Sacramento & Northern California
Support & security emergency: (916) 740-1407 hipaa@comodotechnology.com
COMODO TECHNOLOGY

Security Awareness Training & HIPAA Compliance

Home The training Pricing Who it's for CMIA Certificate Breach check Handouts
Built for California practices

HIPAA and security training your staff will actually finish — and your auditor can actually verify.

Short modules written for the way a medical practice really runs. Every person who passes gets a dated certificate with a serial number anyone can check online. That record is what HIPAA actually asks you to keep — and it is the thing most training providers do not give you.

Comodo Technology is a Sacramento managed IT provider. We have supported California healthcare practices through real incidents, and this training is written from that experience rather than from a template.

At a glance
Two programmes, 17 modules
HIPAA Security Awareness and HIPAA Awareness. Buy one or both.
6–9 minutes a module
Done between patients. Progress saves as they go.
Assigned by role
Front desk, billing, clinical, providers, managers, lab, sterile processing.
Publicly verifiable certificates
Serial number, programme, modules completed, date. Try one below.
Covers California CMIA
Not just federal HIPAA. This is the part that gets California practices sued.
Who this is for

If you hold patient records, this applies to you

HIPAA does not have a version for large hospitals and a lighter one for a three-person office. The obligations are the same. What changes is that a small practice has no compliance department, no IT person in the building, and a front desk being interrupted every ninety seconds. The training is written for that reality.

Family & internal medicine
Urgent care
Optometry & ophthalmology
Podiatry
Chiropractic & physical therapy
Behavioral & mental health
Dermatology & med spa
Pediatrics & OB-GYN
Home health & hospice
Imaging centers
Labs & pathology
DME & billing companies

Billing companies, labs, transcription and IT vendors: you are a business associate, not a covered entity, and you are directly liable under HITECH for parts of the Security Rule. You need this training too, and your clients are increasingly asking you to prove you have it. We issue you the same verifiable certificates.

The training

Two programmes. Take one, or both.

They answer two different questions. HIPAA Security Awareness is about protecting the systems — §164.308(a)(5). HIPAA Awareness is about what you are allowed to say, to whom, and what patients can demand of you — §164.530(b). Most practices need both, but if you already have a HIPAA certificate from somewhere else, buy the security half on its own.

HIPAA Security Awareness Training

9 modules for each person · about 62 minutes · 8 questions per module

  1. 01
    Phishing and Email Threats in a Healthcare Practice

    The lookalike domain trick, the three fakes that actually arrive, and what to do in the first sixty seconds after a click.

  2. 02
    Passwords, Logins and Multi-Factor Authentication

    Why unique user identification is a HIPAA requirement, not an IT preference.

  3. 03
    The Phone Call That Is Not What It Seems

    Voice cloning, spoofed caller ID, and the one sentence that ends every one of these calls.

  4. 04
    Protecting Patient Information Day to Day

    Screens, voices, faxes and phone cameras — where it actually leaks.

  5. 05
    Workstations, Devices and the Office Itself

    Open charts, borrowed USB drives, unescorted visitors and the dumpster.

  6. 06
    Working Outside the Office: Home, Telehealth and Personal Devices

    The post-emergency telehealth rules, personal cloud sync, and paper printed at home.

  7. 07
    Email, Text, Voicemail and the Patient Portal

    Including the CC-field mistake that has produced some of the largest penalties against small practices anywhere.

  8. 08
    When Something Goes Wrong: Reporting and Response

    The three things you do in the first five minutes, and why speed decides everything.

  9. 09
    Their role module

    One of seven, assigned automatically by the role they pick when they join.

HIPAA Awareness Training

8 modules for each person · about 69 minutes · 8 questions per module

  1. 01
    HIPAA Awareness: What You May Share, and What Patients Can Ask For

    Treatment, payment and operations — and everything that falls outside them.

  2. 02
    The Notice of Privacy Practices: The Promise Your Practice Made

    Why a signed acknowledgement is not consent, and the five findings auditors reliably turn up.

  3. 03
    Minimum Necessary: How Much Is Too Much to Share

    The whole-chart attachment, and why looking counts as a use.

  4. 04
    Records, Amendments and Restrictions: The Deadlines You Have to Meet

    30 days, 60 days, cost-based fees, and the one restriction request you cannot refuse.

  5. 05
    Business Associates: The Vendors Who Hold Your Patients' Data

    Including the free app nobody approved, which is the highest-risk vendor in most practices.

  6. 06
    Breach or Not: How That Decision Actually Gets Made

    The four-factor risk assessment, the three exceptions, and the encryption safe harbour.

  7. 07
    When You May Share Without Asking: Police, Family, Courts and Public Health

    Why an attorney's subpoena is not a court order, and does not on its own release anything.

  8. 08
    Their role module

    Same seven roles, written from the privacy side.

Seven role modules

Front desk and intake · insurance, claims and billing · clinical staff and the exam room · providers and prescribers · office managers and HIPAA officers · outside labs and imaging · sterile processing and deliveries.

Graded on the server

80% to pass. Questions are shuffled and the answer key never reaches the browser, so a certificate means somebody actually knew the material.

Six-year records

Every completion is retained for the full HIPAA documentation period, and your office manager can export the whole practice to a spreadsheet at any time.

California

In California, the patient can sue you directly

This is the single most important thing a California practice needs to understand, and a national training course bought off the internet will not tell you about it. California has its own medical privacy law — the Confidentiality of Medical Information Act — and it works differently from HIPAA in one way that changes your whole risk picture.

  Federal HIPAA California CMIA
Can a patient sue you? No. They complain to the Office for Civil Rights, which decides whether to act. Yes. A private right of action — they can sue the practice directly.
Do they have to prove you meant it? Enforcement weighs willfulness in deciding penalties. No. A negligent disclosure is enough. Nobody has to have intended anything.
Does it reach your vendors? Business associates are directly liable for parts of the rules. Yes, CMIA reaches contractors too — so a vendor's mistake becomes a litigation question, not only a compliance one.
How fast must you notify? Without unreasonable delay, and no later than 60 days from discovery. In the most expedient time possible, without unreasonable delay. No 60-day allowance is written into it.

Where state law is tighter, state law is what you have to meet

HIPAA is a floor, not a ceiling. Treating 60 days as a comfortable allowance is a mistake in California, and it is exactly the mistake a generic national course teaches you to make.

We are in Sacramento

Comodo Technology is a California managed IT provider serving California practices. When something happens at 7am on a Monday, you are calling a number that is answered here, not a ticket queue three time zones away.

The actual product

A certificate anybody can check

Read §164.530(b) closely and you will notice the requirement is not only that you train your workforce. It is that you document it, and keep that documentation for six years. What a practice is really buying is proof.

Every certificate we issue carries a serial number, the programme it belongs to, how many of that programme's modules the person had completed, the score, the date, and the practice name — taken from the practice record, never typed by the learner. Anyone holding the serial can confirm it is genuine without an account and without contacting us.

Why the counts are frozen

"Module 4 of 9" is stamped onto the record the moment it is issued, not recalculated when someone looks at it later. When we publish a tenth module next year, that certificate still truthfully says what was true on the day. A certificate that quietly changes its own numbers is worthless as evidence.

A question worth asking any training vendor

There is no federal body that certifies HIPAA trainers. HHS states it plainly on its own site. So when a website sells you a “HIPAA certified” certificate, ask them who certified them.

What the rule actually requires you to keep is proof that a named person was trained, on a named date, that you can still produce six years later. That is precisely what this is — and you can check any one of them from this page.

COMODO TECHNOLOGY

Security Awareness Training & HIPAA Compliance

Certificate of Completion
Maria Delgado
has completed
HIPAA Awareness Training
Module 4 of 8
Records, Amendments and Restrictions
Delgado Family Medical Group
CT-2026-AC44C014
Completed 14 September 2026Score 100%Issued by Comodo TechnologyComodo Technology · HIPAA and security awareness training for healthcare practices · Sacramento, California

Check a certificate right now

This is the same public endpoint an auditor or an insurer would use. No account needed.

Free tool

Four-factor breach self-check

Something went wrong. Is it a breach you have to notify patients about? Under 45 CFR §164.402 it is presumed to be one unless your practice can demonstrate a low probability that the information was compromised — and demonstrate it with a written assessment, not a feeling. Walk the four factors here.

This is a teaching tool, not a legal determination, and nothing you enter leaves your browser. The real assessment is your Privacy Officer's to make and to write down.

1. What information was involved?

How identifiable is it, and how sensitive?

2. Who was the unauthorised person?

Who ended up holding it?

3. Was it actually acquired or viewed?

Not whether it could have been — whether it was.

4. How far has the risk been mitigated?

Mitigation counts — but only where you can evidence it.

Answer the four factors and we will show you how the assessment reads, and what happens next either way.

The clock already started

Discovery is the first day anyone in your workforce knew, or reasonably should have known — not the day it reached the office manager. A fax nobody mentioned until Monday is already three days into the window.

(916) 740-1407
Free, no sign-up

Take these whether you buy anything or not

Print them, laminate them, put them where people work. They are useful on their own and we would rather you had them.

Are you a dental practice?

We have a separate portal written specifically for dental — the payer portals, the imaging systems, the lab workflow, the practice management software you actually run. Same training behind it, written in your language.

Dental portal
Getting started

Four steps, and none of them are hard

  1. 1
    Tell us your practice name and which programmes you want

    HIPAA Security Awareness, HIPAA Awareness, or both.

  2. 2
    We send you one join link for your practice

    Forward it to everyone. Each person fills in their own name and role — your practice name comes from the link, so it is always correct on their certificate and nobody can mistype it.

  3. 3
    They work through it at their own pace

    No passwords — they get an emailed sign-in link. Progress saves, so they can stop between patients and come back.

  4. 4
    Your office manager gets the record

    Who has finished, who has not, every certificate number, exportable to a spreadsheet. That is the file you hand an auditor or an insurance questionnaire.