HIPAA workforce training
HIPAA training for the whole practice.
Patient Protect provides online HIPAA training for healthcare employees, office personnel, managers, and compliance officers. Start with 5 free modules. Unlock the full 19-module HIPAA Foundations series — about 1 hour, 45 minutes of instruction, 95 knowledge-assessment questions, administrator tracking, and QR-verifiable Certificates of Completion.
No credit card for free access · Self-paced · Built for healthcare workforces
19
Focused training modules
~1h 45m
Expert-led instruction
95
Knowledge-assessment questions
25
Personnel included with Basic
Why the training is this deep — and this affordable
HIPAA is not a short subject. Training for it shouldn’t be either.
Most HIPAA training available to a small practice runs 20 to 30 minutes total. That is not enough time to meaningfully cover the Privacy Rule, the Security Rule, the Breach Notification Rule, and the operational workflows that actually put patient information at risk. And practices know it — which is why so many workforces treat annual training as an event to survive rather than an obligation to master.
The Patient Protect HIPAA Foundations series is 19 focused modules totaling about 1 hour, 45 minutes, with 95 knowledge-assessment questions across the series. Each module is short by design. Together they cover the full operational surface of HIPAA a healthcare workforce actually encounters — the vocabulary and regulatory framework, the Privacy Rule, the Security Rule, business associates, breach notification, incident handling, auditing, enforcement, and the workforce decisions that lead to breaches in practice.
The philosophy behind that breadth: breadth belongs in the program, precision belongs in the assignment. The HIPAA officer gets enough content in scope to assign the right depth to the right person — a receptionist, a clinician, a biller, an office manager, and the compliance officer do not need identical training. When the library is broad enough, precision becomes an assignment choice rather than a content limitation.
“Every practice I worked in had a compliance binder on the shelf. Not one of them could have survived a real audit — and none of them knew it. Training that closes that gap has to be written from inside the treatment room, not from a policy outline.”
The economics
What most offices pay for HIPAA training vs. what an office actually needs to pay.
Industry norm · per-seat pricing
$625–$875/office/year
25 personnel × $25–$35 per seat, per year. Training only. Nothing else included.
Patient Protect Basic · office pricing
$468/office/year
25 personnel included. Full 19-module Foundations series, 95 assessment questions, per-learner scoring, verifiable Certificates of Completion, workforce roster — plus the broader Patient Protect compliance platform.
At 25 personnel, Basic works out to $18.72 per person for a full year of training access. The point is not to make HIPAA training cheap by making it thin. The point is to make extensive, accountable training economically realistic for the practices expected to provide it.
Start with substance
The first five modules are completely free.
Not trailers. Not fragments. about 30 minutes covering the laws and responsibilities every healthcare workforce needs to understand — plus 25 assessment questions.
Each module page includes an original educational companion alongside the video — concepts, practical application, common questions, and links to primary CFR and HHS sources. The pages are not summaries. They exist to make the training material easier to retain and apply after the video ends.

Module 01· Free
HIPAA Fundamentals
Vocabulary + regulatory framework
The history of HIPAA, the two federal bodies that enforce it, the two main Rules, and the vocabulary every workforce member should be able to define — PHI, ePHI, encryption, breach, covered entity, business associate.

Module 02· Free
HIPAA Privacy Rule
Use, disclosure + patient rights
The Privacy Rule, Privacy Officer designation, workforce confidentiality practices, the 30-day patient access right, state-varying record retention (6–10 years), and the penalty tiers for non-compliance.

Module 03· Free
HIPAA Security Rule
ePHI protection + safeguards
The Security Rule, mandatory risk assessment, Security Officer designation, secure networks, BAAs, MFA, encryption, secure device use (registered devices, screen time-outs, password rotation), and staff-training cadence.

Module 04· Free
HIPAA Breach Notification Rule
Incident analysis + notification
The definition of a breach and the three exceptions to it, what unsecured PHI is, the individual/media/HHS notification timelines, business associate notification, and the administrative documentation the rule requires.

Module 05· Free
Real-World Breach Scenarios & Best Practices
Applied workforce decision-making
Six real-world scenarios — lost unencrypted laptop, public discussion of patient info, misdirected email, improper record disposal, unauthorized employee access, unlocked workstation — and the specific workforce practices that prevent each one.
~30 min of free instruction · 25 assessment questions
Unlock free training →Breadth with structure
From the law to the moment something goes wrong.
Each module is concise by design. Together, the 19 build a working understanding of privacy, security, safeguards, response, resilience, and accountability.
Learn
Focused instruction turns the rules into understandable responsibilities.
Demonstrate
5 questions per module measure comprehension — not passive attendance.
Prove
Completion, scores, and certificate attribution remain visible to the practice.

Sample certificate. Live certificates populate with the learner’s name, completion date, assessment score, unique certificate ID, and a QR code linking to the verification record.
Not just completed. Documented.
A certificate for the learner. Visibility for the administrator. Evidence for the practice.
Every certificate includes a unique identifier and a QR code that opens its verification record. Office administrators can monitor progress, see full assessment scores, and confirm exactly who has — and has not — completed training.
Independent verification
Scan the QR code to confirm certificate attribution and validity. Any party — auditor, insurer, credentialer — can verify without trusting the presenter. How verification works →
Measured comprehension
Full assessment scores — 95 questions across the 19-module series — reveal understanding, not just attendance.
Workforce-wide tracking
Administrators see progress and completion across office personnel — who is complete, incomplete, or overdue.
Building a defensible training file? Download the HIPAA Training Evidence Checklist →
The economics of the whole office
Stop buying HIPAA training one person at a time.
Move the slider. Patient Protect automatically recommends the more economical plan based on workforce size.
Up to 50independent practices receive one year of complete HIPAA Foundations training — free.
Selected offices receive all 19 modules, 95 knowledge checks, administrator tracking, and QR-verifiable Certificates of Completion for up to 25 personnel. No hidden conversion. No public review required. Applications close September 21.
See the initiativeOffice personnel
25
At 25 personnel, Base costs $1.56 per person per month— $18.72 per person for an entire year of access. Training is only one part of the subscription.
BASE
$39/month
Recommended office subscription
$1.56
per person / month
$18.72
per person / year
$468
annual office cost
25
personnel included
$407 less than a $35-per-seat purchase at this size.
Basic
Complete Foundations
$39/mo
- Up to 25 personnel included
- All 19 Foundations modules
- 95 knowledge-assessment questions
- Tracking and QR-verifiable certificates
- +$10/month per additional five personnel
Pro
Foundations + deeper access
$99/mo
- Up to 50 personnel included
- Everything in Basic
- Advanced training as released
- Full Pro platform access
- +$5/month per additional five personnel
Training that connects to compliance
Most training products end with a certificate. Patient Protect begins there.
Training creates understanding. The surrounding platform helps the practice turn that understanding into an operating compliance program.
Security risk assessments
Identify and document risks to protected information.
Policies and procedures
Connect workforce expectations to documented practice standards.
Vendor and BAA oversight
Manage the third parties that touch patient data.
Incident and breach readiness
Prepare the practice to recognize, respond, and document.
ePHI auditing
Understand where protected information moves and where exposure lives.
Compliance evidence
Keep the work visible instead of scattered across folders and inboxes.
Coming to Pro
Foundations are available now. Mastery keeps expanding.
The Advanced Pro curriculum moves beyond general awareness into role-, specialty-, technology-, and risk-specific education. Every category below shows the modules planned for the series — each becomes available as released. No locked placeholders on the platform.
9 categories · 62modules planned · Included with Pro as released
Role-Based Training
Tailored tracks so staff only sit through what's relevant to their job.
8 planned
Role-Based Training
Tailored tracks so staff only sit through what's relevant to their job.
- HIPAA for Front Desk & ReceptionComing to Pro
- HIPAA for Clinical Staff (Doctors, Hygienists, Nurses)Coming to Pro
- HIPAA for Billing & CodingComing to Pro
- HIPAA for Office Managers & AdministratorsComing to Pro
- HIPAA for Privacy & Security OfficersComing to Pro
- HIPAA for Remote & Hybrid WorkersComing to Pro
- HIPAA for New Hires (Onboarding Track)Coming to Pro
- HIPAA for Leadership & Practice OwnersComing to Pro
Specialty & Practice Type
Generic training doesn't account for how different specialties actually operate.
7 planned
Specialty & Practice Type
Generic training doesn't account for how different specialties actually operate.
- HIPAA for Dental PracticesComing to Pro
- HIPAA for Mental & Behavioral HealthComing to Pro
- HIPAA for Pediatric PracticesComing to Pro
- HIPAA for Physical Therapy & RehabComing to Pro
- HIPAA for Dermatology & Medical SpasComing to Pro
- HIPAA for Telehealth ProvidersComing to Pro
- HIPAA for Multi-Location & Group PracticesComing to Pro
Threat Awareness
Operational security training that goes beyond compliance into active risk prevention.
8 planned
Threat Awareness
Operational security training that goes beyond compliance into active risk prevention.
- Phishing & Social EngineeringComing to Pro
- Ransomware Awareness & ResponseComing to Pro
- Password & Credential SecurityComing to Pro
- Email Security Best PracticesComing to Pro
- Mobile Device RisksComing to Pro
- Insider ThreatsComing to Pro
- Smishing & Vishing (Phone & Text-Based Attacks)Coming to Pro
- Deep Fakes & AI-Generated Fraud in HealthcareComing to Pro
Patient Rights & Experience
Compliance from the patient interaction side — critical for front-facing staff.
6 planned
Patient Rights & Experience
Compliance from the patient interaction side — critical for front-facing staff.
- Understanding Patient Rights Under HIPAAComing to Pro
- Handling Access & Record RequestsComing to Pro
- Patient Authorizations & ConsentComing to Pro
- Responding to Patient ComplaintsComing to Pro
- Communicating About PHI with Family MembersComing to Pro
- Minor Patients & Guardian ConsentComing to Pro
Vendor & Third-Party Management
Goes deeper than BAAs — covers the full vendor lifecycle.
6 planned
Vendor & Third-Party Management
Goes deeper than BAAs — covers the full vendor lifecycle.
- Identifying Business AssociatesComing to Pro
- Vetting & Onboarding VendorsComing to Pro
- BAA Lifecycle ManagementComing to Pro
- Monitoring Third-Party ComplianceComing to Pro
- Subcontractor ObligationsComing to Pro
- Terminating Vendor Relationships CompliantlyComing to Pro
Legal & Regulatory Landscape
For practices that need to go beyond federal HIPAA minimums.
7 planned
Legal & Regulatory Landscape
For practices that need to go beyond federal HIPAA minimums.
- State Privacy Laws & HIPAA Overlap (IL, CA, TX, WA, NY)Coming to Pro
- HIPAA & State Mental Health Privacy LawsComing to Pro
- HIPAA & Substance Use Records (42 CFR Part 2)Coming to Pro
- HIPAA & Reproductive Health Privacy (post-Dobbs)Coming to Pro
- HITECH Act Deep DiveComing to Pro
- OCR Audit PreparationComing to Pro
- Understanding HIPAA Penalties & Enforcement ActionsComing to Pro
Technology & Systems
For the increasingly digital healthcare environment.
7 planned
Technology & Systems
For the increasingly digital healthcare environment.
- EHR Security & ComplianceComing to Pro
- Cloud Storage & HIPAAComing to Pro
- Telehealth Platforms & ComplianceComing to Pro
- AI Tools in Healthcare — Risks & RulesComing to Pro
- HIPAA & Patient PortalsComing to Pro
- Secure Texting & Messaging ToolsComing to Pro
- Wearables & Connected DevicesComing to Pro
Compliance Operations
The management layer — turning training into sustainable systems.
7 planned
Compliance Operations
The management layer — turning training into sustainable systems.
- Building a HIPAA Compliance ProgramComing to Pro
- Conducting Internal AuditsComing to Pro
- Writing & Maintaining PoliciesComing to Pro
- Managing a Workforce Training ProgramComing to Pro
- Compliance Documentation Best PracticesComing to Pro
- Creating a Culture of ComplianceComing to Pro
- Annual Compliance Review ProcessComing to Pro
Incident & Crisis Management
What to do when something actually goes wrong.
6 planned
Incident & Crisis Management
What to do when something actually goes wrong.
- Breach Response PlaybookComing to Pro
- Communicating a Breach to PatientsComing to Pro
- Working with Legal Counsel During an IncidentComing to Pro
- OCR Investigation — What to ExpectComing to Pro
- Post-Incident Review & RemediationComing to Pro
- PR & Reputation Management After a BreachComing to Pro
Advanced Pro modules are unlocked with the Pro plan ($99/office/month, up to 50 personnel) as they are released. Every learner also retains full access to the 19-module Foundations series regardless of plan.

Led by Angie Perrin, RDH
15 years inside independent practices. 13 years at chair-side. Certified HIPAA Privacy Consultant.
Angie is the Chief Security Officer of Patient Protect, a Certified HIPAA Privacy Consultant (CHPC), a Registered Dental Hygienist licensed since 2013, and an adjunct instructor in dental education. She has worked inside independent dental practices since 2011 — the exact vantage that most HIPAA training content is missing.
Every module in the HIPAA Foundationsseries is written from operational experience inside real practices — and reflects the classroom discipline of an instructor whose job includes explaining clinical judgment to students. Not recycled legal boilerplate. Not a marketer’s summary of what the rule says.
Content last reviewed 2026-08-15 · Full instructor bio and review methodology
HIPAA training questions
What HIPAA actually requires — and what it doesn’t.
- Does HIPAA require workforce training?
- Yes. The Privacy Rule (45 CFR §164.530(b)) requires covered entities to train workforce members on applicable policies and procedures concerning protected health information as necessary and appropriate to their functions. The Security Rule (45 CFR §164.308(a)(5)) requires a security-awareness and training program for all workforce members, including management.
- Does HIPAA require annual training?
- Federal HIPAA does not prescribe one universal annual course or government-issued certification. The Privacy Rule requires training for workforce members, for new members within a reasonable period after joining, and for personnel affected by a material policy or procedure change. The Security Rule requires an ongoing security-awareness program with periodic security updates. Many organizations also adopt annual refresher training as a reasonable operational standard on top of those event-driven requirements.
- Is Patient Protect issuing a government-recognized HIPAA certification?
- No. There is no government-issued HIPAA compliance certification. Patient Protect issues a Certificate of Completion that documents successful completion of the assigned training series. The certificate carries a unique identifier and QR code that opens its verification record.
- How is completion verified?
- Every certificate includes a unique identifier and a QR code that opens the certificate's attribution and verification record. Office administrators can also see per-learner assessment scores and workforce-wide completion status.
- What is included for free?
- The first five modules — HIPAA Fundamentals, the Privacy Rule, the Security Rule, the Breach Notification Rule, and Real-World Breach Scenarios & Best Practices — are free and hosted on YouTube on the Patient Protect channel. Together they include ~30 min of instruction and 25 assessment questions. No credit card is required for free access.
- What does the full HIPAA Foundations series cover?
- The complete Foundations series is 19 modules totaling about 1 hour, 45 minutes of instruction with 95 knowledge-assessment questions. It covers Privacy, Security, Breach Notification, real-world breach scenarios, risk assessments, all three safeguard categories (administrative, physical, technical), policies and procedures, workforce training, BAAs, incident response, auditing, backup and recovery, device and media controls, facility access, continuous improvement, and HIPAA enforcement.
- Is HIPAA training the only thing Patient Protect provides?
- No. HIPAA training is included inside a broader compliance platform covering risk assessments, policies, workforce management, vendor oversight, incident readiness, secure workflows, and compliance evidence. Training is one administrative safeguard within a larger operating program.
- How is Patient Protect priced?
- Patient Protect is priced by office rather than by seat. Basic is $39 per office per month and includes up to 25 personnel (+$10/month per additional five). Pro is $99 per office per month and includes up to 50 personnel (+$5/month per additional five). At 25 personnel, Basic works out to $18.72 per person for a full year of access — and training is only one part of the subscription.
Want the regulatory background? Read HIPAA Training Requirements → A companion article on what the Privacy Rule and Security Rule actually require, what counts as proof of completion, and what most offices miss.
Train everyone. Measure understanding. Prove completion.
HIPAA training that leaves evidence behind.
Start with five free modules. Bring the whole practice into the complete program when you are ready.
Part of the HIPAA Foundation · 15+ free tools
See the full collectionTrain the workforce
Five modules here, hosted on YouTube. The platform runs all 19 Foundations modules with role-based assignments, per-learner assessment scores, verifiable Certificates of Completion, and workforce-wide tracking.
Next in the sequence
HIPAA GlossaryPublic HIPAA training modules, a 203-term glossary with regulatory citations, and machine-readable references for acronyms, PHI identifiers, and state breach-notification law.

