
Workforce training
HIPAA staff training that addresses real risks.
The breaches that happen in small practices are not sophisticated attacks. They are a phishing email, a photo posted to social media, a laptop left in a car, and staff looking up records they have no business reading.
Modules
What the training covers.
Social media
Why a photo of the break room with a schedule board behind it is a disclosure, why "no names were used" is not a defence, and what to do when a patient posts about your practice.
Phishing and social engineering
Recognising credential harvesting, invoice fraud and pretext calls requesting patient information. Includes verification procedure for unexpected requests.
Curiosity browsing
Accessing the record of a colleague, family member, neighbour or public figure is a sanctionable violation even when nothing is shared. Audit logs make it visible.
Passwords and access
Unique credentials for every user, why shared logins destroy accountability, multi-factor authentication, and automatic logoff at unattended workstations.
Physical safeguards
Screen positioning at reception, papers on the printer, whiteboards visible from the waiting area, and secure disposal rather than the general waste bin.
Incident reporting
What counts as a security incident, who to tell, how fast, and why early reporting consistently produces better outcomes than concealment.
Documentation
The records the training produces.
- Dated attendance roster with signatures for every workforce member
- Course content and syllabus retained as evidence of subject matter
- Individual certificates of completion
- New-hire training record completed within a reasonable period of hire
- Refresher record following any material change to policies or systems
- Retention of all training documentation for six years
Schedule this year’s workforce training.
On-site or online, with the documentation trail complete when the session ends.