Your Training
Training doesn’t have to be a course with a certificate. A short written description of what you do for each topic, reviewed on a schedule you pick, is all the rule asks of a solo or small practice.
Why this chapter exists, in plain English
The rule behind this chapter just says you need a security awareness and training plan for everyone who works with patient information. For a solo practice, that’s just you. For a two-person office, it’s both of you. The rule doesn’t care how big you are — it cares whether the people who can touch patient information know how to handle it.
It breaks into four plain topics: keeping yourself reminded, protecting your devices from harmful software, watching your sign-ins, and managing your passwords. We’ll walk through each one the same way — what it’s really asking for, the version that fits a solo or small practice, and what “written down” looks like if someone ever asks.
Two quick things to set expectations. The rule says training has to happen regularly but never says how often — so this chapter just asks you to pick a schedule and stick to it. And there’s no certificate or course to take — a short written description of what you do, reviewed on that schedule, is all you need to keep.
Setup
2 questionsHow often will you review your training?
HIPAA says to review regularly but leaves the timing up to you. We suggest once a year at the very least — that’s what the federal government has asked of practices that had a problem and had to fix it.
When did you last review your training?
If this is your first time through, picking today is the right answer — working through this chapter is a review.
The four topics
4 questionsSecurity reminders:
how staying current beats trying to stay expert
This topic is really just “stay in the loop” — the rule wants your awareness to be ongoing, not a one-time thing. For a solo or small practice, it comes down to three small habits: subscribe to the free federal HHS cybersecurity newsletter (the HHS Office for Civil Rights publishes it at hhs.gov/ocr), keep half an eye on the email scams aimed at healthcare (they change fast), and set a short repeating calendar reminder to check for updates on your work devices.
The bar here is low — staying current, not staying expert.
Sign in and we'll email a plain-language security check-in four times a year — what's worth a glance, what's changed, and what to do about it. Calm and clear, never scary. Plus a heads-up when your yearly review is due.
Sign in to subscribeProtection from malicious software:
the three habits that actually keep clinical devices clean
The built-in tools are the answer for almost every solo or small practice. Windows Security on Windows and XProtect on macOS are both on by default and enterprise-grade; paid third-party antivirus rarely improves on them at this scale.
The three habits that matter: keep the operating system current (install updates within a week of release), don’t click unexpected attachments or links in email — especially anything that urges action — and treat any antivirus alert as an incident to write up, not a notification to dismiss. A confirmed malware event goes straight to the “If Something Goes Wrong” chapter and the ransomware scenario there.
Log-in monitoring:
a recurring check on the accounts that touch patient information
For a solo practice this means keeping an eye on your own sign-ins; in a small office, on those of everyone who works with you. Pick a repeating time — first Monday of the month is a common choice — and check the sign-in activity on the three or four accounts that handle patient information. In practice that’s usually:
- Your email (Gmail: myaccount.google.com → Security → Recent security events; Microsoft: account.microsoft.com → Sign-in activity).
- Your EHR audit log — most EHRs surface this under admin or user settings.
- Your cloud storage (Drive, OneDrive, Dropbox) recent activity.
- Your password manager’s activity log if it has one.
What you’re looking for: unfamiliar locations, devices you don’t recognize, failed login attempts in bursts. Any of those is treated as a possible account compromise — see the account-compromise scenario in the “If Something Goes Wrong” chapter.
Password management:
confirming you're following the procedures from Chapter 3
Password management is covered in depth in Chapter 3, “Your Passwords.” The training-rule question here is narrower: confirm you’re following the password procedures you set up there.
The short version: a password manager making and storing a different password for every account that touches patient information, a second step at login turned on wherever the account offers it, and no reusing the same password across accounts. If any of those are in doubt, work back through Chapter 3 before checking this box.
For your insurer (optional)
Optional, and not required to finish this chapter. Some insurance companies (Hiscox especially) ask whether security training is required at least once a year. Your answer pre-fills the training row of the summary you can hand your insurance company.
Carriers ask thisIs annual security-awareness training a standing requirement at your practice?
Where you stand
Not quite there yet
Answer the remaining 6 questions above to see where you stand.