Who We Are
HIPAAITSecurityTraining.com provides web-based HIPAA security awareness training and assessment for healthcare professionals, business associates, and organizations subject to HIPAA requirements or seeking to understand them. This policy explains what personal information we collect, how we use it, and your rights regarding that information.
This policy is designed to comply with applicable US privacy laws. This service is intended for users in the United States.
What We Collect
When you register for and complete training, we collect the following information:
- Full name
- Email address
- Professional credentials (optional)
- Organization code (optional)
- Assessment score and pass/fail status
- A completion record identifier
- Timestamps for registration, training start, assessment start, and completion
- Which assessment questions were answered incorrectly on your first attempt, if any, tied to your completion record identifier rather than your name or email directly
We do not collect payment information, health information, or any data beyond what is listed above.
If you choose to complete our optional feedback survey, we also collect:
- Your role in your organization (selected from a list, with a free-text option if you select "Other")
- Your likelihood to recommend this training (a numeric rating)
- Your reasons for that rating (free-text)
- Your email address, if you voluntarily provide it to allow follow-up on your feedback
Survey responses that do not include an email address are anonymous. Email addresses provided via the survey are deleted within 90 days, after which those responses become anonymous as well.
Why We Collect It
We collect this information solely to:
- Verify your identity before training begins
- Deliver the training assessment
- Issue a certificate of completion
- Maintain completion records for your organization's compliance documentation (if you are completing training as part of a client organization)
- Respond to your inquiries
- Understand user experience and improve the training (survey responses)
- Follow up with survey respondents who requested it
- Identify commonly missed topics so we can improve the content and clarity of the training
We do not sell your data to advertisers or data brokers. We do not use your data for advertising or marketing purposes. Completion records may be provided to organizations under a written agreement, as described in How We Share Your Data.
How We Share Your Data
We do not share your personal data with third parties except as necessary to operate the platform or as described below. The following vendors process data on our behalf:
- Netlify — hosts the platform application. No learner data is stored by Netlify.
- Google (Apps Script and Sheets) — processes registration, token validation, and completion recording. Data is retained for seven days.
- Airtable — serves as the system of record for completed assessments. Data is retained for six years.
- Resend — delivers transactional emails to users.
Completion records may be shared with organizations that have entered into a written agreement with us for access to workforce completion records. We do not independently verify the requester's organizational relationship to you or their authority to receive your record. By completing this training, you grant us the right to share your completion record on this basis. We are not responsible for how records are used once provided.
Data Retention
| Data | Retention Period |
|---|---|
| Airtable assessment records | 6 years |
| Google Sheets assessment records | 7 days |
| Copies of system-generated email notifications (registration, completion, and sync-alert emails), retained as a backup record | 2 years |
| Feedback survey responses (anonymous) | May be retained indefinitely |
| Email addresses provided via survey | 90 days |
At the end of each retention period, data is deleted and is not recoverable.
We also retain copies of certain system-generated emails in our own records for up to two years as a backup in case a completion record cannot be located in Airtable.
International Data Transfers
HIPAAITSecurityTraining.com and all of its vendors are based in the United States. If you are located outside the United States, your personal data will be transferred to and processed in the United States. All vendors represent that they maintain security programs consistent with applicable data protection standards.
Your Rights
You have the right to request access to, correction of, or deletion of your personal data. To submit a request, contact us by email at Support@HIPAAITSecurityTraining.com from the email address associated with your training record. We require requests to come from the email address on file as a reasonable step to verify your identity and confirm that the record belongs to you.
If you no longer have access to that email address, we are unable to verify your identity and cannot process the request. In that case, if your training was completed as part of an organizational account, the organization may be able to submit a request on your behalf.
We will respond to all verified requests within 30 days.
There is no automated decision-making applied to your data that produces legal or significant effects.
Security
We maintain administrative and technical safeguards designed to protect your personal data against unauthorized access, disclosure, or loss. Organizations evaluating our security posture may contact Support@HIPAAITSecurityTraining.com to request additional information.
Changes to This Policy
If we make material changes to this policy, we will update the effective date at the top of this page. We encourage you to review this policy periodically.
Contact
For privacy inquiries, deletion requests, or questions about your data, contact us at:
support@hipaaitsecuritytraining.com
HIPAAITSecurityTraining.com