Skip to content
AwareSprint

HIPAA · Awareness and training safeguard

HIPAA: security awareness and training for the workforce

HIPAA names security awareness and training as an administrative safeguard and lists what the program should address. Unusually for a regulation, it also tells you how long to keep the paperwork.

What it actually asks for

A program for all workforce members
The standard covers the whole workforce, including management. Anyone who handles protected health information sits inside it, employees and others alike.
Periodic security reminders
The rule contemplates ongoing reminders and not a single induction session, which is where a recurring format does the work naturally.
Named subject areas
Protection from malicious software, log in monitoring and password management are called out specifically. Your content should visibly address each.
Six year documentation retention
Documentation of policies and the actions taken must be retained for six years. That includes the record of who was trained and when.

Where organisations come unstuck

Organisations usually run the training and then cannot produce six years of records for it. Because the retention period is unusually long, gaps from previous years surface during an investigation at the worst possible moment.

The evidence to keep

  • A dated completion record for every workforce member, retained for six years
  • Coverage of malicious software, log in monitoring and password management
  • Evidence of periodic reminders across the year, not one annual event
  • Records for people who have since left, kept for the retention period
  • An audit trail supporting the integrity of the record

How AwareSprint helps

AwareSprint runs short security challenges for your whole team and produces a completion register with dates, content versions and participation across the population. That is the record this clause asks you to produce. It does not make you compliant, and no platform can. It gives you the training evidence, so the rest of your programme is what your auditor spends time on.

Work email only. Nothing to install and no card required.

Your spot is saved today. Onboarding opens in September and the challenge starts 1 October 2026.

Registering your whole company?Use the company form

Other standards

FAQ

Questions

What teams ask about HIPAA and awareness training.

How often does HIPAA require security awareness training?

The rule does not set a fixed interval. It requires a program with periodic security reminders, which regulators read as ongoing. Many organisations settle on annual training plus regular reinforcement to show the program is live.

Do we need to train contractors?

Workforce members include people whose conduct is under the direct control of the entity, which often brings contractors and volunteers in. Business associates carry their own obligations under their agreement with you.

How long do we keep the training records?

Six years from creation or from when the documentation was last in effect, whichever is later. This is longer than most standards and it catches organisations out.