Course Overview
Course Content
Lesson 1: Introduction
Course objectives, HIPAA’s purpose, and why comprehensive privacy and security training matters for covered entities.
Lesson 2: HIPAA Basics
Privacy Rule components, covered entities vs. business associates, protected health information (PHI) definition, minimum necessary standard, and organizational requirements.
Lesson 3: Using and Disclosing PHI
Permitted uses without authorization, required disclosures, optional disclosures, and when authorization is mandatory.
Lesson 4: Individuals’ Rights of Access to PHI
Right to access records, request amendments, receive accounting of disclosures, request restrictions on uses/disclosures, and confidential communications, plus organizational response requirements.
Lesson 5: Securing PHI
Security Rule requirements, administrative safeguards, physical safeguards, technical safeguards.
Lesson 6: Breach Notification Rules
Breach definition, risk assessment factors, notification timelines (individual, media, HHS), documentation requirements, and breach prevention strategies.
Lesson 7: Enforcement
Penalty tiers, enforcement authority, investigation procedures, resolution agreements, and recent enforcement actions.
Who This Course Is For
Certificate & Compliance
Upon successful completion, learners receive an official certificate of completion demonstrating compliance with HIPAA training requirements for covered entities under 45 CFR §164.530(b).
The course includes scenario-based assessments that test judgment and decision-making skills in realistic healthcare situations, not just factual recall. This ensures employees can apply HIPAA principles to the ambiguous privacy and security situations they’re likely to encounter in clinical and administrative settings. Certificates are generated immediately and can be downloaded or printed for compliance documentation.
Supports Compliance With:
- HIPAA Privacy Rule (45 CFR §164.530(b))
- HIPAA Security Rule workforce training standards (45 CFR §164.308(a)(5))
- Breach Notification Rule documentation expectations
- Joint Commission compliance for patient rights and privacy
- CMS Conditions of Participation training requirements
- OCR audit and compliance review documentation

