HIPAA privacy and security for healthcare workers

For clinical and non-clinical healthcare staff: protect patient information, honor patient rights and report problems fast.

For: Clinical and non-clinical staff in hospitals, clinics, long-term care and home health, including front desk, nursing, aides, therapy, billing, support services and volunteers

  • 2 contact hours
  • 8 modules
  • 9 interactives
  • 3 job aids
  • Updated October 11, 2026

What you will be able to do

  • Identify protected health information and the organizations and workforce members HIPAA covers.
  • Determine whether a use or disclosure is permitted, applying treatment, payment and operations, family involvement, public interest exceptions and minimum necessary.
  • Process patient requests for access, amendment, restrictions and confidential communications within federal timelines.
  • Apply workstation, password, device, email, texting and social media safeguards to everyday work.
  • Report a suspected breach promptly and accurately, and explain notification deadlines, sanctions and OCR enforcement.
  • Recognize when 42 CFR Part 2, stricter state laws or recent rule changes add to HIPAA's requirements.

Learn what the HIPAA Privacy, Security and Breach Notification Rules (45 CFR Parts 160 and 164) actually ask of you on a normal shift: what counts as protected health information, when you may share it, how to handle records requests, and how to keep screens, devices, texts and conversations safe. You will practice with a decision tree, a branching records-request scenario, two spot-the-problem exercises and an SBAR report to a privacy officer.

The course is written for everyone in the healthcare workforce, from the front desk and billing office to nurses, aides, therapists, home health staff, kitchen and housekeeping teams. No legal background is needed.

It goes beyond the usual annual slideshow. You get real HHS Office for Civil Rights enforcement cases, a dated status check on the 2024 reproductive health privacy rule and the 2024 Part 2 rule, notes on stricter state laws, and three job aids you can use the next day.

What you’ll be able to do Monday morning

  1. Run five quick checks (who, why, what, how, anything special) before you share any patient information.
  2. Take a records request correctly: no questions about why, date-stamped, routed the same day, right format and fee.
  3. Lock your screen, use only your own login and keep patient information off personal phones and social media.
  4. Report a misdirected fax, email or document to the privacy officer within the same shift, with facts.
  5. Recognize Part 2 and state-law situations and pause to ask before you disclose.

Curriculum

8 modules · 31 lessons · about 2 contact hours

01What does HIPAA protect, and who has to follow it?Free preview14 min
  1. Three rules under one law
  2. Who must follow HIPAA?
  3. What counts as protected health information?
  4. Back to the phone call
  • Sort activity: PHI or not PHI?

Diagram · In practice checklist · 2-question knowledge check

02When can you use or share a patient's information?15 min
  1. Treatment, payment and health care operations
  2. Family, friends and people involved in care
  3. Public health, safety and the law
  4. Incidental disclosures and everyday conversations
  • Decision tree: Can I share this?

Diagram · In practice checklist · 2-question knowledge check

03What rights do patients have over their own records?14 min
  1. The right of access
  2. Amendment and the other individual rights
  3. Handling a request at the front line
  • Branching scenario: The records request at the front desk

Diagram · In practice checklist · 2-question knowledge check

04How do you keep PHI safe at your workstation and on devices?15 min
  1. What the Security Rule asks of organizations
  2. Your login is your signature
  3. Workstations, printers, faxes and paper
  4. Phishing and other everyday threats
  • Spot the issue: Spot the security problems: nurses' station at 2 a.m.

Diagram · In practice checklist · 2-question knowledge check

05How should you handle email, texts, social media and conversations?14 min
  1. Email and texting
  2. Social media
  3. Photos, recordings and patients' own devices
  4. Conversations, phones and voicemail
  • Spot the issue: Spot the problems: staff email before it is sent

Diagram · In practice checklist · 2-question knowledge check

06What should you do when you suspect a privacy breach?15 min
  1. What counts as a breach?
  2. Report fast: what to say and to whom
  3. Who gets notified, and how fast?
  4. Sanctions and enforcement
  • SBAR builder: SBAR report to the privacy officer: misdirected fax
  • Branching scenario: Friday afternoon: the wrong discharge pages

Diagram · In practice checklist · 2-question knowledge check

07When do stricter state or federal rules apply on top of HIPAA?15 min
  1. HIPAA is the floor: preemption in plain words
  2. Substance use disorder records: 42 CFR Part 2
  3. Reproductive health privacy: a dated status check
  4. Putting layers together
  • Matching activity: Which rule adds protection?

Diagram · In practice checklist · 2-question knowledge check

08How do you build privacy into every shift?14 min
  1. Privacy habits by setting
  2. Common mistakes and how to avoid them
  3. Documenting privacy events
  4. Where to go for help
  • Self-assessment: How privacy-safe are my habits?

Diagram · In practice checklist · 3-question knowledge check

Final assessment: 23 questions, 80% to pass, then your certificate

Try it now, no account needed

The records request at the front desk

A branching scenario from this course. Your choices are not saved.

Free sample activity

The records request at the front desk

You work the front desk at a family practice. A patient, Mr. Ignatz Orbelian, asks for a copy of his records to take to a new cardiologist. He seems frustrated; he says he asked last month by phone and heard nothing.

Inside the course

Practice activities

  • Sort activity1
  • Decision tree1
  • Branching scenario2
  • Spot the issue2
  • SBAR builder1
  • Matching activity1
  • Self-assessment1

Job aids you keep

  • HIPAA Everyday Decisions Pocket CardPocket card
  • Suspected Privacy Incident Report WorksheetWorksheet
  • Workstation and Device Privacy ChecklistChecklist

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It is not approved or accredited by any licensing board, state agency or continuing education accreditor. HIPAA requires covered entities to train their workforce on their own privacy and security policies (45 CFR 164.530(b) and 164.308(a)(5)), so your employer decides whether this course is part of its required training; some states, such as Texas, add their own training rules. Check with your employer, privacy officer or licensing board whether this course meets your specific requirement.

Pathways we may pursue include review by continuing education approvers for nursing and allied health professions and arrangements with healthcare employers who use the course within their HIPAA training programs. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

Questions about this course

Does this course meet my employer's annual HIPAA training requirement?

HIPAA requires each covered entity to train its workforce on its own policies and procedures, so your employer decides what counts. Many employers use an outside course plus a short session on local policies. This course covers the federal rules in depth and gives you a certificate of completion for 2 contact hours. Check with your privacy officer or supervisor before relying on it.

Is this course approved for nursing or other continuing education credit?

No. The course awards a certificate of completion for 2 contact hours of instruction. It is not approved or accredited by any licensing board or accreditor. Some boards accept courses from providers they have not approved, and some do not, so check with your board before counting it.

I work in billing, dietary or housekeeping. Is this course for me?

Yes. HIPAA's workforce includes everyone whose work is under the organization's control, clinical or not. The examples cover front desk, billing, support services, home health and long-term care, as well as nursing and therapy, so you will see situations that match your job.

Does the course cover state privacy laws?

It explains how stricter state laws work alongside HIPAA and gives verified examples from Texas and California, plus state breach notification timelines. It is not a state edition, and some states add training or confidentiality rules. Your privacy officer can tell you which state laws apply where you work.

How long does it take, and what do I get at the end?

Plan on about two hours, including eight modules, interactive exercises and a 23-question final assessment drawn from a larger bank. You need 80 percent to pass. When you pass, you can download a certificate of completion showing the course title, date and 2 contact hours.

Is the 2024 reproductive health privacy rule covered?

Yes, as a dated status check. A federal court vacated most of that rule in June 2025, so its special prohibitions and attestation requirement are not in effect, while HIPAA's general protections still apply. The course explains what this means for staff and tells you where to check for updates.

This course is general education and training awareness from CE Courses Hub on HIPAA privacy and security. It is not legal, medical or professional advice and does not replace your employer's policies, your licensing board's rules, or advice from a qualified professional or your privacy officer. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.