HIPAA and security training your staff will actually finish — and your auditor can actually verify.
Short modules written for the way a medical practice really runs. Every person who passes gets a dated certificate with a serial number anyone can check online. That record is what HIPAA actually asks you to keep — and it is the thing most training providers do not give you.
Comodo Technology is a Sacramento managed IT provider. We have supported California healthcare practices through real incidents, and this training is written from that experience rather than from a template.
- Two programmes, 17 modules
- HIPAA Security Awareness and HIPAA Awareness. Buy one or both.
- 6–9 minutes a module
- Done between patients. Progress saves as they go.
- Assigned by role
- Front desk, billing, clinical, providers, managers, lab, sterile processing.
- Publicly verifiable certificates
- Serial number, programme, modules completed, date. Try one below.
- Covers California CMIA
- Not just federal HIPAA. This is the part that gets California practices sued.
If you hold patient records, this applies to you
HIPAA does not have a version for large hospitals and a lighter one for a three-person office. The obligations are the same. What changes is that a small practice has no compliance department, no IT person in the building, and a front desk being interrupted every ninety seconds. The training is written for that reality.
Billing companies, labs, transcription and IT vendors: you are a business associate, not a covered entity, and you are directly liable under HITECH for parts of the Security Rule. You need this training too, and your clients are increasingly asking you to prove you have it. We issue you the same verifiable certificates.
Two programmes. Take one, or both.
They answer two different questions. HIPAA Security Awareness is about protecting the systems — §164.308(a)(5). HIPAA Awareness is about what you are allowed to say, to whom, and what patients can demand of you — §164.530(b). Most practices need both, but if you already have a HIPAA certificate from somewhere else, buy the security half on its own.
HIPAA Security Awareness Training
9 modules for each person · about 62 minutes · 8 questions per module
- 01Phishing and Email Threats in a Healthcare Practice
The lookalike domain trick, the three fakes that actually arrive, and what to do in the first sixty seconds after a click.
- 02Passwords, Logins and Multi-Factor Authentication
Why unique user identification is a HIPAA requirement, not an IT preference.
- 03The Phone Call That Is Not What It Seems
Voice cloning, spoofed caller ID, and the one sentence that ends every one of these calls.
- 04Protecting Patient Information Day to Day
Screens, voices, faxes and phone cameras — where it actually leaks.
- 05Workstations, Devices and the Office Itself
Open charts, borrowed USB drives, unescorted visitors and the dumpster.
- 06Working Outside the Office: Home, Telehealth and Personal Devices
The post-emergency telehealth rules, personal cloud sync, and paper printed at home.
- 07Email, Text, Voicemail and the Patient Portal
Including the CC-field mistake that has produced some of the largest penalties against small practices anywhere.
- 08When Something Goes Wrong: Reporting and Response
The three things you do in the first five minutes, and why speed decides everything.
- 09Their role module
One of seven, assigned automatically by the role they pick when they join.
HIPAA Awareness Training
8 modules for each person · about 69 minutes · 8 questions per module
- 01HIPAA Awareness: What You May Share, and What Patients Can Ask For
Treatment, payment and operations — and everything that falls outside them.
- 02The Notice of Privacy Practices: The Promise Your Practice Made
Why a signed acknowledgement is not consent, and the five findings auditors reliably turn up.
- 03Minimum Necessary: How Much Is Too Much to Share
The whole-chart attachment, and why looking counts as a use.
- 04Records, Amendments and Restrictions: The Deadlines You Have to Meet
30 days, 60 days, cost-based fees, and the one restriction request you cannot refuse.
- 05Business Associates: The Vendors Who Hold Your Patients' Data
Including the free app nobody approved, which is the highest-risk vendor in most practices.
- 06Breach or Not: How That Decision Actually Gets Made
The four-factor risk assessment, the three exceptions, and the encryption safe harbour.
- 07When You May Share Without Asking: Police, Family, Courts and Public Health
Why an attorney's subpoena is not a court order, and does not on its own release anything.
- 08Their role module
Same seven roles, written from the privacy side.
Seven role modules
Front desk and intake · insurance, claims and billing · clinical staff and the exam room · providers and prescribers · office managers and HIPAA officers · outside labs and imaging · sterile processing and deliveries.
Graded on the server
80% to pass. Questions are shuffled and the answer key never reaches the browser, so a certificate means somebody actually knew the material.
Six-year records
Every completion is retained for the full HIPAA documentation period, and your office manager can export the whole practice to a spreadsheet at any time.
In California, the patient can sue you directly
This is the single most important thing a California practice needs to understand, and a national training course bought off the internet will not tell you about it. California has its own medical privacy law — the Confidentiality of Medical Information Act — and it works differently from HIPAA in one way that changes your whole risk picture.
Where state law is tighter, state law is what you have to meet
HIPAA is a floor, not a ceiling. Treating 60 days as a comfortable allowance is a mistake in California, and it is exactly the mistake a generic national course teaches you to make.
We are in Sacramento
Comodo Technology is a California managed IT provider serving California practices. When something happens at 7am on a Monday, you are calling a number that is answered here, not a ticket queue three time zones away.
A certificate anybody can check
Read §164.530(b) closely and you will notice the requirement is not only that you train your workforce. It is that you document it, and keep that documentation for six years. What a practice is really buying is proof.
Every certificate we issue carries a serial number, the programme it belongs to, how many of that programme's modules the person had completed, the score, the date, and the practice name — taken from the practice record, never typed by the learner. Anyone holding the serial can confirm it is genuine without an account and without contacting us.
Why the counts are frozen
"Module 4 of 9" is stamped onto the record the moment it is issued, not recalculated when someone looks at it later. When we publish a tenth module next year, that certificate still truthfully says what was true on the day. A certificate that quietly changes its own numbers is worthless as evidence.
A question worth asking any training vendor
There is no federal body that certifies HIPAA trainers. HHS states it plainly on its own site. So when a website sells you a “HIPAA certified” certificate, ask them who certified them.
What the rule actually requires you to keep is proof that a named person was trained, on a named date, that you can still produce six years later. That is precisely what this is — and you can check any one of them from this page.
Security Awareness Training & HIPAA Compliance
Check a certificate right now
This is the same public endpoint an auditor or an insurer would use. No account needed.
Four-factor breach self-check
Something went wrong. Is it a breach you have to notify patients about? Under 45 CFR §164.402 it is presumed to be one unless your practice can demonstrate a low probability that the information was compromised — and demonstrate it with a written assessment, not a feeling. Walk the four factors here.
This is a teaching tool, not a legal determination, and nothing you enter leaves your browser. The real assessment is your Privacy Officer's to make and to write down.
How identifiable is it, and how sensitive?
Who ended up holding it?
Not whether it could have been — whether it was.
Mitigation counts — but only where you can evidence it.
Answer the four factors and we will show you how the assessment reads, and what happens next either way.
The clock already started
Discovery is the first day anyone in your workforce knew, or reasonably should have known — not the day it reached the office manager. A fax nobody mentioned until Monday is already three days into the window.
(916) 740-1407Take these whether you buy anything or not
Print them, laminate them, put them where people work. They are useful on their own and we would rather you had them.
Workstation security cheat sheet
One page for the front desk and every clinical workstation.
OpenIncident response plan
Two pages. What to do in the first hour, in order, with the numbers on it.
OpenHIPAA patient rights
What patients can ask for, and the deadlines that come with each one.
OpenStaff training acknowledgement
The signed form that goes in the file. Keep it for six years.
OpenAre you a dental practice?
We have a separate portal written specifically for dental — the payer portals, the imaging systems, the lab workflow, the practice management software you actually run. Same training behind it, written in your language.
Four steps, and none of them are hard
-
1
Tell us your practice name and which programmes you want
HIPAA Security Awareness, HIPAA Awareness, or both.
-
2
We send you one join link for your practice
Forward it to everyone. Each person fills in their own name and role — your practice name comes from the link, so it is always correct on their certificate and nobody can mistype it.
-
3
They work through it at their own pace
No passwords — they get an emailed sign-in link. Progress saves, so they can stop between patients and come back.
-
4
Your office manager gets the record
Who has finished, who has not, every certificate number, exportable to a spreadsheet. That is the file you hand an auditor or an insurance questionnaire.
Talk to a person
No form that goes nowhere. These reach us.