Skip to main content
Category: Governance and Workforce

Security Awareness and Training

Also known as: SAT, Security Awareness Training, Security Education, Training and Awareness, SETA
Simply put

Security awareness and training is an ongoing program that educates a workforce to understand, identify, avoid, and report cyber threats such as phishing and ransomware, and to properly handle sensitive information. It typically covers cybersecurity fundamentals, strong passwords, and everyday best practices. The goal is to reduce the likelihood that human error leads to a security incident, though no training program can guarantee that all threats are prevented.

Formal definition

Under the HIPAA Security Rule, a security awareness and training program is an administrative safeguard requiring a covered entity or business associate to implement a training program for all members of its workforce, including management. The associated implementation specifications are generally categorized as addressable and typically include security reminders, protection from malicious software, log-in monitoring, and password management; note that 'addressable' does not mean optional, but rather that the entity must assess whether each specification is reasonable and appropriate for its environment and document its decision. In practice, such programs cover cybersecurity fundamentals, strong password practices, recognizing and reporting threats such as phishing and ransomware, and proper handling of sensitive information, and are commonly delivered on an ongoing or annual basis. Readers should confirm the current Security Rule text and implementation specifications against the applicable CFR provisions, and should note that the HITECH Act, state law, and frameworks such as the HITRUST CSF may impose additional training-related requirements beyond HIPAA; HITRUST certification does not by itself establish HIPAA compliance.

Why it matters

The workforce is often the point where security controls succeed or fail. Many security incidents begin with human actions such as clicking a phishing link, mishandling sensitive information, or using weak credentials, and technical safeguards alone cannot fully compensate for these behaviors. Security awareness and training addresses this human dimension by educating workforce members to understand, identify, avoid, and report cyber threats such as phishing and ransomware. It should be understood as a risk-reduction measure rather than a guarantee; no training program can ensure that every threat is prevented.

Under the HIPAA Security Rule, security awareness and training is an administrative safeguard that applies to all members of the workforce, including management. Its implementation specifications are generally categorized as addressable, but addressable does not mean optional. A covered entity or business associate must assess whether each specification is reasonable and appropriate for its environment and document that decision. Failing to establish and document a training program can therefore expose an organization to compliance gaps, and enforcement of the Security Rule falls to HHS OCR.

Beyond HIPAA, additional training-related requirements may arise from the HITECH Act, state law, or frameworks such as the HITRUST CSF. Organizations pursuing HITRUST certification should note that certification does not by itself establish HIPAA compliance. Readers should confirm current obligations against the applicable CFR provisions and the current version of any framework they rely on, rather than assuming that satisfying one framework satisfies all others.

Who it's relevant to

Security Officers
Security officers are typically responsible for establishing, delivering, and maintaining the security awareness and training program as an administrative safeguard. They generally must assess which addressable implementation specifications are reasonable and appropriate for their environment, document those decisions, and ensure training reaches all workforce members including management.
Privacy Officers
Privacy officers have an interest in ensuring workforce members properly handle sensitive information across all forms, not only electronic. While the Security Rule's training safeguard focuses on ePHI, privacy training obligations under the HIPAA Privacy Rule address PHI more broadly, and coordination helps avoid gaps between the two programs.
Compliance and Audit Professionals
Compliance and audit staff use documentation of the training program, including records of decisions on addressable specifications and evidence of workforce completion, to demonstrate adherence during internal reviews or in response to HHS OCR inquiries. They should also account for additional training requirements that may arise from the HITECH Act, state law, or frameworks such as the HITRUST CSF.
Business Associates and Subcontractors
Business associates and their subcontractors that create, receive, maintain, or transmit ePHI are generally subject to the Security Rule's training requirements. Specific obligations often flow through business associate agreements, so these organizations should confirm both their direct Security Rule duties and any contractual training commitments.
Workforce Members and Management
The training program applies to all members of the workforce, including management. These individuals are the intended audience and are expected to learn to identify, avoid, and report threats such as phishing and ransomware and to handle sensitive information properly, since their everyday actions materially affect the organization's risk of a security incident.

Inside SAT

Standard Under Administrative Safeguards
Security Awareness and Training is a standard within the administrative safeguards category of the HIPAA Security Rule, applicable to workforce members who may access electronic protected health information (ePHI). Because it is part of the Security Rule, its scope is generally limited to ePHI rather than PHI in all forms.
Security Reminders
An addressable implementation specification calling for periodic reminders to the workforce about security practices. Addressable does not mean optional; a covered entity or business associate must generally either implement the specification, adopt an equivalent alternative, or document why it is not reasonable and appropriate.
Protection from Malicious Software
An addressable implementation specification addressing procedures for guarding against, detecting, and reporting malicious software. As with other addressable items, the decision and rationale should generally be documented.
Log-in Monitoring
An addressable implementation specification addressing procedures for monitoring log-in attempts and reporting discrepancies to help identify potential unauthorized access to systems containing ePHI.
Password Management
An addressable implementation specification addressing procedures for creating, changing, and safeguarding passwords. Being addressable, it must be evaluated for reasonableness and appropriateness rather than simply ignored.
Workforce Scope
The standard applies to all members of the workforce, which typically includes management and, as appropriate, others who have access to ePHI. Obligations attach through the entity's status as a covered entity or business associate rather than to every unrelated third party.

Common questions

Answers to the questions practitioners most commonly ask about SAT.

Is security awareness and training an optional or addressable implementation specification under the HIPAA Security Rule?
Security Awareness and Training is a required standard under the administrative safeguards of the HIPAA Security Rule. Covered entities and business associates must implement a security awareness and training program for all members of their workforce, including management. While the standard itself is required, it contains several implementation specifications (such as security reminders, protection from malicious software, log-in monitoring, and password management) that are classified as addressable. It is important to note that addressable does not mean optional; an addressable specification must be implemented if reasonable and appropriate, or, where it is not, the entity must document why and implement an equivalent alternative measure where reasonable and appropriate. Readers should verify the current regulatory text for the precise classification of each specification.
Does completing security awareness training guarantee HIPAA compliance or prevent breaches?
No. Training is one required component of the administrative safeguards, but no single measure guarantees HIPAA compliance or prevents all breaches. A training program supports compliance by helping the workforce recognize and respond to security risks, but it operates alongside the full set of administrative, physical, and technical safeguards, risk analysis and risk management processes, and Privacy Rule obligations. Treating training as a checkbox that establishes overall compliance is a common misconception. Effectiveness generally depends on whether the training is current, tailored to actual risks, and reinforced over time, and compliance is assessed against the entity's broader safeguard implementation.
How often should security awareness and training be provided to the workforce?
The HIPAA Security Rule requires training but does not, in most cases, prescribe a specific frequency or fixed schedule. Many organizations typically provide training at onboarding for new workforce members and conduct periodic refresher training thereafter, often on a recurring basis, supplemented by ongoing security reminders. The appropriate frequency generally depends on the entity's risk analysis, changes in threats, and operational or regulatory developments. Entities should document their chosen approach and confirm expectations against current HHS OCR guidance, and be aware that state law or other frameworks may impose additional requirements.
Which members of the workforce must receive security awareness and training?
The standard applies to all members of the workforce, including management. In this context, workforce generally refers to employees, volunteers, trainees, and other persons whose conduct is under the direct control of the entity, whether or not they are paid. Because the requirement extends to management, leadership is not exempt. Business associates and subcontractors have their own obligations to train their respective workforces; those obligations attach through their defined relationships and applicable business associate agreements rather than through the covered entity training the vendor's staff directly.
How can an organization document and demonstrate its training program during an audit?
Organizations typically maintain records that show the content of the training, the dates it was delivered, and which workforce members completed it. Documentation of the reasoning behind addressable implementation specifications, such as security reminders, protection from malicious software, log-in monitoring, and password management, is also generally advisable, including any decisions to implement alternative measures. The HIPAA Security Rule generally requires that documentation be retained and made available, and entities should confirm current retention periods and documentation expectations against the applicable regulatory text and current HHS OCR guidance.
How does a HIPAA training program relate to training expected under the HITRUST CSF?
A HIPAA security awareness and training program addresses a required standard enforced by HHS OCR. The HITRUST CSF, a certifiable control framework maintained by the private organization HITRUST, includes its own controls addressing awareness and training that may map to and expand upon HIPAA expectations. However, HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance. An organization pursuing HITRUST certification should still ensure its training program independently satisfies the HIPAA Security Rule, and should verify specific control requirements against the current HITRUST CSF version.

Common misconceptions

Addressable implementation specifications such as security reminders or password management are optional and can be skipped.
Addressable does not mean optional. A regulated entity must generally implement the specification, implement a reasonable and appropriate equivalent measure, or document why the specification is not reasonable and appropriate for its environment.
Completing a training program by itself establishes HIPAA compliance or guarantees breaches will be prevented.
Training is one required standard among many within the administrative safeguards and does not by itself demonstrate overall compliance or prevent all incidents. Compliance depends on the broader set of administrative, physical, and technical safeguards, and no single measure guarantees compliance.
Security awareness training only needs to cover electronic data and is the same as broader Privacy Rule training.
This training standard sits in the Security Rule and generally focuses on safeguarding ePHI. Separate Privacy Rule training obligations may apply to PHI in all forms, including oral and paper, so entities should not treat the two as interchangeable.

Best practices

Provide security awareness training to all workforce members who may access ePHI, and extend it appropriately to management and others with such access.
For each addressable specification (security reminders, malicious software protection, log-in monitoring, password management), document the decision to implement it, adopt an equivalent measure, or explain why it is not reasonable and appropriate.
Deliver periodic security reminders rather than treating training as a one-time event, so awareness is reinforced over time.
Coordinate Security Rule awareness training with any separate Privacy Rule training obligations to avoid gaps between ePHI-focused and broader PHI-focused content.
Retain documentation of training activities and related decisions to support demonstrating that the standard has been addressed.
Verify current regulatory text and, where applicable, state law or HITECH-related requirements that may impose obligations beyond this HIPAA standard, since training expectations can change over time.