Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Staff Training

Staff training goes without saying, but what does this look like in your organization?

Would this be an annual PowerPoint for HIPAA training that has been presented year after year?

Is there a mandatory online training course that ensures all staff (including physicians) complete, but does not alert management to those who failed the training?

Within the course or throughout the year has cybersecurity and security awareness training been incorporated?

Are part-time, per diems, students or interns required to complete HIPAA, cybersecurity and security awareness training for the organization, or is it fine for them to say they’ve completed with their business already?

Read the questions above again – how did you answer them? We know annual HIPAA training must be completed; we also know the same training over and over again does nothing to enforce learning or compliance.

When investing in the cost of training how is this effective if there is no follow-up? If a staff member, physician or owner fail trainings shouldn’t there be remedial education?

CISA, HHS 405(d), NIST, HHS OCR all have resources, tools and free training videos available. The more information you present will reinforce and educate your team.

Treat part-timers, volunteers or interns, and students the same as your full-time employees. Remember your organization is offering free cybersecurity education which will help each employee safeguard against cyber attacks in their personal lives.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.