Workforce training scope planner

Who needs HIPAA training?

Not everyone who walks through your door, and not only the people on your payroll. HIPAA answers this with a definition, and the definition ends with the words whether or not they are paid. Enter your roster below and this free planner sorts every category into four answers: train them, decide and document, sign an agreement instead, or do nothing. Each line shows the paragraph or the HHS guidance it came from.

14worker categories sorted
4answers HIPAA actually gives
0data leaves your browser

The planner

Count the people you actually have, not the ones on the org chart

Enter a headcount for every row that applies. The panel builds your seat count, separates the vendors who need an agreement, and names the deadline and the record you have to be able to produce later.
1Which are you in the chain?

The training standards differ, and so does what a customer or a regulator will ask you to produce.

45 CFR 160.103; 164.104
2Count the people and the vendors

Enter a headcount for every row that describes someone in your organization. Leave a row at zero if it does not apply. The last three rows count companies rather than people, because those relationships need an agreement instead of a seat.

45 CFR 160.103, workforce and business associate
people
people
people
people
people
people
people
people
people
people
people
vendors
vendors
vendors
3Does Texas law reach you?

Texas sets its own training deadline and its own proof requirement on top of HIPAA, and its definition of covered entity is broader than the federal one.

Texas Health and Safety Code 181.101

This planner applies the workforce and business associate definitions at 45 CFR 160.103, the training standards at 164.530(b) and 164.308(a)(5), the workforce security standard at 164.308(a)(3), the disclosure condition at 164.502(e), published HHS guidance on business associates and incidental contact, and Texas Health and Safety Code 181.101 where you say it applies. It runs entirely in your browser, stores nothing, and sends nothing anywhere. It reports which obligations a described roster triggers. It does not determine that an organization is compliant, it is not legal advice, and it is not a government determination. Completing training proves that named people were trained on a date. Organizational compliance is a separate and larger question. State laws beyond Texas, union agreements, and accreditation standards can each add requirements this planner does not model, and unusual arrangements deserve review by qualified counsel.

What it sorts

Six things the roster makes clear

The planner applies the definitions and standards in 45 CFR parts 160 and 164 and published HHS guidance. It reports which obligations a described roster triggers. It is not a compliance determination and it is not legal advice.

The test

Direct control, not payroll

The workforce definition ends with the words whether or not they are paid. That single phrase pulls volunteers, students, residents, and agency staff inside your training obligation, and it is the phrase most rosters are built without reading.

Most missed

The people nobody counted

Volunteers at the front desk, nursing students on rotation, the travel nurse covering nights, the developer with production database access, and the executive who approved the vendor. Every one of them is a workforce member.

Most overbought

The seats you do not owe

A business associate is expressly not a member of your workforce. Your outsourced billing company, your shredding vendor, and your EHR host each need a signed agreement from you and training from their own employer.

The gray zone

The three calls that are genuinely yours

An embedded vendor engineer, a board that reviews individual cases, and a credentialed physician you do not employ. HHS guidance leaves each of these to you, which means the deliverable is a written determination.

The clock

When the training has to have happened

Federal law says within a reasonable period after joining, which is a standard rather than a date. Texas writes a number into statute: 90 days from hire. Both are easier to satisfy than to reconstruct afterward.

The evidence

What you produce three years later

Documentation that training was provided, kept for six years from creation or last effective date. A completion record with a name and a date is the artifact. A memory of a staff meeting is not.

The answer is a definition, and it is one sentence long

Almost every argument about who needs HIPAA training is really an argument about a sentence nobody at the table has read. 45 CFR 160.103 defines workforce as employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid by the covered entity or business associate.

Read the last clause again, because it is doing all the work. Payment is not the test. Employment is not the test. Direct control over conduct is the test. That is why a volunteer who works Tuesday mornings at the front desk is inside your training obligation and a billing company that processes ten thousand of your claims a month is not.

Once that sentence is settled, two more attach to it. 45 CFR 164.530(b)(1) requires a covered entity to train all members of its workforce on the policies and procedures with respect to protected health information, as necessary and appropriate for the members of the workforce to carry out their functions. And 45 CFR 164.308(a)(5)(i) requires a security awareness and training program for all members of the workforce, including management, in those exact words. The Privacy Rule standard scales the depth of training to the role. Neither standard makes the training optional for anyone inside the definition.

The four answers, and why organizations mix up two of them

Sort any person or company connected to your organization and you land on one of four outcomes. They are a workforce member, in which case you train them. They are a business associate, in which case you sign an agreement and they train their own people. They are neither, because any exposure is incidental to work that has nothing to do with patient information. Or they are a judgment call that the rules deliberately leave to you, in which case the deliverable is a written determination.

The two that get mixed up are the first two, and the error runs in both directions at once. Organizations forget volunteers and students, who are named in the definition, while buying seats for an outsourced billing company that is expressly excluded from it. The definition of business associate at 160.103 says, in its own words, that a business associate is a person other than a member of the workforce of a covered entity. The two categories are mutually exclusive by construction. If someone is your workforce, they are not your business associate, and if a company is your business associate, its staff are not your seats.

The people who get missed

In roughly this order of frequency, here is who falls off a training roster built from a payroll report.

Volunteers. Named in the definition. Often placed at reception, in waiting areas, or escorting patients, which is to say at precisely the points where conversations are overheard and screens are visible. The training can be short. It cannot be absent.

Students, interns, and residents. Trainees are named in the definition too. A school having its own privacy curriculum does not remove someone from your workforce while they are working under your supervision. Rotations also create a specific access problem: credentials get provisioned quickly at the start and revoked slowly at the end, which is the pattern 164.308(a)(3)(ii)(C) is written against.

Agency and temporary staff. Locum clinicians, travel nurses, and seasonal front desk cover work under your direction using your systems. Direct control is satisfied. A short assignment is an argument for training sooner, not for skipping it, because a person who will be gone in six weeks is a person whose mistakes you will be explaining without them.

Your own technical staff. System administrators, developers, and analysts hold the broadest access in most organizations and frequently assume HIPAA training is a clinical exercise. They are workforce members, and the access controls, audit controls, and integrity safeguards your risk analysis depends on are built by them.

Leadership. The security awareness standard says including management because the drafters anticipated the exemption executives grant themselves. Leadership also approves vendors, signs agreements, and answers regulators, so an untrained executive is not a symbolic gap.

Non-clinical employed staff. Housekeeping, transport, food service, and maintenance on your own payroll are workforce members even though their work is not about patient information. The Privacy Rule sets the depth here, not the fact: a brief awareness module on what to do when you see a chart, hear a name, or find paper in a bin is usually appropriate to the function.

The seats you do not owe anyone

A business associate is a person or company that, on behalf of a covered entity, creates, receives, maintains, or transmits protected health information for a regulated function, or that provides legal, actuarial, accounting, consulting, or financial services where the service involves disclosure of PHI. Under 45 CFR 164.502(e)(1)(i) a covered entity may disclose protected health information to a business associate only if it first obtains satisfactory assurances, in the form of a written contract, that the business associate will appropriately safeguard the information. That contract, not a training seat, is what you owe them. The word first is worth noticing.

Your outsourced billing company, your remote transcription provider, your shredding vendor, your release of information service, your EHR host, your managed IT provider, and the lawyer who reviews a patient complaint file are all business associates. Each one is responsible for training its own workforce, and each one is directly liable under the Security Rule. Buying them seats is not a compliance measure. It is a purchase that does nothing your agreement does not already require of them.

There is a floor beneath that. HHS addresses it in guidance about janitorial services: a business associate contract is not required with persons or organizations whose functions, activities, or services do not involve the use or disclosure of protected health information and where any access to PHI would be incidental, if at all. A cleaning crew, a plumber, and a landscaper generally sit here. No seat and no agreement. HHS is equally clear about where that ends. A service hired to routinely handle records or shred documents containing PHI likely is a business associate, and the same vendor can cross that line when someone quietly adds the shred bins to the cleaning contract.

The three calls that are genuinely yours to make

Some categories are not resolved by reading the rule harder, because HHS has left them to the organization. There are three worth naming, and for each one the output is a documented determination rather than a lookup.

Embedded contractor staff. HHS states that when an employee of a contractor, like a software or information technology vendor, has a primary duty station on site at a covered entity, the covered entity may choose to treat the employee of the vendor as a member of the covered entity's workforce rather than as a business associate. May choose. Both routes are available, and they lead to different paperwork: a seat and a training record on one path, a business associate agreement on the other. Pick deliberately, apply it consistently across similar arrangements, and write it down.

Board members and directors. The same direct control test applies, and the practical question is whether the role involves protected health information at all. A governing body that reviews aggregate financial and quality data sits outside it. A board or committee that reviews individual grievances, credentialing files, or case detail is performing work for you using PHI, and the sensible answer is to train them.

Credentialed physicians you do not employ. HHS guidance says a hospital and the physicians with privileges there participate in an organized health care arrangement, and those physicians do not have to enter into business associate contracts with the hospital. They are generally neither workforce nor business associates, and their own practice is the covered entity responsible for training them. Requiring orientation on facility policies as a condition of privileges remains a perfectly reasonable governance choice, and it is worth being clear internally that it is a facility rule rather than a federal one.

When it has to happen

45 CFR 164.530(b)(2)(i)(B) requires training for each new member of the workforce within a reasonable period of time after the person joins the workforce. There is no number, and organizations tend to read the absence of a number as latitude. It is better read as a question you will have to answer with your own facts: on the day this person was given access to charts, what had they been trained on. Putting training ahead of provisioning in the onboarding sequence answers it permanently.

164.530(b)(2)(i)(C) adds the second trigger. When you materially change a policy or procedure, each workforce member whose functions are affected must be trained within a reasonable period of time after the change takes effect. New telehealth workflows, a new EHR, a new policy on which AI tools may receive patient information, and a rewritten release of information procedure all qualify, and this is the trigger most often missed because it does not arrive with a new hire form attached.

On the security side, periodic security updates are an implementation specification at 164.308(a)(5)(ii)(A). There is no federal annual mandate, which surprises people, but periodic means recurring and an organization with nothing on record since its compliance date is not satisfying it. An annual cycle is the common answer.

State law can be more specific, and where it is, the number governs. Texas Health and Safety Code 181.101 requires each covered entity to provide training on state and federal law concerning protected health information as necessary and appropriate for employees to carry out their duties, and requires the employee to complete that training within 90 days of hire. If state or federal law changes materially, affected employees must be trained within a reasonable period and no later than one year after the change takes effect. Texas defines covered entity far more broadly than HIPAA does, so the honest first step is reading the definition rather than assuming it misses you. Our Texas HB 300 guide covers the scope in detail.

What you have to be able to hand over

164.530(b)(2)(ii) is one clause long: document that the training has been provided. The retention period is the part that shapes the system you build. Under 164.530(j)(2), required documentation must be kept for six years from the date of its creation or the date when it last was in effect, whichever is later, and Security Rule documentation carries the same window at 164.316(b)(2)(i).

Six years is longer than the average tenure of the person who was trained, longer than most learning platforms are kept under contract, and longer than many vendor relationships. That is the practical argument for a central, exportable record with the learner name, the content, the completion date, and a verifiable reference, rather than a folder of forwarded PDFs belonging to a manager who has since left. Texas adds a specific artifact at 181.101(d): a signed statement from the employee verifying completion, kept for six years from signature.

Training proof and organizational compliance are different objects

This is worth being blunt about, because the market is not. A training certificate documents that a named person completed named content on a specific date. That is a real and required artifact, and it is what 164.530(b)(2)(ii) and 164.308(a)(5) expect you to produce. It is not a statement about your organization. Organizational compliance is the sum of your risk analysis, your safeguards, your agreements, your policies, and the behavior of people under time pressure, and no course can certify it.

There is also no federal HIPAA certification, no HHS approved training list, and no government accreditation of any training provider, including this one. What training gives you is the required input, the documentation, and the only control the rules name that reaches the moment a person decides whether to look, send, or say something. That control is worth buying on its own terms. It is not worth buying under a description that is not true.

How to build it

Five steps from a vague headcount to a roster you can defend

This is the sequence the planner follows, and it is the same sequence that survives a document request later.
1

Walk the building, not the payroll report

Start with the people physically or digitally present in a normal week. Payroll misses volunteers, students, agency cover, and the contractor at the corner desk, and those are exactly the categories that get left off.

2

Apply the direct control test to each group

Ask whether the person's conduct, in performing work for you, is under your direct control. If yes, they are a workforce member regardless of who signs their check.

3

Separate the companies from the people

A vendor that creates, receives, maintains, or transmits protected health information on your behalf needs a written agreement, not seats. Count relationships there, not headcount.

4

Write down the judgment calls

For embedded contractors, board members, and credentialed medical staff, record the determination and the reasoning with your policies. Consistency is what makes the call defensible later.

5

Train, then keep the record retrievable

Assign training before system access rather than after, capture completion with a name and a date, and store it somewhere that will still exist in six years when the person and the vendor may not.

Sources

Every determination in the planner traces to one of these. Read them directly rather than taking this page's word for it.

  • 45 CFR 160.103 , the definitions of workforce, business associate, covered entity, and protected health information.
  • 45 CFR 164.530 , administrative requirements including the training standard at (b), sanctions at (e), and the six year documentation retention period at (j)(2).
  • 45 CFR 164.308 , administrative safeguards including workforce security at (a)(3), security awareness and training at (a)(5), and business associate contracts at (b).
  • 45 CFR 164.502(e) , the condition on disclosing protected health information to a business associate.
  • 45 CFR 164.316 , Security Rule policies, procedures, and the six year documentation window.
  • HHS FAQ 256 , software vendors, and the option to treat an on-site contractor employee as a workforce member.
  • HHS FAQ 243 , incidental contact, janitorial services, and where routine record handling changes the answer.
  • HHS FAQ 248 , physicians with hospital privileges and the organized health care arrangement.
  • HHS guidance on business associates , including the statement that a business associate is not a member of a covered entity's workforce.
  • Texas Health and Safety Code Chapter 181 , including the 90 day training deadline and the signed completion statement at 181.101.

Keep going

What to read once you know who is on the roster

The planner answers the scope question. These pages cover the program, the agreements, and the records that follow from it.

Workforce training FAQ

The questions that decide a seat count

Who needs HIPAA training?

Every member of a covered entity's workforce, and workforce is a defined term rather than a synonym for employees. 45 CFR 160.103 defines workforce as employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid by the covered entity or business associate. Two consequences follow. First, unpaid people are included, so volunteers, students on rotation, and residents are all inside the obligation. Second, people paid by someone else are included when you control their conduct, so agency nurses and temporary front desk cover are in as well. 45 CFR 164.530(b)(1) then requires training on your privacy policies and procedures as necessary and appropriate for members of the workforce to carry out their functions, and 164.308(a)(5)(i) requires a security awareness and training program for all members of the workforce including management. The role determines how deep the training goes. It does not determine whether it happens.

Do volunteers need HIPAA training?

Yes, and this is the most commonly missed line on a training roster. Volunteers are named explicitly in the workforce definition at 45 CFR 160.103, which closes with the phrase whether or not they are paid by the covered entity. A gift shop volunteer, a patient escort, a chaplain, and an auxiliary greeter are all workforce members. The practical case is stronger than the legal one: volunteers often sit at reception, walk hallways where charts and screens are visible, and speak with families, all without the professional training a licensed clinician brings to those situations. The training does not have to match what a nurse receives. 164.530(b)(1) scales training to the person's functions, so a focused module on what may be said, shown, and overheard is usually the right depth.

Do we need to train contractors and temporary staff?

It depends on whether their conduct is under your direct control, not on the contract type. A travel nurse who works your shifts, uses your login, and reports to your charge nurse is a workforce member under 45 CFR 160.103 even though a staffing agency employs them, and they belong on your training roster. A remote billing company that processes your claims from its own office using its own systems is a business associate under the same section, which expressly excludes members of your workforce from that definition. For that vendor you need a written agreement under 164.502(e)(1)(i), not a training seat, and the vendor trains its own workforce. The middle case is real and HHS addresses it: when an employee of a contractor such as a software or IT vendor has a primary duty station on site at a covered entity, the covered entity may choose to treat that employee as a member of its workforce rather than as a business associate. Because it is a choice, write down which way you went and why.

Do business associates have to train their own employees?

Yes, though the route is different from a covered entity's. The Privacy Rule training standard at 164.530(b)(1) is written as an obligation of covered entities. The Security Rule, however, applies directly to business associates, and 164.308(a)(5)(i) requires a security awareness and training program for all workforce members including management. On top of that, a business associate is directly liable for impermissible uses and disclosures under 164.502(a)(3), and its business associate agreement carries specific terms about what it may do with a customer's protected health information. Those terms only reach the people who handle the data if someone trains them. In practice most business associates train their workforce on both privacy and security, because a covered entity performing vendor diligence asks for the training records long before a regulator does.

Do we have to train physicians who have privileges but are not employed?

Usually they are neither your workforce nor your business associates. HHS guidance states that a hospital and the physicians with privileges there participate in an organized health care arrangement, defined at 45 CFR 164.501, and that those physicians do not have to enter into business associate contracts with the hospital. Each independent practitioner practices through their own covered entity, which is responsible for training its own workforce. Many facilities still require orientation on facility privacy policies as a condition of privileges, and that is a sound governance decision rather than a Privacy Rule mandate. The line moves if the relationship changes: a physician who also serves as an employed medical director or who works under the facility's direct control in that second role is a workforce member for that role.

How soon after hire does HIPAA training have to happen?

The federal rule sets a standard rather than a deadline. 45 CFR 164.530(b)(2)(i)(B) requires training each new member of the workforce within a reasonable period of time after the person joins the workforce. Reasonable is judged against your own facts, and the uncomfortable version of the question is how many days someone held chart access before they were trained on how to use it. Sequencing training ahead of system provisioning resolves the question rather than answering it. Some states are more specific. Texas Health and Safety Code 181.101 requires employees of a covered entity to complete training on state and federal law concerning protected health information within 90 days of hire, and to be retrained within a reasonable period after a material change in the law and no later than one year after it takes effect. The Texas definition of covered entity is broader than the federal one, so read it directly rather than assuming it misses you.

Is HIPAA training required every year?

The federal rules do not contain an annual interval, which surprises most people who have been told otherwise. What they contain are three triggers and one recurring expectation. The triggers are new workforce members under 164.530(b)(2)(i)(B), material changes to policies or procedures under 164.530(b)(2)(i)(C), and, for security, periodic security updates as an implementation specification at 164.308(a)(5)(ii)(A). Periodic means recurring, so an organization with nothing since the compliance date is not meeting it. An annual cycle is the common way to satisfy the periodic expectation, to keep records tidy, and to make the roster reconciliation a scheduled task rather than an emergency. Some state laws and many contracts specify annual training outright, and where they do, that requirement governs the people it reaches.

What documentation do we have to keep, and for how long?

45 CFR 164.530(b)(2)(ii) requires you to document that the training was provided, and 164.530(j)(2) requires required documentation to be retained for six years from the date of its creation or the date when it last was in effect, whichever is later. Security Rule documentation carries the same six year window at 164.316(b)(2)(i). A defensible record identifies the person, the content, the date, and how completion was determined. Texas adds a specific artifact at 181.101(d): the covered entity must have each trained employee sign a statement, electronically or in writing, verifying completion, and keep that signed statement for six years from the date of signature. Six years outlasts most staff, most systems, and most vendor relationships, which is the argument for keeping completion records centrally and exportable rather than in individual inboxes.

Does everyone need the same HIPAA training?

No, and building it that way is usually the reason training does not change behavior. 164.530(b)(1) requires training as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity. A biller who handles release of information requests, a nurse discussing a case in a shared space, a developer with production database access, and a housekeeper who empties bins in an exam room face genuinely different decisions. The requirement is common to all of them. The content should not be identical for all of them. A practical structure is a shared core covering the rules, the definitions, and reporting, plus role-specific material for the groups whose daily decisions differ most.

Does completing training make our organization HIPAA compliant?

No, and the distinction matters enough to state plainly. Completing a course proves that named individuals received instruction on a stated date, and a certificate is documentation of that fact, which is exactly what 164.530(b)(2)(ii) and 164.308(a)(5) expect you to keep. Organizational compliance is a much larger thing: your risk analysis, your safeguards, your business associate agreements, your policies, your access controls, and the way people actually behave on a busy Tuesday. No course, vendor, or certificate can establish that an organization is compliant, and there is no federal accreditation, government endorsement, or HHS approved list that does so either. Training proof and organizational compliance are different objects, and anyone selling you the second one as if it were the first is selling something that does not exist.

Once the roster is settled, start with individual certification or plan a team rollout for everyone inside the definition.

Train everyone the definition reaches

A roster is only useful once the people on it are trained

The Privacy Rule requires workforce training and the Security Rule requires a security awareness program for everyone including management. Train them with courses that produce dated, verifiable certificates, assign seats centrally so the records stay retrievable for the six year window, and keep the volunteers, students, and agency staff on the same list as everyone else.