Skip to main content

HR & Compliance, 15 minutes, self-paced

HIPAA

Comply with HIPAA privacy and security requirements

Back to the library

Part of the compliance library: free for every employee at any company size.

Who it is for

Employees at covered entities and business associates who touch health information, such as healthcare, benefits administration, and some HR functions. Relevant to anyone who handles employee health or medical records.

What you will learn

  • Distinguish protected health information from ordinary information and know when HIPAA applies
  • Apply the minimum-necessary principle when accessing, using, or sharing health data
  • Follow safeguards for storing, transmitting, and discussing PHI, including verbal disclosures
  • Respond to a suspected privacy or security incident through the correct reporting channel

What changes on the job

  • Fewer casual disclosures of health information in hallways, emails, or shared systems
  • Staff who apply minimum-necessary access instead of browsing records freely
  • Faster, correct incident reporting when a privacy lapse occurs

This course is one part of the mix. The same topic runs as a live workshop where a facilitator who has held the role watches you practice, and Coach Taylor follows up afterward.

Talk to ARIA

Ask what you would ask us.

ARIA works the way a good first call works. She asks who is involved and what should change, recommends the closest starting point, quotes the real price, and hands you to a person when you want one.

Start with one of these

Prefer a person? Say so in the conversation and the team follows up, or use the contact page.

Questions

Questions about this course.

Does HIPAA apply to my company if we are not a hospital?

HIPAA applies to covered entities and their business associates. Many non-healthcare employers still encounter PHI through benefits and leave administration. The course helps you tell when the rules are in play.

Is this a technical security course?

No. It focuses on the everyday privacy habits that prevent most violations, such as how you talk about, store, and share health information, rather than IT security configuration.