Ask a facility administrator whether staff receive HIPAA training and the answer is almost always yes. Ask to see the records and the answer is often slower: a sign-in sheet in a drawer, an old spreadsheet, a login to a training site that nobody remembers. When a surveyor, auditor or insurer asks for proof, the quality of your records matters as much as the quality of the training.
Here is what to keep, how to organize it and how long it must be retained.
The HIPAA Privacy Rule requires covered entities to train all workforce members on the policies and procedures relevant to their roles, and to document that training. The Security Rule requires a security awareness and training program for all workforce members, including management. Under the administrative requirements, you must keep written or electronic records of policies, procedures and required actions, activities or assessments, and retain that documentation for six years from the date of creation or the date it was last in effect, whichever is later.
State laws and other contracts may call for longer retention, so confirm with your attorney.
The definition is broad. It includes employees, volunteers, trainees and others whose work is under your direct control, whether or not they are paid. Agency staff, students on clinical rotations and some contractors working in your building may fall under it or under their employer's responsibilities, depending on the arrangement. Decide and document how you treat each group.
For each individual, keep:
Name, role and department
Date of hire and date of each training session
Topics covered, such as privacy, security, breach reporting or specific policies
Format and trainer: in person, online module, huddle
A signature or electronic acknowledgment
Test results, if you use quizzes
Acknowledgment of key policies, such as confidentiality, acceptable use and mobile devices
For the program as a whole, keep:
The training materials and slides used on each date, with version numbers
Attendance lists and completion reports
A calendar or plan showing when training occurs
Records of simulated phishing exercises and follow-up coaching
Notes on updates made after policy changes, incidents or audits
Records of sanctions applied for violations, which HIPAA also requires you to document
For new workforce members, within a reasonable period after joining and, as a best practice, before they access resident information
When policies or procedures change materially, for those affected
Periodically, as part of your security reminders. Many organizations train annually, and add shorter reminders between sessions.
After an incident reveals a gap in understanding
A learning management system, an HR platform or even a well-structured shared drive can work. What matters is consistency. Avoid scattering records across paper binders, email and individual desktops.
For example, organize by year and topic, with one file per person or per session. Keep a master index of who completed what and when.
Training records contain personnel information and should be accessible only to those who need them, such as HR, compliance and administration.
Include training records in your backup plan. Losing six years of documentation because of a server failure is avoidable.
Pick five employees at random from different departments.
Can you find proof of onboarding training for each?
Can you show their most recent annual training and what it covered?
Can you show that the materials matched your current policies at that time?
Can you show that agency or temporary staff were trained?
Do records exist from six years ago for people who have left?
If the answers are not all yes, you have found your next project.
Sign-in sheets with no indication of topic or date
Training content that was updated without keeping the earlier version
Records that disappear when an employee leaves or a vendor contract ends
No documentation for management or the board
Training that is completed but never tied to the current risk analysis
Reports from your training system can show which departments lag, which topics need follow-up and how phishing test results change over time. Share trends with leadership.
We help healthcare organizations set up training tracking, store records securely and prepare documentation for audits and insurance reviews. If you are unsure whether your records would hold up to scrutiny, we can do a short review of your training program and recommend improvements.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172