HIPAA
2h 25 min! Run Time
Employees
only
of Completion
What you'll learn
Skills covered in this course
Description
HIPAA — the acronym alone strikes fear in the medical industry and beyond, and violation settlements can cost an organization millions.
What this course covers:
- The background behind the HIPAA law
- Which organizations must comply with HIPAA rules
- How to tell whether the rules apply to you
- The kind of HIPAA training your role may need
A concise introduction for employees meeting HIPAA compliance for the first time.
System Requirements
See System Requirements in the Coggno Knowledge Base
Author
HIPAA
In 2009, Congress passed the Health Information Technology for Economic and Clinical Health Act — HITECH. This sweeping law has implications for nearly every health care provider and organization in the medical industry.
What this course covers:
- What the HITECH Act is and why it passed
- How HITECH connects to and strengthens HIPAA
- Who the law affects across the medical industry
- Why HITECH still shapes compliance today
A short primer for anyone who needs to understand HITECHs role in HIPAA compliance.
HITECH, part of 2009 legislation, was designed to encourage electronic health records nationwide — and it further refined HIPAA by clarifying the roles of the business associates of covered entities.
What this course covers:
- What a business associate is under HIPAA
- How HITECH expanded their responsibilities
- Why business associates must be HIPAA compliant
- How covered entities and associates share PHI duties
Built for vendors, contractors, and partners who handle PHI on behalf of covered entities.
Nearly every part of HIPAA revolves around protected health information, or PHI. Before diving into the rules, every employee needs to understand exactly what PHI is.
What this course covers:
- How HIPAA defines protected health information
- The identifiers that turn data into PHI
- Examples of PHI you may handle at work
- Why recognizing PHI is the foundation of compliance
A short, essential lesson for any employee who encounters patient information.
HIPAA is built on two main components: the Privacy Rule and the Security Rule. This course zeroes in on the authorizations portion of the Privacy Rule, with a practical summary for the average employee.
What this course covers:
- What a HIPAA authorization is
- When patient authorization is required to use or disclose PHI
- What a valid authorization must include
- Everyday situations where authorizations apply
Note: this course summarizes the authorizations portion, not the entire Privacy Rule. Ideal for frontline staff.
HIPAA rests on two main components: the Privacy Rule and the Security Rule. This course focuses on the disclosures portion of the Privacy Rule, offering a practical summary for the average employee.
What this course covers:
- What counts as a disclosure of PHI
- Permitted disclosures under the Privacy Rule
- When PHI can be shared without authorization
- How disclosure rules play out day to day
Note: this course summarizes the disclosures portion, not the entire Privacy Rule. Built for frontline staff.
HIPAA is built on two main components: the Privacy Rule and the Security Rule. This course focuses on the Security Rule, with a clear summary suited to the average employee.
What this course covers:
- What the HIPAA Security Rule protects
- How it safeguards electronic protected health information
- The role of administrative, physical, and technical safeguards
- Everyday practices that keep ePHI secure
Note: this course summarizes the Security Rule, not the entire regulation. Ideal for staff handling electronic PHI.
Understanding HIPAA means putting the rules into practice. This course explains what happens when an organization fails to follow the Privacy or Security Rules.
What this course covers:
- What the HIPAA Enforcement Rule establishes
- How violation complaints are handled
- The enforcement responsibilities and processes involved
- Why managers and supervisors benefit from knowing them
Especially useful for managers and supervisors, though valuable for any employee curious about the consequences.
HIPAA exists to prevent the unauthorized use or disclosure of protected health information. Under the Privacy Rule, any impermissible release of PHI is considered a "breach."
What this course covers:
- How HIPAA defines a breach
- What counts as an impermissible release of PHI
- Common ways breaches happen
- Steps every employee can take to prevent one
Built for all staff who handle protected health information and want to avoid costly mistakes.
HIPAA passed Congress in 1996 to protect the security and confidentiality of patient health information. In 2009, the HITECH Act amended and strengthened it — and established the penalty structure for violations.
What this course covers:
- How the HITECH Act reshaped HIPAA enforcement
- The tiered structure behind HIPAA penalties
- What drives the size of a fine
- Why penalties matter to every covered entity
Useful for managers, supervisors, and staff who want to grasp the real cost of HIPAA noncompliance.
HIPAA dedicates a great deal of its content to how and when covered entities can disclose protected health information. This FAQ-style course keeps you prepared.
What this course covers:
- When covered entities may disclose PHI
- Common questions about permitted disclosures
- Everyday situations where disclosure rules apply
- How to stay compliant when sharing patient information
Built for staff who field real-world disclosure questions and need clear, reliable answers.
HIPAA greatly affects how covered entities can market products and services to patients. Marketing means any communication that encourages someone to buy or use a product or service — and it is a tricky area for compliance.
What this course covers:
- How HIPAA defines marketing
- When protected health information may be used for marketing
- Frequently asked marketing compliance questions
- Why legal review matters before sharing PHI
Ideal for marketing, compliance, and administrative staff at covered entities.
HIPAA is a cumbersome maze of rules, and staying compliant is your organizations job. A formal risk analysis is one of the most important steps toward protecting PHI and limiting breach exposure.
What this course covers:
- Why a formal risk analysis matters under HIPAA
- HHS recommendations for conducting one
- How risk analysis reveals gaps in your safeguards
- How it can limit fines from the Office for Civil Rights if a breach occurs
Aimed at compliance leads and managers responsible for HIPAA safeguards.
Staying HIPAA compliant is your organizations job, and safeguards are central to it. Alongside a formal risk analysis, the right safeguards greatly limit the risk of a breach.
What this course covers:
- The administrative safeguards HIPAA expects
- Technical safeguards for protecting electronic PHI
- Physical safeguards for facilities and devices
- How safeguards can mitigate fines from the Office for Civil Rights
Built for teams putting HHS safeguard recommendations into daily practice.
HIPAA is a big topic — so big that hours of training go into full compliance. But what does the average health care worker or volunteer actually need to know?
What this course covers:
- The HIPAA essentials every employee should know
- How to handle protected health information day to day
- Simple habits that keep patient data secure
- When to ask for help or escalate a concern
A fast, focused option for frontline staff and volunteers who need the key points without the deep dive.
HIPAA exists to protect patients. Beyond the rules and regulations, it is just as important to understand the rights consumers hold over their own health information.
What this course covers:
- The rights HIPAA gives consumers over their PHI
- What patients expect from your compliance efforts
- How consumer rights shape everyday interactions
- Your role in honoring those rights
Helpful for any employee who interacts with patients and their protected health information.
HIPAA devotes much of its content to how and when covered entities can disclose PHI. Sharing information with family and friends is one of the more complex topics, because the situations vary so widely.
What this course covers:
- When PHI may be shared with family and friends
- How the Privacy Rules permitted disclosures apply
- Judgment calls in common real-world situations
- How to protect patient privacy while helping loved ones
Built for clinical and front-desk staff who face these conversations firsthand.
As an emergency responder, you meet patients during the most vulnerable moments of their lives. A common first question is: "Am I required to be HIPAA compliant?" Most of the time, the answer is yes.
What this course covers:
- Why most emergency responders are covered entities
- How HIPAA applies to EMS agencies, fire departments, and rescue squads
- Protecting PHI while treating and transporting patients
- Balancing patient privacy with urgent care
Written for EMTs, paramedics, firefighters, and rescue personnel.
Using genetic information to predict a patients risk of illness is a remarkable advance — but it can also be misused. The Genetic Information Nondiscrimination Act (GINA), passed in 2008, exists to make sure it helps rather than harms.
What this course covers:
- What GINA is and why it became law
- How GINA protects people from genetic discrimination
- Limits on how employers may use genetic information
- Limits on how health insurers may use genetic information
Relevant for HR, benefits, and health care staff who handle genetic health information.
HIPAA — the acronym alone strikes fear in the medical industry and beyond, and no wonder: violation settlements can cost an organization millions.
What this course covers:
A plain-language starting point for employees who need to understand where HIPAA compliance begins.