Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA workforce training

HIPAA training for the whole practice.

Patient Protect provides online HIPAA training for healthcare employees, office personnel, managers, and compliance officers. Start with 5 free modules. Unlock the full 19-module HIPAA Foundations series — about 1 hour, 45 minutes of instruction, 95 knowledge-assessment questions, administrator tracking, and QR-verifiable Certificates of Completion.

No credit card for free access · Self-paced · Built for healthcare workforces

19

Focused training modules

~1h 45m

Expert-led instruction

95

Knowledge-assessment questions

25

Personnel included with Basic

Why the training is this deep — and this affordable

HIPAA is not a short subject. Training for it shouldn’t be either.

Most HIPAA training available to a small practice runs 20 to 30 minutes total. That is not enough time to meaningfully cover the Privacy Rule, the Security Rule, the Breach Notification Rule, and the operational workflows that actually put patient information at risk. And practices know it — which is why so many workforces treat annual training as an event to survive rather than an obligation to master.

The Patient Protect HIPAA Foundations series is 19 focused modules totaling about 1 hour, 45 minutes, with 95 knowledge-assessment questions across the series. Each module is short by design. Together they cover the full operational surface of HIPAA a healthcare workforce actually encounters — the vocabulary and regulatory framework, the Privacy Rule, the Security Rule, business associates, breach notification, incident handling, auditing, enforcement, and the workforce decisions that lead to breaches in practice.

The philosophy behind that breadth: breadth belongs in the program, precision belongs in the assignment. The HIPAA officer gets enough content in scope to assign the right depth to the right person — a receptionist, a clinician, a biller, an office manager, and the compliance officer do not need identical training. When the library is broad enough, precision becomes an assignment choice rather than a content limitation.

“Every practice I worked in had a compliance binder on the shelf. Not one of them could have survived a real audit — and none of them knew it. Training that closes that gap has to be written from inside the treatment room, not from a policy outline.”
— Angie Perrin, RDH · Chief Security Officer · adjunct dental instructor, in offices since 2011

The economics

What most offices pay for HIPAA training vs. what an office actually needs to pay.

Industry norm · per-seat pricing

$625–$875/office/year

25 personnel × $25–$35 per seat, per year. Training only. Nothing else included.

Patient Protect Basic · office pricing

$468/office/year

25 personnel included. Full 19-module Foundations series, 95 assessment questions, per-learner scoring, verifiable Certificates of Completion, workforce roster — plus the broader Patient Protect compliance platform.

At 25 personnel, Basic works out to $18.72 per person for a full year of training access. The point is not to make HIPAA training cheap by making it thin. The point is to make extensive, accountable training economically realistic for the practices expected to provide it.

Start with substance

The first five modules are completely free.

Not trailers. Not fragments. about 30 minutes covering the laws and responsibilities every healthcare workforce needs to understand — plus 25 assessment questions.

Each module page includes an original educational companion alongside the video — concepts, practical application, common questions, and links to primary CFR and HHS sources. The pages are not summaries. They exist to make the training material easier to retain and apply after the video ends.

HIPAA Fundamentals — What is HIPAA? Everything Your Practice Needs to Know
5:33

Module 01· Free

HIPAA Fundamentals

Vocabulary + regulatory framework

The history of HIPAA, the two federal bodies that enforce it, the two main Rules, and the vocabulary every workforce member should be able to define — PHI, ePHI, encryption, breach, covered entity, business associate.

Open module
HIPAA Privacy Rule — HIPAA Privacy Rule Explained: What Your Practice Must Know
4:55

Module 02· Free

HIPAA Privacy Rule

Use, disclosure + patient rights

The Privacy Rule, Privacy Officer designation, workforce confidentiality practices, the 30-day patient access right, state-varying record retention (6–10 years), and the penalty tiers for non-compliance.

Open module
HIPAA Security Rule — HIPAA Security Rule: How to Protect Patient Data in Your Practice
5:30

Module 03· Free

HIPAA Security Rule

ePHI protection + safeguards

The Security Rule, mandatory risk assessment, Security Officer designation, secure networks, BAAs, MFA, encryption, secure device use (registered devices, screen time-outs, password rotation), and staff-training cadence.

Open module
HIPAA Breach Notification Rule — HIPAA Breach Notification Rule: What Your Practice Must Do
7:56

Module 04· Free

HIPAA Breach Notification Rule

Incident analysis + notification

The definition of a breach and the three exceptions to it, what unsecured PHI is, the individual/media/HHS notification timelines, business associate notification, and the administrative documentation the rule requires.

Open module
Real-World Breach Scenarios & Best Practices — 6 HIPAA Violations That Happen in Every Healthcare Practice
5:23

Module 05· Free

Real-World Breach Scenarios & Best Practices

Applied workforce decision-making

Six real-world scenarios — lost unencrypted laptop, public discussion of patient info, misdirected email, improper record disposal, unauthorized employee access, unlocked workstation — and the specific workforce practices that prevent each one.

Open module

~30 min of free instruction · 25 assessment questions

Unlock free training →

Breadth with structure

From the law to the moment something goes wrong.

Each module is concise by design. Together, the 19 build a working understanding of privacy, security, safeguards, response, resilience, and accountability.

01
HIPAA FundamentalsFree
5:33
02
HIPAA Privacy RuleFree
4:55
03
HIPAA Security RuleFree
5:30
04
HIPAA Breach Notification RuleFree
7:56
05
Real-World Breach Scenarios & Best PracticesFree
5:23
06
Risk Assessments
5:43
07
Administrative Safeguards
5:41
08
Physical Safeguards
4:52
09
Technical Safeguards
5:00
10
Policies & Procedures
5:31
11
Workforce Training
4:53
12
Business Associate Agreements
5:31
13
Incident Response
5:33
14
Auditing & Monitoring
5:14
15
Data Backup & Recovery
4:48
16
Device & Media Controls
5:08
17
Facility Access Controls
4:25
18
Continuous Improvement
4:23
19
HIPAA Enforcement, Audits & Penalties
5:28

Learn

Focused instruction turns the rules into understandable responsibilities.

Demonstrate

5 questions per module measure comprehension — not passive attendance.

Prove

Completion, scores, and certificate attribution remain visible to the practice.

Patient Protect Certificate of Completion example — includes learner name, series completed, completion date, assessment score, certificate ID, and QR verification code

Sample certificate. Live certificates populate with the learner’s name, completion date, assessment score, unique certificate ID, and a QR code linking to the verification record.

Not just completed. Documented.

A certificate for the learner. Visibility for the administrator. Evidence for the practice.

Every certificate includes a unique identifier and a QR code that opens its verification record. Office administrators can monitor progress, see full assessment scores, and confirm exactly who has — and has not — completed training.

Independent verification

Scan the QR code to confirm certificate attribution and validity. Any party — auditor, insurer, credentialer — can verify without trusting the presenter. How verification works →

Measured comprehension

Full assessment scores — 95 questions across the 19-module series — reveal understanding, not just attendance.

Workforce-wide tracking

Administrators see progress and completion across office personnel — who is complete, incomplete, or overdue.

Building a defensible training file? Download the HIPAA Training Evidence Checklist →

The economics of the whole office

Stop buying HIPAA training one person at a time.

Move the slider. Patient Protect automatically recommends the more economical plan based on workforce size.

Up to 50independent practices receive one year of complete HIPAA Foundations training — free.

Selected offices receive all 19 modules, 95 knowledge checks, administrator tracking, and QR-verifiable Certificates of Completion for up to 25 personnel. No hidden conversion. No public review required. Applications close September 21.

See the initiative

Office personnel

25

1–150
12550100150

At 25 personnel, Base costs $1.56 per person per month— $18.72 per person for an entire year of access. Training is only one part of the subscription.

BASE

$39/month

Recommended office subscription

$1.56

per person / month

$18.72

per person / year

$468

annual office cost

25

personnel included

$407 less than a $35-per-seat purchase at this size.

Basic

Complete Foundations

$39/mo

  • Up to 25 personnel included
  • All 19 Foundations modules
  • 95 knowledge-assessment questions
  • Tracking and QR-verifiable certificates
  • +$10/month per additional five personnel

Pro

Foundations + deeper access

$99/mo

  • Up to 50 personnel included
  • Everything in Basic
  • Advanced training as released
  • Full Pro platform access
  • +$5/month per additional five personnel

Training that connects to compliance

Most training products end with a certificate. Patient Protect begins there.

Training creates understanding. The surrounding platform helps the practice turn that understanding into an operating compliance program.

Security risk assessments

Identify and document risks to protected information.

Policies and procedures

Connect workforce expectations to documented practice standards.

Vendor and BAA oversight

Manage the third parties that touch patient data.

Incident and breach readiness

Prepare the practice to recognize, respond, and document.

ePHI auditing

Understand where protected information moves and where exposure lives.

Compliance evidence

Keep the work visible instead of scattered across folders and inboxes.

Coming to Pro

Foundations are available now. Mastery keeps expanding.

The Advanced Pro curriculum moves beyond general awareness into role-, specialty-, technology-, and risk-specific education. Every category below shows the modules planned for the series — each becomes available as released. No locked placeholders on the platform.

9 categories · 62modules planned · Included with Pro as released

Role-Based Training

Tailored tracks so staff only sit through what's relevant to their job.

8 planned
  1. HIPAA for Front Desk & ReceptionComing to Pro
  2. HIPAA for Clinical Staff (Doctors, Hygienists, Nurses)Coming to Pro
  3. HIPAA for Billing & CodingComing to Pro
  4. HIPAA for Office Managers & AdministratorsComing to Pro
  5. HIPAA for Privacy & Security OfficersComing to Pro
  6. HIPAA for Remote & Hybrid WorkersComing to Pro
  7. HIPAA for New Hires (Onboarding Track)Coming to Pro
  8. HIPAA for Leadership & Practice OwnersComing to Pro

Specialty & Practice Type

Generic training doesn't account for how different specialties actually operate.

7 planned
  1. HIPAA for Dental PracticesComing to Pro
  2. HIPAA for Mental & Behavioral HealthComing to Pro
  3. HIPAA for Pediatric PracticesComing to Pro
  4. HIPAA for Physical Therapy & RehabComing to Pro
  5. HIPAA for Dermatology & Medical SpasComing to Pro
  6. HIPAA for Telehealth ProvidersComing to Pro
  7. HIPAA for Multi-Location & Group PracticesComing to Pro

Threat Awareness

Operational security training that goes beyond compliance into active risk prevention.

8 planned
  1. Phishing & Social EngineeringComing to Pro
  2. Ransomware Awareness & ResponseComing to Pro
  3. Password & Credential SecurityComing to Pro
  4. Email Security Best PracticesComing to Pro
  5. Mobile Device RisksComing to Pro
  6. Insider ThreatsComing to Pro
  7. Smishing & Vishing (Phone & Text-Based Attacks)Coming to Pro
  8. Deep Fakes & AI-Generated Fraud in HealthcareComing to Pro

Patient Rights & Experience

Compliance from the patient interaction side — critical for front-facing staff.

6 planned
  1. Understanding Patient Rights Under HIPAAComing to Pro
  2. Handling Access & Record RequestsComing to Pro
  3. Patient Authorizations & ConsentComing to Pro
  4. Responding to Patient ComplaintsComing to Pro
  5. Communicating About PHI with Family MembersComing to Pro
  6. Minor Patients & Guardian ConsentComing to Pro

Vendor & Third-Party Management

Goes deeper than BAAs — covers the full vendor lifecycle.

6 planned
  1. Identifying Business AssociatesComing to Pro
  2. Vetting & Onboarding VendorsComing to Pro
  3. BAA Lifecycle ManagementComing to Pro
  4. Monitoring Third-Party ComplianceComing to Pro
  5. Subcontractor ObligationsComing to Pro
  6. Terminating Vendor Relationships CompliantlyComing to Pro

Legal & Regulatory Landscape

For practices that need to go beyond federal HIPAA minimums.

7 planned
  1. State Privacy Laws & HIPAA Overlap (IL, CA, TX, WA, NY)Coming to Pro
  2. HIPAA & State Mental Health Privacy LawsComing to Pro
  3. HIPAA & Substance Use Records (42 CFR Part 2)Coming to Pro
  4. HIPAA & Reproductive Health Privacy (post-Dobbs)Coming to Pro
  5. HITECH Act Deep DiveComing to Pro
  6. OCR Audit PreparationComing to Pro
  7. Understanding HIPAA Penalties & Enforcement ActionsComing to Pro

Technology & Systems

For the increasingly digital healthcare environment.

7 planned
  1. EHR Security & ComplianceComing to Pro
  2. Cloud Storage & HIPAAComing to Pro
  3. Telehealth Platforms & ComplianceComing to Pro
  4. AI Tools in Healthcare — Risks & RulesComing to Pro
  5. HIPAA & Patient PortalsComing to Pro
  6. Secure Texting & Messaging ToolsComing to Pro
  7. Wearables & Connected DevicesComing to Pro

Compliance Operations

The management layer — turning training into sustainable systems.

7 planned
  1. Building a HIPAA Compliance ProgramComing to Pro
  2. Conducting Internal AuditsComing to Pro
  3. Writing & Maintaining PoliciesComing to Pro
  4. Managing a Workforce Training ProgramComing to Pro
  5. Compliance Documentation Best PracticesComing to Pro
  6. Creating a Culture of ComplianceComing to Pro
  7. Annual Compliance Review ProcessComing to Pro

Incident & Crisis Management

What to do when something actually goes wrong.

6 planned
  1. Breach Response PlaybookComing to Pro
  2. Communicating a Breach to PatientsComing to Pro
  3. Working with Legal Counsel During an IncidentComing to Pro
  4. OCR Investigation — What to ExpectComing to Pro
  5. Post-Incident Review & RemediationComing to Pro
  6. PR & Reputation Management After a BreachComing to Pro

Advanced Pro modules are unlocked with the Pro plan ($99/office/month, up to 50 personnel) as they are released. Every learner also retains full access to the 19-module Foundations series regardless of plan.

Angie Perrin, RDH — Certified HIPAA Privacy Consultant and instructor of the Patient Protect HIPAA Foundations series

Led by Angie Perrin, RDH

15 years inside independent practices. 13 years at chair-side. Certified HIPAA Privacy Consultant.

Angie is the Chief Security Officer of Patient Protect, a Certified HIPAA Privacy Consultant (CHPC), a Registered Dental Hygienist licensed since 2013, and an adjunct instructor in dental education. She has worked inside independent dental practices since 2011 — the exact vantage that most HIPAA training content is missing.

Every module in the HIPAA Foundationsseries is written from operational experience inside real practices — and reflects the classroom discipline of an instructor whose job includes explaining clinical judgment to students. Not recycled legal boilerplate. Not a marketer’s summary of what the rule says.

CHPC Certified
RDH · Licensed 2013
Adjunct Instructor
In offices since 2011

Content last reviewed 2026-08-15 · Full instructor bio and review methodology

HIPAA training questions

What HIPAA actually requires — and what it doesn’t.

Does HIPAA require workforce training?
Yes. The Privacy Rule (45 CFR §164.530(b)) requires covered entities to train workforce members on applicable policies and procedures concerning protected health information as necessary and appropriate to their functions. The Security Rule (45 CFR §164.308(a)(5)) requires a security-awareness and training program for all workforce members, including management.
Does HIPAA require annual training?
Federal HIPAA does not prescribe one universal annual course or government-issued certification. The Privacy Rule requires training for workforce members, for new members within a reasonable period after joining, and for personnel affected by a material policy or procedure change. The Security Rule requires an ongoing security-awareness program with periodic security updates. Many organizations also adopt annual refresher training as a reasonable operational standard on top of those event-driven requirements.
Is Patient Protect issuing a government-recognized HIPAA certification?
No. There is no government-issued HIPAA compliance certification. Patient Protect issues a Certificate of Completion that documents successful completion of the assigned training series. The certificate carries a unique identifier and QR code that opens its verification record.
How is completion verified?
Every certificate includes a unique identifier and a QR code that opens the certificate's attribution and verification record. Office administrators can also see per-learner assessment scores and workforce-wide completion status.
What is included for free?
The first five modules — HIPAA Fundamentals, the Privacy Rule, the Security Rule, the Breach Notification Rule, and Real-World Breach Scenarios & Best Practices — are free and hosted on YouTube on the Patient Protect channel. Together they include ~30 min of instruction and 25 assessment questions. No credit card is required for free access.
What does the full HIPAA Foundations series cover?
The complete Foundations series is 19 modules totaling about 1 hour, 45 minutes of instruction with 95 knowledge-assessment questions. It covers Privacy, Security, Breach Notification, real-world breach scenarios, risk assessments, all three safeguard categories (administrative, physical, technical), policies and procedures, workforce training, BAAs, incident response, auditing, backup and recovery, device and media controls, facility access, continuous improvement, and HIPAA enforcement.
Is HIPAA training the only thing Patient Protect provides?
No. HIPAA training is included inside a broader compliance platform covering risk assessments, policies, workforce management, vendor oversight, incident readiness, secure workflows, and compliance evidence. Training is one administrative safeguard within a larger operating program.
How is Patient Protect priced?
Patient Protect is priced by office rather than by seat. Basic is $39 per office per month and includes up to 25 personnel (+$10/month per additional five). Pro is $99 per office per month and includes up to 50 personnel (+$5/month per additional five). At 25 personnel, Basic works out to $18.72 per person for a full year of access — and training is only one part of the subscription.

Want the regulatory background? Read HIPAA Training Requirements → A companion article on what the Privacy Rule and Security Rule actually require, what counts as proof of completion, and what most offices miss.

Train everyone. Measure understanding. Prove completion.

HIPAA training that leaves evidence behind.

Start with five free modules. Bring the whole practice into the complete program when you are ready.

Part of the HIPAA Foundation · 15+ free tools

See the full collection
TrainFree · proprietary

Train the workforce

Five modules here, hosted on YouTube. The platform runs all 19 Foundations modules with role-based assignments, per-learner assessment scores, verifiable Certificates of Completion, and workforce-wide tracking.

Next in the sequence

HIPAA Glossary

Public HIPAA training modules, a 203-term glossary with regulatory citations, and machine-readable references for acronyms, PHI identifiers, and state breach-notification law.