HIPAAFluent

Plain answers

There is no official HIPAA certification. Here's what the law actually requires.

If you've searched for "HIPAA certification," you've seen dozens of vendors — including us — offering courses that end in a certificate. So it's fair to ask: which certificate is the official one? The honest answer, which surprisingly few training companies put in writing, is that none of them are.

No government body certifies HIPAA compliance

The Department of Health and Human Services — the agency that writes and enforces the HIPAA rules through its Office for Civil Rights — does not issue HIPAA certifications, does not accredit training vendors, and does not endorse any course, product, or seal. Any certificate you or your staff earn, from any provider, is a private credential: evidence that a person completed a particular training program, nothing more.

That also means no vendor can truthfully sell you "certified compliant" status. Compliance isn't a certificate; it's an ongoing state of meeting the rules' requirements — and it can only be assessed against what your organization actually does.

What the rules do require: documented workforce training

Two provisions create the training obligation nearly every healthcare workplace is trying to meet:

  • The Privacy Rule requires a covered entity to train all members of its workforce on its privacy policies and procedures, as necessary and appropriate for their jobs — including new workforce members within a reasonable period after joining, and retraining when a material policy change affects someone's work. (45 CFR 164.530(b))
  • The Security Rule requires a security awareness and training program for all members of the workforce, including management. (45 CFR 164.308(a)(5))

"Workforce" is broader than "employees": it includes volunteers, trainees, and anyone whose work the organization directs, paid or not. And the training must be documented — HIPAA's documentation rules require records to be retained for six years. (45 CFR 164.530(j), 164.316)

What auditors and investigators actually ask for

When OCR investigates a complaint or breach, or when a business partner's security questionnaire lands on your desk, nobody asks which vendor's logo is on your certificates. They ask for the records: who was trained, on what, and when — and whether new hires and policy changes triggered training on schedule. A certificate of completion matters as one piece of that documentation trail, alongside your training log.

So what is a "certificate of completion" honestly worth?

It's proof that a specific person finished a specific course on a specific date — and that's genuinely useful, because it's exactly the kind of record the documentation rules expect you to keep. That's what our certificate is: each learner passes a quiz on every chapter and a final exam, and the certificate records that. What no certificate from anyone can be is a government credential or a guarantee of compliance.

How our course fits in

Our eight-chapter video course covers the Privacy and Security Rules with every claim cited to the regulations and HHS's own guidance — you can check each chapter's sources yourself. Learners must score 80% on every chapter quiz and the final exam, each learner earns an individual certificate, and organization admins can export their team's training records. It's built to be exactly the documented workforce training the rules describe.

45 CFR 164.530(b) 45 CFR 164.308(a)(5) 45 CFR 164.316 All our sources

Common questions

Is HIPAA certification required by law?

No. The law requires workforce training and documentation of it — not any certification. Certificates are simply a convenient way to document that training happened.

Does a training certificate make my practice HIPAA compliant?

No certificate can. Training is one requirement among many — risk analysis, safeguards, policies, business associate agreements, and breach procedures are separate obligations. Training documentation covers the training requirement, nothing else.

How often does my staff need to retrain?

The rules set triggers rather than a calendar: train new workforce members within a reasonable period, and retrain when material policy changes affect someone's job. Annual retraining is the widely adopted convention because it comfortably satisfies those triggers and is easy to document.

Read the training provisions in full
Who counts as "workforce" for training purposes?

Employees, volunteers, trainees, and other people whose work is under the organization's direct control — whether or not they are paid. If they can encounter patient information doing work you direct, plan to train them.

We're a substance use disorder treatment program — is HIPAA training enough?

HIPAA awareness is the foundation, but most SUD treatment programs are also subject to 42 CFR Part 2, a separate, consent-based federal confidentiality rule with its own requirements. Our course covers HIPAA; your Part 2 policies belong with your compliance officer or counsel.

Read our HIPAA vs. 42 CFR Part 2 comparison

Need your team's training documented?

Eight short video chapters, quizzes, individual certificates, and exportable records.

Start the course