Skip to main content
Category: Governance and Workforce

Periodic Security Reminders

Also known as: Security Reminders, Security Awareness Reminders
Simply put

Periodic security reminders are ongoing communications that a healthcare organization sends to its workforce throughout the year to keep security practices top of mind. They are typically short pieces of information about security topics, such as protecting login credentials or handling sensitive data, shared with all staff members including management. They are one part of a broader security awareness effort rather than a one-time training event.

Formal definition

Periodic security reminders are an implementation specification within the Security Awareness and Training standard under the administrative safeguards of the HIPAA Security Rule. As an addressable implementation specification, it is not optional in the sense of being ignorable; a covered entity or business associate must assess whether the measure is reasonable and appropriate for its environment and either implement it, implement an equivalent alternative, or document why it is not reasonable and appropriate. In practice, security reminders are recurring communications distributed to the entire workforce (including management) covering security topics such as password practices, malware awareness, or safeguarding electronic protected health information (ePHI). The specification applies to safeguards protecting ePHI under the Security Rule and is distinct from Privacy Rule training obligations, which may address PHI in all forms. Cadence and content are not prescribed by a fixed regulatory schedule; organizations should confirm current requirements against the applicable Security Rule text and note that state law or other frameworks may impose additional expectations. Implementing security reminders supports, but does not by itself establish, HIPAA compliance.

Why it matters

Workforce members are a frequent point of exposure for security incidents, and a single annual training session tends to fade from memory as staff return to daily routines. Periodic security reminders address this gap by keeping core security practices, such as protecting login credentials, recognizing malware, and safeguarding electronic protected health information (ePHI), visible throughout the year rather than only at the moment of formal training. This ongoing reinforcement is the practical rationale behind treating security awareness as a continuous effort instead of a one-time event.

Under the HIPAA Security Rule, periodic security reminders sit within the Security Awareness and Training standard as an addressable implementation specification. Addressable does not mean optional. A covered entity or business associate must assess whether the measure is reasonable and appropriate for its environment and then either implement it, adopt an equivalent alternative, or document why it is not reasonable and appropriate. Skipping the assessment altogether, or ignoring the specification without documentation, can leave an organization exposed during an HHS OCR review.

It is important to keep expectations calibrated: implementing security reminders supports HIPAA compliance but does not by itself establish it, and the Security Rule does not prescribe a fixed schedule or mandated content. Organizations should confirm current requirements against the applicable Security Rule text and remember that state law, the HITECH Act, or other frameworks may impose additional expectations beyond HIPAA. Reminders are one component of a broader awareness program, not a substitute for it.

Who it's relevant to

Security Officers
Security officers are typically responsible for designing and maintaining the security awareness program, including deciding on the cadence and content of periodic reminders. They should document the assessment of whether reminders are reasonable and appropriate, retain records of what was distributed, and be prepared to demonstrate this to HHS OCR.
Compliance and Privacy Officers
Compliance and privacy officers help ensure that security reminders coordinate with broader training obligations without conflating Security Rule requirements (which cover ePHI) with Privacy Rule training (which may cover PHI in all forms). They should also confirm whether state law or other frameworks impose additional expectations beyond the Security Rule.
Covered Entities and Business Associates
Both covered entities and business associates are subject to the Security Rule's administrative safeguards and must address the security reminders specification for their own workforces. Business associates should note that these obligations apply to them directly under the Security Rule, in addition to any terms flowing through a business associate agreement.
Workforce Members and Management
Reminders are directed at all staff, including management, since everyone who handles ePHI contributes to the organization's security posture. Recipients should treat reminders as ongoing reinforcement of expected practices, not as a formality that replaces required training.
Auditors and Assessors
Auditors reviewing HIPAA Security Rule conformance will look for evidence that the organization assessed the reminders specification and either implemented it, adopted an equivalent alternative, or documented why it was not reasonable and appropriate. Note that HITRUST CSF assessments may reference related controls, but HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance.

Inside Periodic Security Reminders

Security Awareness and Training Standard
Periodic security reminders fall under the HIPAA Security Rule's administrative safeguards, specifically as an implementation specification within the security awareness and training standard applicable to covered entities and business associates handling ePHI.
Addressable Implementation Specification
Under the Security Rule, security reminders are generally treated as an addressable implementation specification. Addressable does not mean optional; an organization must implement the specification, adopt a reasonable and appropriate alternative, or document why it is not reasonable and appropriate for its environment.
Ongoing Workforce Communication
The core idea is recurring, periodic communication to the workforce to reinforce security practices over time rather than relying on a single point-in-time training event. Delivery methods can vary and are left to the organization's reasonable judgment.
Typical Reminder Topics
Reminders commonly reinforce awareness of matters such as protection against malicious software, login monitoring, and password management, which are themselves separate addressable specifications within the same training standard. The specific content should reflect the organization's own risk analysis.
Scope Limited to ePHI
Because this requirement derives from the Security Rule, it concerns the protection of electronic protected health information. Awareness obligations relating to PHI in oral or paper form arise instead under the Privacy Rule and its training provisions.

Common questions

Answers to the questions practitioners most commonly ask about Periodic Security Reminders.

Are periodic security reminders an optional part of HIPAA compliance since they are an addressable implementation specification?
No. Security reminders fall under the addressable implementation specifications within the Security Rule's administrative safeguards (as part of the security awareness and training standard), but addressable does not mean optional. Generally, a covered entity or business associate must assess whether the specification is reasonable and appropriate for its environment, and if it is not implemented as written, must document why and adopt an equivalent alternative measure where appropriate. Simply skipping reminders without that analysis and documentation is typically not consistent with the rule.
Does sending periodic security reminders by itself make an organization compliant with the HIPAA Security Rule or prevent breaches?
No. Security reminders are one component of the broader security awareness and training standard, which is itself only part of the administrative safeguards. They do not guarantee HIPAA compliance and do not, by themselves, prevent all breaches. They generally work alongside other administrative, physical, and technical safeguards. Compliance depends on the organization's overall implementation of the Security Rule, and effectiveness against breaches depends on many factors beyond periodic reminders.
How often should periodic security reminders be sent?
The Security Rule does not specify a fixed frequency; 'periodic' is left to the organization's reasonable judgment based on its risk analysis, workforce, and environment. In practice, many organizations distribute reminders on a recurring schedule and supplement them when circumstances change, but the appropriate cadence should be determined by your own risk assessment. Readers should verify current requirements against the applicable regulatory text and consider whether state law or other frameworks impose additional expectations.
What topics can periodic security reminders cover?
Reminders commonly address recurring, real-world risks relevant to the workforce, such as guarding against malicious software, monitoring for suspicious activity, password and login practices, and recognizing social engineering. The specific topics should generally be driven by the organization's risk analysis and current threat landscape rather than a fixed list, and may be updated as new risks emerge.
Who must receive periodic security reminders within an organization?
The security awareness and training standard applies to the entire workforce, which generally includes employees, and may include volunteers, trainees, and others under the direct control of the covered entity or business associate, regardless of whether they are paid. Reminders are typically directed at all members of the workforce who may interact with ePHI or the systems that handle it, rather than only IT staff.
How should an organization document its periodic security reminders?
Because the Security Rule generally requires that policies, procedures, and certain actions be documented and retained, organizations typically keep records of the reminders issued, their content, distribution dates, and intended audience. If reminders are implemented as an alternative to, or a tailored version of, the addressable specification, the organization should also document the rationale. Retention and documentation practices should be confirmed against current HIPAA requirements, and note that HITRUST CSF or other frameworks may set additional documentation expectations.

Common misconceptions

Because security reminders are addressable, an organization can simply skip them.
Addressable does not mean optional. An organization must either implement periodic reminders, implement a reasonable and appropriate alternative that achieves the same purpose, or document its assessment that the specification is not reasonable and appropriate for its environment and why.
A single annual training session satisfies the security reminder expectation.
The specification contemplates periodic, ongoing reinforcement rather than a one-time event. A single annual training may support the broader training standard, but periodic reminders are generally intended to sustain awareness between formal training cycles.
Sending security reminders guarantees compliance or prevents breaches.
No single measure guarantees HIPAA compliance or prevents all breaches. Periodic reminders are one component of the administrative safeguards and must be integrated with an organization's broader risk analysis and security program; they do not by themselves demonstrate overall compliance.

Best practices

Base the content and frequency of reminders on your organization's risk analysis, and document that reasoning as part of your Security Rule compliance record.
Since this is an addressable specification, document your decision to implement it, adopt an alternative, or forgo it, along with the rationale supporting that determination.
Deliver reminders on a recurring schedule that reinforces awareness between formal training events rather than relying solely on point-in-time training.
Tailor reminder topics to reinforce related specifications such as malware protection, login monitoring, and password management, and update them as your environment and threats evolve.
Extend reminders to the full workforce, and coordinate with business associate arrangements where relevant so that awareness expectations are addressed through the appropriate defined relationships.
Verify the current regulatory text and any applicable state law or HITECH provisions, since additional awareness or training requirements may apply beyond the baseline Security Rule expectation.