HIPAA-aware training sized for a small practice
Dental and medical practices handle protected health information every day with front-desk, billing, and clinical staff who are not security specialists. Cyberwareness builds HIPAA security-awareness training around the roles that actually touch patient data.
What practice staff actually face
- Phishing emails impersonating insurance payers, billing clearinghouses, or practice management software vendors.
- Front-desk staff handling patient scheduling and insurance verification calls, a target for pretexting attempts to extract patient details.
- Shared front-desk and clinical workstations with patient records open to anyone walking by if screens are not locked.
- Billing staff processing patient payments, exposed to fake payment-portal links and business email compromise.
- Mobile and personal devices used to text or photograph patient information outside approved systems.
HIPAA Security Rule awareness and training
The HIPAA Security Rule (45 CFR 164.308(a)(5)) requires a security awareness and training program for all workforce members. HIPAA specifies 'periodic' training, not a fixed calendar requirement, so we say this 'supports your periodic training duty' rather than claiming it satisfies an annual HIPAA mandate. Confirm your practice's specific HIPAA compliance program with your privacy officer or legal counsel.
See our other US page: CPA & tax firms →Recommended tracks
Frequently asked questions
Does this satisfy HIPAA's annual training requirement?
HIPAA requires "periodic" training, not a specifically named annual cadence. We phrase this as supporting your periodic training duty under 45 CFR 164.308(a)(5). Confirm your practice's training policy and cadence with your privacy officer, since what counts as adequately "periodic" can depend on your risk assessment.
Is this a replacement for a full HIPAA compliance program?
No. Staff awareness training is one required safeguard. A full HIPAA program also needs a risk assessment, policies and procedures, business associate agreements, and breach response planning, which are outside the scope of this training.
Can front-desk staff with no security background follow this?
Yes, modules are written in plain language with no assumed technical background, and are 3-7 minutes each so they fit between patients.