Which workers must receive HIPAA security training?

All workforce members, including management, must be in the security training program.

Start playing free

  1. Only IT staff
  2. Only new patients
  3. All workforce members, including management ✔

Why: The Security Rule requires a security awareness and training program for all members of the workforce, including management. It is not just for the IT department.

Huh, didn't know that: The program covers security reminders, malware protection, log-in monitoring and password management.

The dad joke
Why did the entire staff attend security training? Because HIPAA said so, and they wanted a break from the waiting room.
Like this card?
Play the game

References

Answer: All workforce members, including management. The Security Rule requires a security awareness and training program for all members of the workforce, including management. It is not just for the IT department.

  1. 45 CFR 164.308(a)(5)(i) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
    Implement a security awareness and training program for all members of its workforce (including management).
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game