What This Training Accomplishes
The political reality in many health systems is that security requirements often take a back seat when they compete with clinical demands. That is a problem. IT security is not just a compliance requirement, it is critical to the well-being of patients and the organizations that care for them. Blocking, overriding, or ignoring security measures puts patient data and clinical systems at risk. The people involved often don't recognize the consequences of their actions. That is what this training was designed to address.
The first version of this training was developed by Michael E. Brown MD, MS, MHCM, a physician executive who served as Chief Information Officer and Chief Information Security Officer at Harvard University Health Services. Dr. Brown created the training after finding that IT security was not adequately appreciated by clinical staff, and that available training was not engaging clinicians the way he thought it should.
Rather than framing security as a compliance obligation, it presents the operational and clinical consequences of security failures and lets those facts make the case. The training is designed to be direct without being alarmist, and it focuses on what clinical staff actually need to know.
The training uses real cases and specific statistics throughout rather than simply presenting general principles. Most clinical staff already know much of what they should do. The challenge is that competing clinical priorities make it easy to treat security as someone else's problem. Real cases help clinicians see themselves in the middle of a ransomware attack in which systems stop working and care is disrupted. The cases in this training were selected because they make that case in ways that general guidance cannot.
The training also avoids covering material clinical staff don't need. It assumes clinicians are backed by IT and medical records staff, and it does not attempt to cover topics owned by those roles, such as endpoint virus protection or the release of records to outside organizations. Password complexity is similarly left out since these days most clinical systems already enforce it.
The training itself is a self-paced online module with a built-in assessment. Learners have two attempts on each question and must answer every question correctly to pass. On completion, learners receive a certificate of completion, and the platform maintains verified completion records suitable for compliance documentation.
Organizations can assign the online training directly to staff, or license the underlying content for use in their own LMS. The training is intended for use as-is by most organizations, though custom versions can be developed on request. It was designed with clinicians in mind but is appropriate for most staff without dedicated IT, medical records, or compliance responsibilities.
Who This Training Is Designed For
This training was built for clinicians, but it does not require clinical knowledge. It works well for both clinical and non-clinical staff who are comfortable reading evidence-based material and drawing conclusions from it.
That said, it is not designed for everyone. Staff who have difficulty with this reading level may find this training challenging. Organizations with staff across a wide range of educational backgrounds may be better served by pairing it with a simpler option for those who need it. If you have staff for whom this training is too difficult and have decided you want one unified training for everyone, this product may not be the right fit.
This training also does not cover what staff in specialized roles such as IT or medical records need to know. People in those roles may find it useful and relevant, but organizations should expect to supplement it with additional training specific to those responsibilities.
We designed this training to be accessible to a broad audience, but we optimized it for clinicians. That focus is what makes it effective for its intended audience, and it is also what distinguishes it from training built to reach everyone at once.
Why There Is No "Certified HIPAA Training"
HIPAA requires regular security training, and most organizations interpret this as an annual requirement. This training was designed to meet that requirement for clinicians as-is in a typical healthcare system, though whether it does so for your organization is a determination only your organization can make.
No training product, including ours, can claim to be "HIPAA certified" or guarantee compliance on its own, because no such certification exists. These terms are used by some in marketing, but they don't carry any regulatory weight.
Federal regulations require organizations to conduct annual risk assessments and implement training that reasonably addresses the risks those assessments identify. What counts as reasonable is determined by each organization, and that determination needs to hold up under scrutiny. Enforcement typically follows audits by the Office for Civil Rights, and organizational leadership needs to be able to explain what they did and why they believed it was sufficient. A vendor product that simply claims certification status would not strengthen that explanation, and could weaken it by suggesting the organization relied on vendor claims instead of considering what its staff actually needed.
This means any training product, however well designed, is one input into a larger compliance picture that each organization must define for itself. Two factors in particular shape what an organization actually needs:
First, organizational context matters. If clinicians are well supported by IT and medical records departments, training does not need to cover ground those departments already own. If technology systems enforce specific behaviors, training time does not need to be spent encouraging those behaviors.
Second, training portfolio matters. If an organization runs other training throughout the year, that changes what the annual training needs to cover. Some content is more effective delivered in other contexts. Knowing who to call when something looks wrong, for example, is important for every staff member, but organizations may prefer to handle that through onboarding or department-level training rather than annual security modules.
Standards and Sources
Two NIST publications informed the training's structure and standards alignment.
NIST Special Publication 800-50, Revision 1, Building a Cybersecurity and Privacy Learning Program (September 2024) informed our approach to training design and awareness program structure, though it is not HIPAA specific and we did not use it as a source for specific content. Available at https://doi.org/10.6028/NIST.SP.800-50r1.
NIST Special Publication 800-66, Revision 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide (February 2024) helped define HIPAA Security Rule compliance standards, though its focus is organizational compliance rather than end user education. Available at https://doi.org/10.6028/NIST.SP.800-66r2.
For every topic in the training, we documented our rationale for inclusion and how it connects to NIST and other standards, in a form that can support your organization's own audit trail. We also documented the topics we chose to exclude and why. That full review, along with our learning objectives document, is available to organizations evaluating our content. Contact Licensing@HIPAAITSecurityTraining.com to request it.