Training & Documentation

HIPAA Training Log & Acknowledgment Template

Track who was trained, on what, when and by whom. Due dates compute automatically, overdue staff are flagged, and each employee gets a printable signed attestation. Built to satisfy 45 CFR 164.530(b) and the six-year record rule in 164.530(j).

Cyanotype vignette of a sign-in clipboard by a training-room door with empty chairs behindFIG · 01
A sign-in clipboard by a training-room door with empty chairs behind.

What a HIPAA training log has to prove

The Privacy Rule requires every covered entity to train all members of its workforce on its PHI policies and to document that the training happened (45 CFR 164.530(b)). The Security Rule adds a security awareness program with periodic updates (164.308(a)(5)). Neither rule prescribes a form. What OCR asks for in an investigation is simple: who was trained, on what, when, by whom, and the signed acknowledgment. This log records exactly those fields, and the training requirements guide walks through the rule text.

When training must be logged

New hire §164.530(b)(2)(i)(B)

Within a reasonable period after joining the workforce

Most practices set 30 days and do it in week one. Log the hire date so the gap is visible.

Material policy change §164.530(b)(2)(i)(C)

Within a reasonable period after the change takes effect

New EHR, new texting platform, new breach procedure. Record the change as the topic.

Periodic refresher §164.308(a)(5)

Security awareness updates, periodicity set by your policy

HIPAA does not name a number of months. Annual is the norm auditors expect; OSHA BBP is annual by rule.

Documentation §164.530(b)(2)(ii), (j)(2)

Document that training was provided; keep 6 years

If it is not written down, OCR treats it as not done. The log is the proof.

How to use this template

  1. 1

    Set the practice header and refresher cycle

    Enter the practice name and Privacy Officer. Choose 12 months unless your written policy says otherwise; the next-due column recalculates immediately.

  2. 2

    Fill in each workforce member

    Name, role, hire date, last training date, method, trainer and quiz score. Include volunteers, students, temps and contractors who touch PHI: they are workforce under 45 CFR 160.103.

  3. 3

    Tick the topics covered

    Each topic maps to a regulation section so an auditor can see coverage at a glance. Tick Bloodborne pathogens only for staff with occupational exposure.

  4. 4

    Act on the status badges

    Red means the refresher date has passed; amber means it is inside 30 days; dark red means no training on file at all. Schedule those first.

  5. 5

    Print the acknowledgment for each person

    Switch to the Employee acknowledgment tab, pick the name, print, sign, and file. Keep the signed copy 6 years.

Pair the log with the free HIPAA training quiz for the score column, and with the onboarding checklist so new hires cannot reach the EHR before the first row is filled.

Retention periods that apply to this record

Two agencies, two clocks. Keep the longer one when a record satisfies both.

RecordAuthorityKeepClock starts
HIPAA training documentation45 CFR 164.530(j)(2)6 yearsDate created, or date last in effect (later of the two)
Signed employee acknowledgment45 CFR 164.530(j)(2)6 yearsDate signed
Security awareness training records45 CFR 164.316(b)(2)6 yearsDate created or last in effect
OSHA bloodborne pathogens training record29 CFR 1910.1030(h)(2)(ii)3 yearsDate the training occurred
OSHA medical record (Hep B, exposure follow-up)29 CFR 1910.1030(h)(1)(iv)Employment + 30 yearsKept per 1910.1020

State medical-record and employment laws can be longer. If staff have occupational exposure, the exposure control plan generator covers the OSHA side, and the bloodborne pathogens training guide explains what the annual session must include.

What an investigator looks for

OCR’s data requests in breach investigations routinely ask for “evidence of workforce training” for the period before the incident. A log that fails usually fails one of these ways:

  • Training dates exist but no content: a date without topics does not show the person was trained on your policies.
  • New hires trained months after they were given EHR access. Compare the hire-date and trained columns.
  • No retraining after a material change, such as the switch to a new patient texting platform.
  • No signed acknowledgment, so the sanctions policy cannot be enforced when a common violation happens.

Put the log on the agenda of every compliance committee meeting and fold the overdue count into your annual work plan. Missing training also shows up as a finding in the HIPAA audit checklist.

Frequently asked questions

For what a certificate does and does not prove, read HIPAA and bloodborne pathogens certification. For the penalty exposure when training is missing, see HIPAA violation penalties.

Related Tools & Guides