Compliance · HIPAA

HIPAA security awareness and training requirements 45 CFR §164.308(a)(5)

The HIPAA Security Rule requires covered entities and business associates to implement a security awareness and training programme for all members of the workforce, including management. It does not mention phishing simulation, but simulation helps you demonstrate it.

Here is the clause, what “addressable” means, why phishing simulation helps, and the evidence SecurityRing gives you.

Last reviewed 10 October 2026 against the official texts. Not legal advice.

The short answer

HIPAA in three lines

  • Who it applies to

    Covered entities (health plans, health care clearinghouses and most health care providers) and their business associates, for electronic protected health information.

  • What it asks on awareness training

    A security awareness and training programme for the whole workforce, including management, with four addressable specifications (§164.308(a)(5)).

  • Where phishing simulation fits

    It helps you show training and resilience. The Security Rule does not mention phishing simulation; “protection from malicious software” and “security reminders” are addressable specifications that simulation and lessons can help you address.

Who it applies to

Who has to follow HIPAA

HIPAA is United States law. The Security Rule applies to covered entities and business associates (§164.302). HHS describes covered entities as health plans, health care clearinghouses and most health care providers. Business associates are the vendors and others that handle electronic protected health information (ePHI) for them.

If you are a business associate, for example a service provider that handles a US customer’s ePHI, the awareness standard applies to your workforce as well.

What it asks for

What HIPAA asks for on awareness training

The clauses that matter, with their numbers. “Official wording” is quoted exactly; “Our paraphrase” is our summary in plain words.

  1. §164.308(a)(5)(i), standardOfficial wording

    Implement a security awareness and training program for all members of its workforce (including management).

  2. §164.308(a)(5)(ii)(A), Security reminders (Addressable)Official wording

    Periodic security updates.

  3. §164.308(a)(5)(ii)(B), Protection from malicious software (Addressable)Official wording

    Procedures for guarding against, detecting, and reporting malicious software.

  4. §164.308(a)(5)(ii)(C) and (D), AddressableOur paraphrase

    Log-in monitoring (procedures for monitoring log-in attempts and reporting discrepancies) and password management (procedures for creating, changing and safeguarding passwords).

  5. §164.306(d)(3), what “addressable” meansOur paraphrase

    Addressable does not mean optional. You assess whether each specification is reasonable and appropriate in your environment, then implement it, or document why it is not and implement an equivalent alternative measure if that is reasonable.

  6. §164.316(b), documentationOur paraphrase

    Keep your security policies and procedures in writing (electronic is fine) and a written record of any action, activity or assessment the rule requires to be documented, and retain that documentation for six years from when it was created or last in effect, whichever is later.

Phishing simulation

Why phishing simulation helps

Phishing simulation lets you show that people were trained and that they were tested. Four reasons it helps come first; then, so you are not misled, we say exactly what the framework text itself asks for.

  1. Test

    A realistic simulated attack

    SecurityRing sends a realistic simulated attack to your employees.

  2. Teach

    A short lesson after the click

    A short lesson opens straight after the click, designed to take under two minutes.

  3. Evidence

    A report a reviewer can read

    Campaign report, completion records, trend report and audit trail, exported as PPT, PDF or CSV.

Illustrative flow: how a simulation moves from test to lesson to report.
Reports / Campaign

Campaign results

Evidence for HIPAA review

  • People tested
  • Opened
  • Clicked
  • Completed the lesson

In the report

  • Completion records
  • Trend report
  • Audit trail

Export as

  • PPT
  • PDF
  • CSV
Illustrative report layout. Bars and fields are placeholders, not data.
  • Show training and resilience

    Employees are tested with realistic attacks, not only shown a course. Your reports show who was tested, how they behaved and what followed, so you can evidence resilience as well as training.

  • Faster, with less chasing

    A simulation reaches people in their inbox. There is no long course to schedule and no constantly chasing employees to finish it, so your time goes where it is needed.

  • A short lesson at the right moment

    When someone clicks, a short lesson opens straight away on the exact attack they just met, designed to take under two minutes. That saves you and your employees time compared with a long course.

  • Reports a reviewer can read

    The campaign report, per-person completion records, executive trend report and dated audit trail, exported as PPT, PDF or CSV, serve as evidence of security training and phishing awareness and of actual resilience testing. Offer them alongside your other evidence.

Phishing is one route for malicious software and stolen credentials. Simulations show who clicked, and the lesson teaches the exact attack they met, so they support your “security reminders” and “protection from malicious software” procedures (§164.308(a)(5)(ii)(A) and (B)). Dated campaign reports and completion records for the people who clicked, exported as PPT, PDF or CSV, can go into the documentation you retain for six years (§164.316(b)).

What HIPAA says

The Security Rule does not mention phishing simulation.

The Security Rule does not mention phishing or phishing simulations. The awareness standard is general, and its four specifications are all addressable: security reminders, protection from malicious software, log-in monitoring and password management.

Many programmes use simulations and lessons to address the “malicious software” and “security reminders” specifications. Whether that is reasonable and appropriate for you is a result of your own risk analysis, and your auditor or OCR decides.

How SecurityRing runs phishing simulations

Good to know

The Security Rule is being updated, but the current rule is in force

On 27 December 2024 HHS’s Office for Civil Rights issued a proposed rule to update the Security Rule, and HHS states that the current rule remains in effect while it is undertaking that rulemaking. As of 10 October 2026 we have not found a final rule. Read the proposal itself for what it would change about training before you plan around it.

Evidence from SecurityRing

Evidence for HIPAA from SecurityRing

SecurityRing gives evidence for the workforce-training part of the Security Rule. This is how its outputs line up with the clauses.

What HIPAA asksEvidence from SecurityRing
A security awareness and training programme for all members of the workforce (a)(5)(i)Per-person lesson-completion records for people who clicked and dated campaign reports. This is part of a workforce programme, not all of it; HIPAA covers all members of the workforce, including management.
Security reminders: periodic security updates (a)(5)(ii)(A)Recurring campaigns, each with a dated report and lesson. Admins can send training reminders from the report to people who have not finished.
Protection from malicious software: procedures for guarding against, detecting and reporting (a)(5)(ii)(B)Simulations show who clicked, and the lesson teaches the exact attack they missed. One part of your procedures, not all of them.
Documentation retained for six years (§164.316(b))Export campaign reports and completion records as PPT, PDF or CSV for your compliance file. Retention is your responsibility.

What SecurityRing produces

  • Campaign report. For each campaign: sent, opened, clicked, video completed and training completed, time to action, results by department, location, seniority and manager cohort, repeat exposure and recommended follow-up.
  • Completion records. A per-person roster for each campaign, with drill-downs, showing who was phished, who finished the lesson and when. The lesson goes to people who act on a simulation, so this is not a record of training for your whole workforce.
  • Executive trend report. Across campaigns over a six-month lookback: phishing exposure score, trends by department and senior management, response speed and a 30-day action plan.
  • Audit trail. A dated interaction audit trail for each campaign: what each recipient did and when.
  • PPT, PDF and CSV export. Download the campaign and executive trend reports as PPT, PDF or CSV for your auditor, or present them on screen.

What it does not do

  • SecurityRing covers phishing and deepfake awareness for the employees you enrol. It is not a HIPAA risk analysis and does not cover the rest of the Security Rule.
  • SecurityRing’s lesson goes to people who click or submit in a simulation, not to every employee. Where a requirement covers all staff, keep your baseline training programme and use SecurityRing for simulation results and follow-up.
  • SecurityRing’s reports are not mapped to HIPAA clause numbers. You decide which report supports which clause, and your auditor decides whether it is enough.
  • It does not provide training on log-in monitoring or password procedures beyond what a lesson on a simulated attack covers.

This page is a plain-language summary for GRC teams, not legal advice. SecurityRing gives you evidence for the awareness-training part of a framework and helps you demonstrate it. Using SecurityRing does not make you compliant, it is not a certification, and no regulator or standards body endorses it. Your auditor or regulator decides whether the evidence is enough.

FAQ

HIPAA awareness training FAQ

More questions? Ask us in a demo.

What does HIPAA require for security awareness training?

Under 45 CFR §164.308(a)(5), covered entities and business associates must implement a security awareness and training programme for all members of the workforce, including management. The standard has four addressable specifications: security reminders, protection from malicious software, log-in monitoring and password management.

How does phishing simulation help with HIPAA, and does the rule require it?

Simulation helps you show both training and resilience, and the reports can go into your documentation. The Security Rule itself does not mention phishing simulation. Training on guarding against malicious software and periodic security updates are addressable specifications, so you decide through your risk analysis whether simulations are a reasonable part of your programme, and document that decision.

Are HIPAA’s addressable specifications optional?

No. For each addressable specification you must assess whether it is reasonable and appropriate. If it is, implement it. If it is not, document why and implement an equivalent alternative measure where reasonable (§164.306(d)(3)). The assessment and the decision should be written down.

Does SecurityRing make us HIPAA compliant?

No. SecurityRing helps you demonstrate the workforce awareness-training part of the Security Rule with completion records, campaign reports and exports. The rest of the rule, including risk analysis, is outside it, and no regulator endorses SecurityRing. Your auditor or OCR decides whether you comply.

Sources and how we checked

Last reviewed 10 October 2026. Quoted text is from the eCFR version current on 1 October 2026 (sections 164.302, 164.306, 164.308 and 164.316). The proposed-rule paragraph relies on HHS’s own NPRM page; whether a final rule has since been issued should be confirmed there.

See the evidence your HIPAA reviewer will read

Book a demo to see how a campaign report, completion records and the executive trend report would look for your team, and how they line up with HIPAA.