Itโs Friday morning and I am catching up on my HIPAA governance for training.
For all you vCISO/Fractional types, there is no HIPAA requirement for annual training but there is a rule that requires training with a reasonable amount of time upon employment or change in job function or role.
A lot of people think itโs annual but that requirement is not HIPAA.
It is good practice to use the requirements above AND use a awareness program that provides annual HIPAA refresher training to catch anyone who may have had role/function changes and not provided training during the normal business operations processes for changes in personnel. This reduces the risk of missing training and allows the org to comply with governance for other privacy related activities (GDPR,CCPA/CPRA, etcโฆ)
Remember, I am not a lawyer, this is not legal advice, governance is always something that should involve professionals that specialize in the legal requirements for your organization.
#awarenesstraining #InfoSec #hipaa #hipaacompliance