FOR THE PRACTICE TO KEEP. Print one of these for each member of your workforce who completes the training —
employees, associates, clinical staff, assistants, front desk, billing, and any temporary or contract staff who touch patient
information. Signed copies are the evidence an auditor, an insurer, or a patient’s attorney will ask for.
1 · Practice Information
2 · Workforce Member
3 · What I Was Trained On
Recognising phishing, spoofed senders and urgent payment or records requests — and stopping to verify.
Named logins only. No shared or borrowed accounts, no written-down passwords, screens locked when I step away.
Minimum necessary: sharing only what the task requires, and the treatment exception to it.
What I may disclose for treatment, payment and operations — and what needs a signed authorisation.
Patient rights and the clocks that go with them, including the 30 days for a records request.
Never putting patient information into personal email, personal messaging, or AI and chat tools.
Sending records safely, and checking the recipient before anything leaves the practice.
Reporting a suspected incident straight away, who to call, and that reporting is never punished.
4 · Acknowledgement
By signing below I confirm that I completed the training described above; that I had the opportunity to ask
questions; and that I understand I am responsible for protecting the privacy and security of patient information in my daily
work. I understand that I must report any suspected privacy or security incident to the practice immediately, that I will not
access patient information I do not need for my job, and that these obligations continue after I stop working at this practice.
I understand that failure to follow them may lead to disciplinary action and, in some cases, to personal legal liability.
Workforce Member Signature
Printed Name & Date
Trainer / HIPAA Officer Signature
Printed Name & Date
Where this goes: keep the signed original in the practice’s HIPAA training file — not in the personnel file if your
policy separates them — for six years from the date of signature. Re-run the training and sign a fresh copy at least
annually, and whenever a material change to your systems or procedures affects how staff handle patient information.
Workforce training required under 45 CFR § 164.308(a)(5) and § 164.530(b); six-year retention under § 164.530(j).
This form is provided by Comodo Technology as a practical template for its client practices. It is not legal advice. Your
practice remains responsible for its own HIPAA policies, and state law may impose additional requirements.