Annual compliance training — Record ID:
HIPAA Security & Privacy Awareness Training & Test
Required annual training for all employees of your company. Covers how a company protects patient information. This is one part of annual HIPAA training. The test result can be saved as a PDF as per HIPAA compliance.
Protected Health Information (PHI) is any information that relates to a person's health, health care, or payment for health care, and that can be tied to that person — directly or indirectly.
Because our product is a website intake form and AI assistant for doctor's offices, PHI shows up constantly in our systems: patient names, appointment reasons, symptoms typed into a form, insurance details, or even a phone number tied to a patient record.
- PHI includes obvious things (diagnosis, treatment notes) and less-obvious things (a name plus a date of an appointment, an email address tied to a patient account, or free-text notes typed into an intake field).
- Electronic PHI (ePHI) is PHI in electronic form — which is the only kind we ever handle, since all data lives in our cloud.
- De-identified data (with all 18 HIPAA identifiers removed) is not PHI — but de-identification must follow a specific standard, not just "removing the name."
The minimum necessary standard means you only access, use, or view the PHI required to do your specific job — nothing more, out of nothing more than curiosity.
- Every employee has a unique login. Sharing credentials, even with a coworker, is prohibited.
- Access is role-based: your account can only see the client data your role actually requires.
- Looking up a record you don't need for work — even if you technically have access — is a policy violation. This includes looking up your own family, friends, or anyone out of personal interest.
- Multi-factor authentication (MFA) is required on every account with access to PHI.
Because we have no office, every device you use to access PHI is effectively "the office." That means the same safeguards a clinic would apply to a server room apply to your laptop.
- Full-disk encryption must be enabled on any device used to access PHI.
- Screens must auto-lock after a short idle period, and you must lock your screen manually when stepping away.
- PHI may never be downloaded or stored locally outside the cloud-hosted application — no exporting to a personal spreadsheet, no screenshotting patient data, no copying into email or chat.
- Public Wi-Fi (coffee shops, airports) requires a company-approved VPN before accessing PHI — or should be avoided for that work entirely.
- All data is encrypted in transit (TLS) and at rest (AES-256 via our cloud servers) automatically — you don't configure this, but you should never do anything that routes PHI outside these encrypted channels (e.g., pasting patient data into an unapproved tool).
Our product includes an AI-assisted component, which raises a HIPAA question most software companies never have to answer: can PHI reach a third-party AI model?
- PHI may only be sent to an AI/LLM provider that has signed a Business Associate Agreement (BAA) with us, or must be excluded from reaching the model entirely — check with the Security Officer if you're touching this part of the product.
- The same rule applies to any other vendor that could touch PHI: our cloud servers, email/helpdesk tools, monitoring/logging tools. A signed BAA must exist before PHI reaches any of them.
- Never connect a new tool, plugin, browser extension, or "quick automation" to any system that touches PHI without checking with the Security Officer first — this is the single most common way an untracked subcontractor ends up handling PHI without a BAA.
A security incident is any attempted or actual unauthorized access, use, disclosure, or loss involving our systems or PHI — whether or not anything was ultimately viewed.
- Examples: a lost or stolen laptop, a suspicious login alert, an email sent to the wrong recipient, a phishing attempt that may have captured your credentials, or noticing you can see data you shouldn't.
- Report anything you notice to the Security Officer immediately — even if you're not sure it's serious. Reporting a false alarm has no downside; staying quiet about a real one does.
- Do not try to "fix it quietly" yourself, and do not delete logs, emails, or files related to a possible incident — this can destroy evidence needed for the investigation.
- Once reported, the Security Officer leads containment, investigation, a formal risk assessment, and — if it turns out to be a reportable breach — notifies the affected doctor's office client within the timeframe set in our BAA with them.
HIPAA compliance isn't just a company policy — individuals can face real consequences for violations, separate from what the company faces.
- Violating this policy can result in disciplinary action up to and including termination, regardless of intent — though willful or repeated violations are treated more seriously than one-time accidental mistakes.
- Some violations can also carry personal civil or criminal liability under HIPAA, particularly for willful neglect or knowing misuse of PHI.
- You are required to complete this training annually, and immediately upon being granted access to any system with PHI.
- Documentation of your training (this course) is retained for six years, along with a signed acknowledgment form.
Knowledge check
16 questions, one answer each. You need 80% (13 of 16) to pass. If you don't pass, you can retake it immediately — this isn't a one-shot test, it's a check that the material sank in.
HIPAA Training — Quiz Results
TRAINED
Certificate of completion
Annual HIPAA security & privacy awareness training
This certificate documents completion of the training content. It does not replace the signed Workforce Training Acknowledgment Form — please also sign and return that form to your Security Officer so it can be filed with your six-year training records.
Built for healthcare
Patient trust starts with privacy. Ochatbot Health AI is designed to keep protected health information (PHI) secure at every step, so you can automate patient interactions with confidence.
HIPAA-compliant AI requires a signed Business Associate Agreement (BAA), and depending on your practice’s workflows, may also require additional custom development. Our team works with you to configure a compliant setup tailored to your needs.
HIPAA compliant. Your patients’ data, protected.
AI Agents built with
patients in mind
Patient safety and privacy are built into one easy-to-build and manage platform
Meet your digital front desk
An AI agent that works your website around the clock, delivering fast and reliable patient access and streamlining patient care.
Healthcare Agent Skills
Custom Forms for Intake, New Patient Meetings, and More
Walks prospective patients through your signup flow, captures their details, and routes them to your team as a qualified lead 24/7.
Lead Capture & Routing
Standard or fully custom lead forms, changing your website to a patient generation platform.
Current Patient Direction
Points existing patients to the right resource, form, or department instead of leaving them on hold.
Staff Escalation
Complex queries requiring human intervention are passed along to your team.
FAQ Resolution
Instant answers on hours, location, insurance accepted, required documents, and what to expect. These are the questions eating up your staff’s day.
Controlled AI
Ochatbot Health AI does not provide medical advice or diagnoses. It handles scheduling, intake, and administrative questions. It always directs clinical concerns to your staff.
Responsible AI for patient conversations
Scoped
The agent answers from your practice’s own content. It doesn’t improvise, and it doesn’t provide medical advice or diagnoses.
Escalated
Clinical and sensitive questions route to your staff by design.
HIPAA-Compliant AI Chatbot
Ochatbot Health AI answers patient questions, signs up new patients, and points current patients to the right place — 24/7, without adding to your team’s workload. Built for medical practices and fully HIPAA compliant. A BAA is required.