HIPAA · United States
HIPAA workforce security
awareness, evidenced.
The HIPAA Security Rule, at 45 CFR 164.308(a)(5), requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management.
- Rule
- 45 CFR 164.308(a)(5): security awareness and training
- Specifications
- Security reminders, malware protection, log-in monitoring and password management, all addressable
- Frequency
- Not set in the current rule; a January 2025 proposal is not final
- KeenSec evidence
- Training certificates, simulation results, report logs, policy acknowledgements
What HIPAA says about training
The rule today, and
what is proposed.
The current rule is in force.
| Provision | What it says | Status |
|---|---|---|
| 164.308(a)(5)(i) | A security awareness and training program for all members of the workforce, including management. | In force |
| 164.308(a)(5)(ii) | Security reminders, protection from malicious software, log-in monitoring and password management, all addressable. | In force |
| 164.404(b) | Notify individuals without unreasonable delay, and no later than 60 days after discovering a breach. | In force |
| Security Rule proposal, 6 January 2025 | Training at least every 12 months, and within 30 days of new access, covering malicious software and social engineering. | Proposed, not final |
| NIST SP 800-50 Rev. 1 | Practical exercises can include phishing, smishing and vishing simulations, and should not be punitive. | Guidance |
Busy people, urgent requests
Front desks and clinics
are always on the phone.
Healthcare staff juggle patients, calls and messages, which makes urgent-sounding requests hard to question.
Patient Portal <no-reply@portal-update.example>
Portal password expires today
Your staff portal password expires today. Sign in to keep access to patient records.
Keep my access- Deadline pressure
- Lookalike domain
Expectation to record
The workforce record
for your security officer.
Workforce completes security training.
LMS completions, assessments and certificates.
Workforce tested on realistic threats.
Outcomes per channel, team and location.
Workforce reports suspicious messages.
Phishing Reporter logs with automated analysis.
Workforce accepts your policies.
Dated records per person and version.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- 45 CFR 164.308, Administrative safeguardseCFR, current
- 45 CFR 164.404, Notification to individualseCFR, current
- HIPAA Security Rule notice of proposed rulemaking6 January 2025 · 90 FR 898 · not final
- NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning ProgramSeptember 2024 · guidance
Questions buyers ask
Frequently asked questions.
How often does HIPAA require security training?
The current rule sets no frequency. The Security Rule update proposed in January 2025 would require training at least every 12 months, but it was not final as of September 2026.
Are phishing simulations appropriate under HIPAA?
The rule does not mention them. NIST SP 800-50 Rev. 1 describes phishing, smishing and vishing simulations as practical exercises and recommends they are not punitive.
Does KeenSec make us HIPAA compliant?
No tool makes you compliant on its own. KeenSec helps you run and evidence workforce security awareness; your compliance team and auditors decide compliance.
Can KeenSec train staff who share workstations or work shifts?
Yes. Micro-learning fits short breaks, and training works on any device, with reminders to chase anyone who has not completed.
Let’s connect the dots
Prepare the workforce.
Prove the programme.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo