of patients not under their care; social media; vendor contracts without a business associate agreementApproved channels, access rules and audit logs, the social media policy, business associate agreement requirement before any vendor touches PHIA physician replies to a one-star review with details of the patient's visit
Everyone, including managementSnooping in records of coworkers, family or public figures; shared passwords; walking away from an open workstationAccess is logged and audited; the sanctions policy; lock the screen; passwords are individualA staff member looks up a coworker's chart "to check she was OK"

The four topics that account for most incidents

Phishing is first. The breach reports OCR publishes and the settlements it announces, including the ransomware cases this spring, share an entry point: a person clicked. Training that works is not a definition of phishing; it is showing staff five real messages, three of them fake, and having them decide, then explaining the tells (a mismatched sender domain, urgency, a link to a login page, a request to change bank details). Do it live, and do it more than once a year; quarterly five-minute refreshers with a new example are more effective than one long session.

Texting patients is second. Practices text appointment reminders, results and even clinical instructions, often from staff members' personal phones. The training point is the policy: what may be sent by unencrypted text (reminders and logistics with minimal PHI, with the patient's agreement), what may not (results, diagnoses, anything detailed), and which tool is approved. If the practice has no written texting policy, the training exposes that, which is useful.

Minimum necessary is third, and it is the one the front desk violates most often without knowing. Reading a full name and reason for visit across a waiting room, leaving a schedule with diagnoses visible at the window, faxing a whole chart when a payer asked for one visit note. The training is concrete: here is what the schedule printout may contain, here is how we call patients from the waiting room, here is what goes in the appeal packet.

Device handling is fourth: encrypted laptops, no PHI on personal phones outside approved apps, what to do in the first hour after a device is lost. A lost encrypted laptop is usually not a reportable breach; a lost unencrypted one is, and the difference is a setting.

How often, how long and how to deliver it

Our recommended cadence for a small practice: a full annual session of 60 to 90 minutes with the role-based scenarios, new-hire training within the first week and before independent access to systems, a short retraining whenever a policy changes (a new texting tool, a new EHR, a new state privacy law), and quarterly security reminders of five to ten minutes, mostly phishing examples and one policy point. That schedule satisfies both rules, tracks the proposed 12-month requirement, and matches what investigators look for.

Delivery matters less than content. Purchased online courses are fine for the common material and give you a completion record; they must be supplemented with the practice-specific policies, ideally in a live session led by the privacy officer where staff can ask about the situations they actually face. A short quiz at the end of the annual session, scored and kept, is the cheapest way to show that training was received and understood, and it is the document that turns a certificate into evidence.

The records an investigator asks for

HIPAA requires that training be documented and that the documentation be retained for six years. The record that answers item seven has five parts: the date; the content, as an outline or slide deck or course description, specific enough to show what was covered; the attendees, by name and role, with signatures or system completion records; the assessment results, if any; and the trainer. A sign-in sheet with a slide deck attached is enough for a live session. A vendor completion report is enough for an online course, if the course outline is kept with it. Keep them together in a training binder or a compliance folder, one entry per session, and add the new-hire trainings as they happen.

When a policy changes, the retraining record should note which policy and which staff were affected. When a staff member is disciplined for a privacy violation, the sanctions record should reference the training they received on that point; that pairing is what shows a program that works rather than a folder of certificates.

Questions we hear

Can we just buy an online HIPAA course and be done?

You can buy one and use it for the common material. You cannot be done, because the rule requires training on your policies, and no vendor knows them. Add a 30-minute practice-specific session and a quiz, and keep the outline. That combination is defensible; the course alone is not.

Do the physicians and the practice owner have to attend?

Yes. The Security Rule names management specifically, and in our experience the incidents that involve physicians (texted consults, social media replies, records access outside a treatment relationship) are the ones that produce complaints. A physician who skips training and then appears in a complaint has made the investigator's case for them.

What about our billing company and other vendors?

They are business associates, responsible for training their own workforce under their own obligations, and your business associate agreement should say so. You are not required to train them, but you are required to have the agreement, and it is reasonable to ask a vendor for its training policy before you sign.

What to do this week

  1. Pull your training records for the past six years and check each one for date, content outline, attendees and assessment; note the gaps.
  2. Write or update the three policies training depends on most: texting and email with patients, device and mobile phone use, and social media.
  3. Build the role-based scenario list from the table, using situations that have actually happened in your practice.
  4. Schedule the annual session for the fall, the new-hire module for the next hire, and a quarterly phishing refresher starting next month.
  5. Create a one-page training log template and start using it at the next session.

Our RCM audit includes a review of billing office security practices when a practice asks for it, and the compliance module in our RCM training courses covers the billing-office scenarios above with real phishing examples.