Skip to main content
Category: Administrative Safeguards

Security Awareness Training

Also known as: SAT, Security Awareness and Training, Cybersecurity Awareness Training, Security Awareness Program
Simply put

Security awareness training is an ongoing educational program that teaches an organization's workforce how to understand, identify, avoid, and report cyber threats such as phishing, ransomware, and social engineering. Its general goal is to help employees protect the organization's data and sensitive information from attack. Training is typically delivered on a recurring basis rather than as a one-time event.

Formal definition

Security awareness training is a workforce education program covering topics that commonly include secure communication, data classification, phishing, physical security, social engineering, and data privacy, intended to equip personnel to identify, avoid, and report security threats. Under the HIPAA Security Rule, a security awareness and training program is an administrative safeguard standard applicable to covered entities and business associates handling electronic protected health information (ePHI); the associated implementation specifications (such as security reminders, protection from malicious software, log-in monitoring, and password management) are generally designated as addressable, meaning an organization must assess whether each specification is reasonable and appropriate for its environment and implement it or document an equivalent alternative rather than treating it as optional. Note that the specific evidence provided here describes general commercial and government security awareness training and does not itself detail HIPAA regulatory requirements; readers should verify current obligations against the applicable Security Rule text at 45 CFR Part 164. Training content, frequency, and documentation requirements may also be shaped by state law, the HITECH Act, or frameworks such as the HITRUST CSF, which impose requirements beyond HIPAA.

Why it matters

The human workforce is consistently one of the most targeted vectors in healthcare security incidents. Attacks such as phishing, ransomware, and social engineering are engineered to exploit individual behavior rather than technical controls alone, which means that even robust technical safeguards can be undermined by a single misdirected click or disclosed credential. Security awareness training addresses this gap by educating personnel to understand, identify, avoid, and report cyber threats before they result in unauthorized access to sensitive information.

For organizations subject to HIPAA, a security awareness and training program is not merely a best practice but an administrative safeguard standard under the Security Rule, applicable to covered entities and business associates that handle electronic protected health information (ePHI). Several of its associated implementation specifications, such as security reminders, protection from malicious software, log-in monitoring, and password management, are generally designated as addressable, which is often misunderstood as optional. In practice, addressable means an organization must assess whether each specification is reasonable and appropriate for its environment and then implement it or document an equivalent alternative and the rationale for doing so.

Because training is generally an ongoing program rather than a one-time event, its value depends on sustained reinforcement, current content, and documentation that can demonstrate the program's operation over time. Readers should note that the general commercial and government training examples cited here do not by themselves establish HIPAA compliance, and that state law, the HITECH Act, and frameworks such as the HITRUST CSF may impose additional requirements beyond the Security Rule. Specific obligations should be verified against the current Security Rule text at 45 CFR Part 164.

Who it's relevant to

Security Officers
Security officers are typically responsible for establishing, delivering, and maintaining a security awareness and training program as part of the HIPAA Security Rule's administrative safeguards. They generally decide which addressable implementation specifications are reasonable and appropriate for the organization's environment, implement them or document equivalent alternatives, and ensure content addresses current threats such as phishing, ransomware, and social engineering.
Privacy Officers
While the Security Rule focuses on ePHI, privacy officers have an interest in ensuring workforce education reinforces appropriate handling of protected health information across all forms. Data privacy is a common training topic, and coordinating awareness content with privacy policies helps promote a consistent understanding of both security and privacy obligations among the workforce.
Compliance Officers and Auditors
Compliance officers and auditors evaluate whether a security awareness program exists, operates on a recurring basis, and is documented in a way that can demonstrate its application to the workforce. They should verify current training obligations against the applicable Security Rule text at 45 CFR Part 164, and account for any additional requirements imposed by state law, the HITECH Act, or the HITRUST CSF, which may exceed HIPAA's baseline.
Business Associates and Subcontractors
Business associates handling ePHI are subject to the Security Rule's administrative safeguard standards, including security awareness and training. Their specific training obligations are generally shaped by the business associate agreement and their own compliance program, and subcontractors may inherit comparable obligations through downstream agreements. HITRUST CSF certification, where required contractually, does not by itself establish HIPAA compliance.
Workforce Members
General workforce members are the primary audience for the training. Recurring programs are intended to help them identify, avoid, and report threats such as phishing, ransomware, and social engineering, and to apply practices around secure communication, data classification, physical security, and data privacy in their daily work.

Inside SAT

Security Reminders
Periodic communications that reinforce security-conscious behavior among workforce members, such as updates on emerging threats, policy changes, and reminders about safe handling of ePHI. Under the HIPAA Security Rule, security reminders are an addressable implementation specification within the administrative safeguards, meaning covered entities and business associates must assess whether the specification is reasonable and appropriate and implement it or document why not and adopt an equivalent measure.
Protection from Malicious Software
Training on procedures for guarding against, detecting, and reporting malicious software. This is an addressable implementation specification supporting the workforce's ability to recognize and respond to threats that could compromise ePHI.
Log-in Monitoring
Training on procedures for monitoring log-in attempts and reporting discrepancies, such as repeated failed access attempts. This is an addressable implementation specification intended to help workforce members recognize potential unauthorized access.
Password Management
Training on procedures for creating, changing, and safeguarding passwords. This is an addressable implementation specification that supports proper authentication practices for systems containing ePHI.
Workforce Scope
Security awareness training under the Security Rule is directed at all members of the workforce, including management, and applies to the electronic protected health information (ePHI) environment. Because it is a Security Rule requirement, its scope is limited to ePHI rather than PHI in all forms.
Ongoing Nature
Security awareness and training is generally treated as an ongoing program rather than a one-time event, supporting sustained awareness as threats, systems, and policies evolve over time.

Common questions

Answers to the questions practitioners most commonly ask about SAT.

Is security awareness training an optional or 'nice-to-have' safeguard under the HIPAA Security Rule?
No. Security awareness and training is a required standard under the administrative safeguards of the HIPAA Security Rule, and covered entities and business associates must implement a program for all workforce members, including management. It is worth noting that the standard itself is required, though some of its associated implementation specifications are categorized as addressable. Addressable does not mean optional; it means the organization must assess whether the specification is reasonable and appropriate for its environment and, if not, document why and implement an equivalent alternative where appropriate. Readers should verify the current regulatory text for the specific categorization of each implementation specification.
Does completing security awareness training make an organization HIPAA compliant or guarantee it will avoid breaches?
No. Training is one component of a broader compliance program and does not by itself establish HIPAA compliance. The Security Rule requires a range of administrative, physical, and technical safeguards, and training addresses only part of the administrative safeguard requirements. No single measure, including training, can guarantee compliance or prevent all breaches. Training generally reduces the likelihood of certain human-error incidents, but organizations should treat it as complementary to risk analysis, policies, technical controls, and other required safeguards.
How often should security awareness training be conducted?
The HIPAA Security Rule requires security awareness and training but does not, in the regulatory text, prescribe a rigid frequency such as annually. In most cases, organizations provide training to new workforce members upon hire and then conduct periodic refresher training, with many opting for at least annual sessions as a common practice. Additional or ad hoc training is generally advisable when there are material changes to systems, policies, threats, or roles. Frequency should be informed by the organization's risk analysis. Note that state law or other frameworks may impose more specific timing requirements.
Who within an organization must receive security awareness training?
The requirement generally applies to all members of the workforce, which typically includes employees, and may include volunteers, trainees, and others whose conduct is under the direct control of the entity, regardless of whether they are paid. Management should be included as well. The scope applies to both covered entities and business associates. Organizations should confirm the definition of workforce in the current regulatory text and consider whether contractors and similar personnel fall within that definition or are instead addressed through business associate agreements or other contractual arrangements.
What topics should a security awareness training program typically cover?
The Security Rule identifies several addressable implementation specifications associated with the training standard, which generally relate to areas such as periodic security reminders, protection from malicious software, log-in monitoring, and password management. Because these are addressable, the specific content and emphasis should be tailored to the organization's risk analysis and environment, with documentation of the rationale where a specification is addressed through an alternative approach. Readers should verify the exact implementation specifications and their categorization against the current regulatory text.
How should an organization document its security awareness training to support its compliance posture?
While the specifics are left to each organization, maintaining records that demonstrate training was provided is generally advisable to support the organization's compliance posture and to be able to respond to inquiries, including from HHS OCR. Documentation commonly includes items such as training materials, dates, and evidence of workforce participation, along with the risk-based rationale for how addressable specifications were handled. Organizations should align retention of this documentation with applicable Security Rule documentation retention requirements and confirm current expectations against the regulatory text and current guidance.

Common misconceptions

Because the log-in monitoring, password management, malicious software, and security reminder specifications are labeled 'addressable,' they are optional and can be skipped.
Addressable does not mean optional. For each addressable implementation specification, a covered entity or business associate must assess whether it is a reasonable and appropriate safeguard in its environment, and then either implement it, implement an equivalent alternative measure, or document the rationale for not implementing it. This assessment and documentation are expected practice under the Security Rule.
Completing security awareness training establishes overall HIPAA compliance or guarantees that breaches will not occur.
Training is one administrative safeguard within a broader compliance program and does not by itself establish HIPAA compliance or guarantee prevention of all incidents. It must operate alongside other administrative, physical, and technical safeguards, and no single measure can be said to guarantee compliance or prevent all breaches.
Security awareness training covers all protected health information regardless of form.
The security awareness and training standard sits within the HIPAA Security Rule, which governs only electronic protected health information (ePHI). Privacy-related workforce training obligations concerning PHI in oral, paper, and other forms arise separately under the Privacy Rule.

Best practices

Deliver security awareness training to all workforce members, including management, rather than limiting it to IT or security staff.
Treat training as an ongoing program with periodic security reminders rather than a single onboarding event, updating content as threats, systems, and policies change.
For each addressable specification (security reminders, protection from malicious software, log-in monitoring, and password management), document your reasonable-and-appropriate assessment and either implement the specification, adopt an equivalent alternative, or record your rationale for not implementing it.
Include practical content on recognizing and reporting malicious software, monitoring and reporting log-in discrepancies, and creating and safeguarding passwords.
Maintain records of training completion and the content delivered to support your ability to demonstrate the safeguard during an HHS OCR inquiry or internal review.
Coordinate Security Rule training with separate Privacy Rule workforce training, and verify whether state law, the HITECH Act, or a chosen framework such as the HITRUST CSF imposes additional training expectations, confirming specifics against current regulatory text and the current framework version.