
Your workforce is an important part of protecting electronic protected health information (ePHI). HIPAA already requires covered entities and business associates to train their workforce, maintain security policies, and control access to ePHI. A proposed update to the HIPAA Security Rule would make many of these requirements more specific.
What Does HIPAA Require Today?
The current Security Rule requires a security awareness and training program for all workforce members, including management. It also includes addressable provisions covering security updates, protection from malicious software, login monitoring, and password management.
Organizations must maintain written Security Rule policies and procedures, update them when needed, and have procedures for ending access when a workforce member leaves. However, the current Security Rule does not set a specific annual training schedule, a deadline for training new workforce members, or a timeframe for removing access.
What Would the Proposed Rule Change?
If finalized as written, the proposed rule would establish clearer training content and deadlines. Covered entities and business associates would need to:
- Provide role-based security training at least once every 12 months
- Train new workforce members no later than 30 days after they first receive system access
- Provide updated training within 30 days of a material policy or procedure change affecting someone’s role
- Provide ongoing reminders/continuous trainings about security responsibilities and emerging threats
- Document that training and reminders were provided
The proposal would also require workforce security policies and procedures to be reviewed and tested annually.
Training is only one part of workforce security. Under the proposal, system and facility access would need to be terminated as soon as possible, but no later than one hour after a workforce member’s employment or other arrangement ends. When that person had authorized access to systems maintained by another covered entity or business associate, that organization would generally need to be notified within 24 hours.
These changes are not final, but organizations can begin preparing by reviewing their training, policies, documentation, and access-removal processes.

Leave a Reply