Plain answers
What HIPAA actually requires for training, quoted from the regulation
Search for HIPAA training requirements and you will find long lists: a minimum number of hours, an approved curriculum, a renewal date fixed on the calendar. Very little of that is in the law. The training obligation lives in two provisions, both short enough to quote in full, and most of the confusion around it clears up as soon as you read them.
The Privacy Rule states it in one sentence
A covered entity must train all members of its workforce on the policies and procedures with respect to protected health information required by this subpart and subpart D of this part, as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity. — 45 CFR 164.530(b)(1)
Read it closely and you will notice what the training is about: your policies and procedures, rather than HIPAA in the abstract. That division of labor is worth understanding before you buy anything. A course teaches the rules those policies exist to implement, which is the part that takes real time to learn. Your organization still has to introduce people to its privacy officer, its complaint process, and the specific procedures it has written down, and no vendor can do that half for you.
The timing sits in the implementation specifications just below, and it is entirely event-driven:
(A) To each member of the covered entity's workforce by no later than the compliance date for the covered entity;
(B) Thereafter, to each new member of the workforce within a reasonable period of time after the person joins the covered entity's workforce; and
(C) To each member of the covered entity's workforce whose functions are affected by a material change in the policies or procedures required by this subpart or subpart D of this part, within a reasonable period of time after the material change becomes effective in accordance with paragraph (i) of this section. — 45 CFR 164.530(b)(2)(i)
The compliance date in (A) passed for everyone years ago: 45 CFR 164.534 set it at April 14, 2003 for providers, clearinghouses, and all but the smallest health plans. In a working practice today, two triggers remain. Someone joins, or a material change in your policies affects what they do. Each carries the same deadline, "within a reasonable period of time," and the regulation never puts a number on it.
The Security Rule adds an awareness program
Implement a security awareness and training program for all members of its workforce (including management). — 45 CFR 164.308(a)(5)(i)
That parenthetical matters: owners, practice managers, and physician partners are workforce members for this purpose, so the requirement reaches them too. Four implementation specifications hang off the standard at 164.308(a)(5)(ii), each marked Addressable — periodic security updates, procedures for guarding against, detecting, and reporting malicious software, log-in monitoring, and password management.
"Addressable" gets read as "optional," and it does not mean that. The rule that governs it spells out the alternatives:
[A] covered entity or business associate must — (i) Assess whether each implementation specification is a reasonable and appropriate safeguard in its environment … and (ii) … (A) Implement the implementation specification if reasonable and appropriate; or (B) If implementing the implementation specification is not reasonable and appropriate — (1) Document why it would not be reasonable and appropriate to implement the implementation specification; and (2) Implement an equivalent alternative measure if reasonable and appropriate. — 45 CFR 164.306(d)(3)
So the sequence is to assess the specification, then either implement it or document why it is not reasonable and appropriate and put an equivalent measure in its place. Passing over a specification in silence is not among the choices, which is why "addressable" tends to create paperwork rather than remove it.
"Workforce" reaches past your payroll
Workforce means employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid by the covered entity or business associate. — 45 CFR 160.103
Volunteers and trainees are named in the definition, and the closing clause settles the question people usually ask next: the test is direct control over the work, whether or not anyone is paid. A shadowing student or a retired physician who volunteers on Fridays is a workforce member. The courier who collects specimens for an outside laboratory usually is not, because that company rather than your practice directs their work.
What the regulation does not say
We searched the complete text of 45 CFR Parts 160 and 164 as published on August 19, 2026. Apart from the two provisions above, the word "training" appears only inside definitions that have nothing to do with workforce education. There is no required hour count, no mandated syllabus, no list of approved providers, and no certification anyone can issue on the government's behalf.
There is also no annual deadline. The words "annual" and "annually" appear exactly three times across Parts 160 and 164 — in the receipts test that defines a small health plan, in the yearly inflation adjustment to penalty amounts, and in a health plan's next annual mailing when its notice of privacy practices changes — and not once in connection with training. Retraining every twelve months is a convention the industry converged on, and a sensible one, because a yearly cycle comfortably covers both regulatory triggers and leaves a documentation trail an investigator can follow. The twelve-month cycle is an industry convention rather than something you can point to in the text, so treat a vendor's claim that the law mandates it as a sales line.
How long you have to keep the record
Training that leaves no record is difficult to defend, and the rules make the record itself an obligation. The Privacy Rule requires a covered entity to "document that the training as described in paragraph (b)(2)(i) of this section has been provided" (45 CFR 164.530(b)(2)(ii)), and its documentation standard sets how long that record has to survive:
A covered entity must retain the documentation required by paragraph (j)(1) of this section for six years from the date of its creation or the date when it last was in effect, whichever is later. — 45 CFR 164.530(j)(2)
The Security Rule carries a matching requirement at 164.316(b)(2)(i), in the same six-year terms. When OCR opens an investigation after a complaint or a breach, or when a hospital system sends your practice a vendor questionnaire, this is the material that gets requested — who was trained, on what, and when. (45 CFR 164.316(b)(2)(i))
How our course fits
Our eight chapters cover the Privacy and Security Rules in about thirty-five minutes of video, with every claim cited to the regulations and to HHS guidance you can open yourself. Every chapter ends with a five-question quiz and the course closes with a final exam; the pass mark is 80% throughout. Each learner earns a dated certificate in their own name, and organization admins see who has finished and can export the roster as a CSV, which is the training log the documentation rules expect you to keep. No certificate from any vendor, ours included, is a government credential or a guarantee of compliance. Why there is no official HIPAA certification goes into that in more detail.
Regulation text on this page was pulled from the eCFR on August 21, 2026, reflecting Title 45 as current through August 19, 2026. Educational material, not legal advice.
Common questions
Is annual HIPAA training required by law?
No. Nothing in 45 CFR Parts 160 or 164 sets a calendar interval for workforce training. The regulation gives two triggers instead: train new workforce members within a reasonable period after they join, and retrain anyone whose job is affected by a material change to your policies. Most organizations run a yearly cycle because it satisfies both triggers and produces a clean record, which is a practical choice rather than a regulatory one.
How many hours of HIPAA training are required?
The regulation sets no hour count. It requires training on your policies and procedures "as necessary and appropriate" for people to carry out their functions, so the standard is relevance rather than clock time. A front desk coordinator and a systems administrator need different material.
Does HIPAA require a specific curriculum or an approved provider?
Neither exists. HHS does not publish a syllabus, accredit training vendors, or endorse any course. What it can ask you for is evidence that the training happened and covered what your workforce needs.
Does "addressable" mean we can skip it?
No. Under 45 CFR 164.306(d)(3) you assess whether the specification is reasonable and appropriate in your environment, then either implement it or document why it is not and put an equivalent alternative in place where one is reasonable. An addressable specification you passed over without writing anything down leaves you with a gap to explain.
Do volunteers, interns, and temps need HIPAA training?
If their work is under your direct control, yes — the definition of workforce names volunteers and trainees explicitly and ends by saying it applies whether or not they are paid. Contractors working under another company's direction are usually business associates instead, with obligations of their own.
What counts as a "material change" that triggers retraining?
The regulation uses the phrase without defining it. The workable reading is a change that alters what someone actually does with protected health information — a new records system, or a revised process for releasing charts. Cosmetic edits to a policy document do not change anyone's job.
Training your workforce, documented
Eight short video chapters, quizzes on each, individual certificates, and an exportable record for the whole team.