Resources
What HIPAA requires you to document.
HIPAA requires two things in combination: that you actually train your workforce, and that you document it. The Privacy Rule (45 CFR §164.530(b)(2)(i)) requires workforce training on your organization's privacy policies and procedures. The Security Rule (45 CFR §164.308(a)(5)) requires a security awareness and training program. Neither rule mandates one exact record format — but both require retaining that documentation for six years from the date it was created or last in effect (45 CFR §164.530(j)(2)).
How often is HIPAA training required?
HIPAA doesn’t set a fixed retraining interval by rule. It requires training at the time someone joins the workforce, and again whenever a material policy change affects their duties. Most well-run organizations treat it as ongoing rather than annual-only — policy and role changes don’t happen on a calendar, so a training program built around a once-a-year event tends to miss the changes that happen in between.
How long do you have to keep HIPAA training records?
Six years from the date the record was created, or from the date it was last in effect, whichever is later — 45 CFR §164.530(j)(2).
What has to be in the record?
At minimum: name, date, topic covered, and delivery method. Beyond the minimum, the record is only as useful as your ability to prove it hasn’t been altered since it was created — which is a documentation-integrity problem most training platforms don’t actually solve.
Who counts as “workforce” under HIPAA?
Employees, volunteers, trainees, and anyone else under the direct control of a covered entity or business associate — not only clinical staff.
This is exactly what an attestation record is built to hold. See how it works.