Compliance & HR
Managing Remote and Hybrid Teams
For: Managers & supervisors
By profession
For employees who handle personal data and the supervisors who lead them: prevent breaches, report fast, and understand US notification duties under state laws, HIPAA, the FTC Safeguards Rule and SEC rules.
For: All employees who handle customer, patient or employee personal data, plus supervisors and managers who receive incident reports, in businesses, health care organizations, financial services, nonprofits and public companies.
Most data breaches start with an ordinary moment: an autocompleted email address, a laptop left in a car, a password typed into a fake page. This course shows you how breaches happen, the everyday controls that prevent them, how to recognize a possible breach, and exactly what to do in the first hour: report, preserve evidence and let the response team lead.
It then explains the US notification landscape in practical terms: state breach laws (definitions, deadlines, attorney general notice, encryption safe harbors) with verified examples, the HIPAA Breach Notification Rule, the FTC Safeguards Rule's 30-day notice to the FTC for events involving 500 or more consumers, and SEC Form 8-K disclosure for public companies. It finishes with containment, breach logs and blameless lessons-learned reviews.
Scenarios from a Texas auto dealership, a Michigan pediatric therapy clinic, a Florida staffing agency and a Nebraska public company make the rules concrete. You will practice with a decision tool, a state look-up, spot-the-problem exercises, a manager's dilemma and a full branching scenario, and leave with a checklist, a policy starter, a tabletop worksheet and a state quick reference.
What you’ll be able to do Monday morning
7 modules · 28 lessons · about 2 contact hours
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Try it now, no account needed
A branching scenario from this course. Your choices are not saved.
Practice activities
Job aids you keep
This course awards a certificate of completion for 2 contact hours of instruction. It is not currently approved or accredited by any continuing education accreditor, professional association or state agency, and it does not provide CPE for accountants or privacy certification credit. Employers decide whether to accept it for internal training requirements. It is general awareness training and does not replace your organization's incident response plan or legal advice.
Pathways we may pursue include IACET-aligned continuing education units and NASBA-registered CPE, if approval is obtained. None of these approvals exists today; the course page will show an approval only after it is granted.
Our full approvals listState notes
Every state, the District of Columbia, Puerto Rico and the Virgin Islands has a breach notification law, and the law of each affected person's state generally applies. The laws differ in:
What to check locally: your organization's incident response plan, which states your customers and employees live in, and current statutes, which counsel should confirm before any notice.
No. It awards a certificate of completion for 2 contact hours. It is not approved by NASBA, IAPP, IACET or any state agency. Your employer decides whether it meets internal training requirements. If you need CPE or certification credit, check with the credentialing body before relying on this course.
No. It explains how the major laws work so you understand the process and act quickly. Whether a specific incident requires notice under state law, HIPAA, the FTC Safeguards Rule or SEC rules is a legal decision for your privacy officer and counsel.
Any employee who handles customer, patient or employee personal data, including sales, finance, HR, payroll, customer service, billing and IT staff, and supervisors who receive incident reports. It is especially relevant in health care, auto sales and lending, staffing and public companies.
It explains how state laws work and gives verified details for 14 jurisdictions in a look-up tool and quick reference: AL, AZ, CA, CO, CT, DC, DE, FL, HI, ID, IL, ME, NY and VA. Every state has a law; for others, check your state attorney general's site and ask counsel.
Plan on about 2 hours for seven modules with interactive exercises, then a final assessment of 23 questions drawn from a larger bank. You need 75% to pass, and you receive a certificate of completion showing 2 contact hours.
It was checked against official sources in October 2026, including California's SB 446 30-day rule effective January 1, 2026, and the FTC Safeguards Rule notice duty effective May 13, 2024. Breach laws change often; the course is reviewed at least every 12 months and after major changes.
This course is general education and training awareness from CE Courses Hub on data breach prevention and US notification laws. It is not legal or professional advice and does not replace your employer's policies or incident response plan, your licensing board's rules, or advice from a qualified attorney or security professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.