3 Effective HIPAA Training Methods
Effective HIPAA training methods help prevent avoidable privacy violations and data breaches by increasing the amount of HIPAA knowledge retained by members of the workforce and by reducing carelessness – the number 1 cause of data breaches in healthcare. However, many HIPAA training methods used over the past two decades have been far from effective.
HIPAA training became mandatory for HIPAA covered entities in 2002, since when HHS’ Office for Civil Rights has received more than 100,000 justified privacy complaints. As privacy complaints can also be made directly to HIPAA covered entities, the total number of justified privacy complaints is likely much higher. However, nobody knows for sure, because – unlike data breaches – HIPAA covered entities are not required to report privacy complaints.
With regards to data breaches, HIPAA covered entities have been required to notify HHS’ Office for Civil Rights of data breaches and impermissible disclosures of unsecured Protected Health Information (PHI) since the effective date of the Interim Breach Notification Final Rule in 2009. Up to December 2022 (the most recent year for which data is available), HHS’ Office for Civil Rights received more than 680,000 notifications of data breaches or impermissible disclosures.
Why So Many HIPAA Data Breaches?
Due to a lack of transparency in data breach notifications, it is impossible to determine the exact reason for there being so many HIPAA data breaches. However, by “reading between the lines” of the web descriptions in the HHS Breach Report Archive, it is possible to surmise that the majority of HIPAA data breaches are attributable to a lack of knowledge or a lack of care.
The lack of knowledge is evident by the number of HIPAA data breaches attributable to weak passwords and user interactions with phishing emails. These data breaches are usually described as “cyberattacks” or “ransomware attacks” in the Breach Report web descriptions, but most cyberattacks and ransomware attacks involve a human element (68% according to the 2024 Verizon DBIR Report).
In the healthcare industry, the percentage of data breaches that involve a human element increases to 83% (according to Verizon) due to “lack of care” issues such as misdeliveries of emails, losses of devices, and misconfigurations. In addition, Verizon has a category for “gaffes”, which it describes as “when people simply blurt out sensitive data in the hearing of others”. Privilege misuse by malicious insiders is also a notable cause of data breaches in healthcare.
Why the Human Element is Higher in Healthcare
It has long been understood that healthcare data is targeted by cybercriminals because it can be used – or resold – for purposes such as medical identity theft, healthcare fraud, and tax fraud. These crimes are not only harder to detect, but can continue for much longer than other types of data misuse. For example, it is possible to detect and resolve credit card fraud within minutes. It may take years to detect and resolve medical identity theft.
However, this does not explain why the human element in healthcare data breaches is higher than in other industries. While it is true that cybercriminals may use more sophisticated techniques to obtain healthcare data, and that there are more attack surfaces in healthcare than in other industries, a lack of knowledge, carelessness, misdeliveries, losses, and misconfigurations potentially account for more than 40,000 avoidable data breaches per year.
One likely culprit is HIPAA training. It is not necessarily the case that HIPAA covered entities are failing to provide the “required” training. It is more likely the case that the HIPAA training requirements can leave gaps in workforce members’ HIPAA knowledge and can be misinterpreted so that the nature of security awareness training is generic rather than being tailored to protect against anticipated threats to – and impermissible disclosures of – PHI. The HIPAA Journal is the top online HIPAA training provider and has a reputation for providing comprehensive and relevant HIPAA training.
The Issues with the HIPAA Training Requirements
There are two primary issues with the HIPAA training requirements. The first is that the HIPAA Privacy Rule training standard requires HIPAA covered entities to train members of the workforce on policies and procedures with respect to PHI “as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity”.
This implies that, if a workforce member does not need to know about (for example) the privacy protections allowed by §164.522(a) of the HIPAA Privacy Rule in order to carry out their functions, the workforce member will not know to check whether privacy protections exist before (impermissibly in this example) disclosing a patient’s PHI to a third party.
The second issue with the HIPAA training requirements is that the HIPAA Security Rule training standard requires HIPAA covered entities to implement a security awareness and training program for all members of the workforce. However, this Administrative Safeguard must be implemented “in accordance with §164.306” – the HIPAA Security Rule General Requirements.
The HIPAA Security Rule General Requirements stipulate that the implementation of Administrative, Physical, and Technical Safeguards must (among other requirements) protect against any reasonably anticipated threats to the security or integrity of electronic PHI and protect against any reasonably anticipated uses or disclosures of PHI that are not permitted or required by the HIPAA Privacy Rule.
HIPAA covered entities that fail to implement security awareness and training programs that take the General Requirements into account – and that only provide generic security awareness training – are not only violating HIPAA, but they are also limiting the effectiveness of HIPAA training by not making it relevant to healthcare data. This is one of the most reasonable explanations of why there are so many avoidable HIPAA data breaches.
3 Effective HIPAA Training Methods
For most HIPAA covered entities, overhauling existing HIPAA training programs to extend HIPAA Privacy Rule training to more members of the workforce and redesigning HIPAA Security Rule training to incorporate the General Requirements may be too complicated. However, it may be possible to improve existing HIPAA training by supporting it with these three effective HIPAA training methods.
HIPAA Awareness Training
HIPAA awareness training is training that provides a holistic view of HIPAA by explaining what the purpose of HIPAA is, what it protects, and why HIPAA compliance is important. It can be used to provide all members of the workforce with an overview of permissible uses and disclosures of PHI, the minimum necessary standard, and patients’ rights. It can also be used to explain why healthcare data is targeted by cybercriminals and the sophisticated techniques that are used.
The provision of HIPAA awareness training is one of the most effective HIPAA training methods when it is provided prior to “required” policy and procedure training and security awareness training. This is because it introduces trainees to the terms they will encounter in policy and procedure training and security awareness training – making the “required” HIPAA training more understandable and thereby enhancing trainees’ HIPAA knowledge.
Really Engaging Security Training
Most sources advocate engagement as one of the most effective HIPAA training methods. But, with so much other training required in healthcare, HIPAA training has to be really engaging to make it stand out. One of the best ways to make security training really engaging is to hack – or appear to hack – a trainee’s personal social media account and then take it over. Naturally, this will require the permission of the trainee, but it is not too difficult to organize.
Simply set up a fake account in the trainee’s name with their profile and posts lifted from the trainee’s genuine social media account. Then explain to the other trainees that you are going to lift clues from the posts to hack the password for the account. Once access to the fake account is established, post a new message tagging the social media aliases of as many trainees as possible so they can see how easy it is for a cybercriminal to socially engineer contacts.
What if It Was Your Mom?
One of the most effective HIPAA training methods to reduce carelessness is to personalize the real consequences of healthcare data breaches. This means that, rather than focus on sanctions as the consequences of non-compliance, focus on the operational and personal consequences of data breaches and potential delays in the delivery of care when organizations adopt remediation efforts to prevent future data breaches and impermissible disclosures.
Most trainees will have friends or family members whose healthcare data is maintained by the organization. Connecting the real consequences of healthcare data breaches to how they might impact friends and family members is likely to make trainees take more care when handling PHI in order to prevent many types of avoidable data breaches and impermissible disclosures. It may also make potential malicious insiders think twice before misusing their privileges.
Why it is Important to Refresh HIPAA Training
It was mentioned above that there is a lot of training in healthcare. In addition to HIPAA training, workforce members may be required to earn Continuing Education Units (CEUs) towards license renewals, participate in annual OSHA bloodborne pathogen training, and be involved in CMS’ Emergency Planning exercises. Many states also have mandatory sexual harassment and/or workplace violence training requirements – some of which have to be repeated annually.
Therefore, although many sources advocate annual HIPAA refresher training as well as ongoing security awareness training. The HIPAA Journal offers HIPAA refresher training to help healthcare professionals stay up to date with current regulations and best practices. The training is designed to reinforce key HIPAA concepts and support ongoing compliance efforts in a practical and accessible format. It includes testing and certification to confirm understanding, and Continuing Education Units (CEUs) are available to support professional development. The above three effective HIPAA training methods should help HIPAA training be more easily understood, more memorable, and better retained to help prevent avoidable data breaches and impermissible disclosures.
