HIPAA · United States

HIPAA workforce security
awareness, evidenced.

The HIPAA Security Rule, at 45 CFR 164.308(a)(5), requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management.

Rule
45 CFR 164.308(a)(5): security awareness and training
Specifications
Security reminders, malware protection, log-in monitoring and password management, all addressable
Frequency
Not set in the current rule; a January 2025 proposal is not final
KeenSec evidence
Training certificates, simulation results, report logs, policy acknowledgements

What HIPAA says about training

The rule today, and
what is proposed.

The current rule is in force.

ProvisionWhat it saysStatus
164.308(a)(5)(i)A security awareness and training program for all members of the workforce, including management.In force
164.308(a)(5)(ii)Security reminders, protection from malicious software, log-in monitoring and password management, all addressable.In force
164.404(b)Notify individuals without unreasonable delay, and no later than 60 days after discovering a breach.In force
Security Rule proposal, 6 January 2025Training at least every 12 months, and within 30 days of new access, covering malicious software and social engineering.Proposed, not final
NIST SP 800-50 Rev. 1Practical exercises can include phishing, smishing and vishing simulations, and should not be punitive.Guidance

Busy people, urgent requests

Front desks and clinics
are always on the phone.

Healthcare staff juggle patients, calls and messages, which makes urgent-sounding requests hard to question.

Expectation to record

The workforce record
for your security officer.

TRAINING

Workforce completes security training.

LMS completions, assessments and certificates.

SIMULATION RESULTS

Workforce tested on realistic threats.

Outcomes per channel, team and location.

REPORT LOGS

Workforce reports suspicious messages.

Phishing Reporter logs with automated analysis.

POLICY ACKNOWLEDGEMENTS

Workforce accepts your policies.

Dated records per person and version.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. 45 CFR 164.308, Administrative safeguardseCFR, current
  2. 45 CFR 164.404, Notification to individualseCFR, current
  3. HIPAA Security Rule notice of proposed rulemaking6 January 2025 · 90 FR 898 · not final
  4. NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning ProgramSeptember 2024 · guidance

Questions buyers ask

Frequently asked questions.

How often does HIPAA require security training?

The current rule sets no frequency. The Security Rule update proposed in January 2025 would require training at least every 12 months, but it was not final as of September 2026.

Are phishing simulations appropriate under HIPAA?

The rule does not mention them. NIST SP 800-50 Rev. 1 describes phishing, smishing and vishing simulations as practical exercises and recommends they are not punitive.

Does KeenSec make us HIPAA compliant?

No tool makes you compliant on its own. KeenSec helps you run and evidence workforce security awareness; your compliance team and auditors decide compliance.

Can KeenSec train staff who share workstations or work shifts?

Yes. Micro-learning fits short breaks, and training works on any device, with reminders to chase anyone who has not completed.

Let’s connect the dots

Prepare the workforce.
Prove the programme.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo