HIPAA and security training your staff will actually finish — and your auditor can actually verify.
Short modules written for the way a practice really runs. Everyone who passes gets a dated certificate with a serial number anyone can check online. That record is what HIPAA actually asks you to keep, and it is the thing most training providers do not give you.
Comodo Technology is a Sacramento managed IT provider. We have supported California healthcare practices through real incidents, and this training is written from that experience rather than from a template.
- Two programmes, 17 modules
- HIPAA Security Awareness and HIPAA Awareness. Buy one or both.
- 6–9 minutes a module
- Done between patients. Progress saves as they go.
- Assigned by role
- Front desk, billing, clinical, providers, managers, lab, sterile processing.
- Publicly verifiable certificates
- Serial number, programme, modules completed, date. Try one below.
- State law included
- California CMIA and Texas HB 300, not just federal HIPAA.
Two programmes. Take one, or both.
They answer two different questions. HIPAA Security Awareness is about protecting the systems — §164.308(a)(5). HIPAA Awareness is about what you may say, to whom, and what patients can demand of you — §164.530(b). Most practices need both. If you already hold a HIPAA certificate from somewhere else, buy the security half on its own.
HIPAA Security Awareness Training
9 modules each · about 62 minutes · 8 questions per module
- Phishing and email threats in a healthcare practice
- Passwords, logins and multi-factor authentication
- The phone call that is not what it seems
- Protecting patient information day to day
- Workstations, devices and the office itself
- Working outside the office: home, telehealth, personal devices
- Email, text, voicemail and the patient portal
- When something goes wrong: reporting and response
- Plus their own role module
HIPAA Awareness Training
8 modules each · about 69 minutes · 8 questions per module
- What you may share, and what patients can ask for
- The Notice of Privacy Practices: the promise your practice made
- Minimum necessary: how much is too much to share
- Records, amendments and restrictions: the deadlines you must meet
- Business associates: the vendors who hold your patients' data
- Breach or not: how that decision actually gets made
- Police, family, courts and public health
- Plus their own role module
Seven role modules
Front desk · billing and claims · clinical staff and the exam room · providers and prescribers · office managers · outside labs and imaging · sterile processing.
Graded on the server
80% to pass. Questions are shuffled and the answer key never reaches the browser, so a certificate means somebody actually knew the material.
Six-year records
Every completion is kept for the full HIPAA documentation period, and your office manager can export the whole practice to a spreadsheet at any time.
One price per practice, per year. Both programmes included.
No per-course maths, no separate charge for the security half, no extra for the role modules. One price covers both programmes, every role module and your documentation, and replacing somebody who leaves costs nothing.
Cheaper looks cheaper until you add up what you actually need.
A $29.99 sticker is one course. You need two. Then the role modules, then the documents — sold as two more kits. Here is the same shopping basket, priced both ways.
They price HIPAA Awareness and HIPAA Security separately and discount the second. We do not sell halves.
Some providers charge more for the people who need it most. Same price here as everybody else.
Two separate kits there, at $499.99 each. One pack here, and ours includes the security risk assessment.
Compared against the published prices of a widely used online HIPAA training provider, checked September 2026. Prices change and theirs may have. Go and look — we would rather you checked than took our word for it.
The training
Minimum 5 people. Over 25, ask us — it comes down.
- Both programmes — HIPAA Security Awareness and HIPAA Awareness
- Every role module, assigned automatically
- Certificates anyone can verify online
- Your practice report, exportable to a spreadsheet
- Six years of records kept for you
- Replace a leaver at no extra cost
HIPAA Compliance Pack
Add $39 a head above ten. Training for everyone is included.
Training proves your staff were taught. This proves your practice is compliant — which is what anyone actually asks you for.
- Everything in option one, for every member of staff
- Notice of Privacy Practices, written for your practice
- Security risk assessment — the one §164.308(a)(1) requires and most practices have never done
- Business associate agreements and a vendor register to fill in
- Policies and procedures set
- Incident response plan and breach assessment worksheet
- Staff acknowledgement forms, signed and filed
If the Office for Civil Rights called tomorrow and asked for your Notice, your risk assessment, your vendor agreements and six years of training records — how long would that take you?
Buying for yourself?
One person, both programmes, your own certificate. For job seekers, temps, contractors and anyone whose employer is not providing it.
Already a Comodo Technology managed IT client?
Then the training is part of what you already pay for. Don't buy it — call us and we will switch it on for your practice, set up your join link and add your staff. The free tools further down this page are yours as well, whether or not anyone takes the training.
hipaa@comodotechnology.comA certificate anybody can check
Read §164.530(b) closely and you will notice the requirement is not only that you train your workforce. It is that you document it, and keep that documentation for six years. What a practice is really buying is proof.
Every certificate carries a serial number, the programme it belongs to, how many of that programme's modules the person had completed, the score, the date, and the practice name — taken from the practice record, never typed by the learner. Anyone holding the serial can confirm it is genuine without an account and without contacting us.
A question worth asking any training vendor
There is no federal body that certifies HIPAA trainers. HHS states it plainly on its own site. So when a website sells you a “HIPAA certified” certificate, ask them who certified them.
What the rule actually requires you to keep is proof that a named person was trained, on a named date, that you can still produce six years later. That is precisely what this is — and you can check any one of them from this page.
Security Awareness Training & HIPAA Compliance
Check a certificate right now
This is the same public endpoint an auditor or an insurer would use. No account needed.
HIPAA is the floor. Your state may sit above it.
The federal training is identical wherever you practise, and we sell in all fifty states. What changes is the state-law section, because some states go further than HIPAA — and where they do, the state law is what you have to meet.
In California, the patient can sue you directly
California has its own medical privacy law — the Confidentiality of Medical Information Act — and it differs from HIPAA in one way that changes your whole risk picture. A national course bought off the internet will not tell you about it.
We are in Sacramento. When something happens at 7am on a Monday, you are calling a number answered in California, not a ticket queue three time zones away.
Take these whether you ever buy anything or not
Print them, laminate them, put them where people work. They are useful on their own, and we would rather you had them. If you are already a Comodo managed IT client, all of this is yours too — you do not need to be buying certificates to use it.
Workstation security cheat sheet
One page for the front desk and every clinical workstation.
Incident response plan
Two pages. What to do in the first hour, in order.
HIPAA patient rights
What patients can ask for, and the deadlines that come with each.
Staff training acknowledgement
The signed form that goes in the file. Keep it six years.
The dental practice toolkit
Eleven interactive tools built around how a dental office actually runs: department-by-department protocols, a phishing simulator, a breach scorecard, a safe transfer checker, HR offboarding and software crash triage.
Open the toolkitMedical & specialty practices
The same training, written for family medicine, urgent care, optometry, podiatry, behavioural health, home health, imaging and labs — plus a free four-factor breach self-check you can run right now.
Open the pageFour steps, none of them hard
- 1
Tell us your practice name and how many staff
That sets your band. Both programmes are included either way.
- 2
We send one join link for your practice
Forward it to everyone. Each person fills in their own name and role — your practice name comes from the link, so it is always right on their certificate and nobody can mistype it.
- 3
They work through it at their own pace
No passwords — they get an emailed sign-in link. Progress saves, so they can stop between patients and come back.
- 4
Your office manager gets the record
Who has finished, who has not, every certificate number, exportable to a spreadsheet. That is the file you hand an auditor or an insurance questionnaire.
Talk to a person
No form that goes nowhere. These reach us.
Comodo managed IT clients: keep using your usual support number for anything IT. This line is for training and HIPAA.