HIPAA Annual Training

Annual compliance training — Record ID:

HIPAA Security & Privacy Awareness Training & Test

Required annual training for all employees of your company. Covers how a company protects patient information. This is one part of annual HIPAA training. The test result can be saved as a PDF as per HIPAA compliance.

Modules6
Quiz questions16
Passing score80%
Est. time25–35 min
0 of 6 modules reviewed

Protected Health Information (PHI) is any information that relates to a person's health, health care, or payment for health care, and that can be tied to that person — directly or indirectly.

Because our product is a website intake form and AI assistant for doctor's offices, PHI shows up constantly in our systems: patient names, appointment reasons, symptoms typed into a form, insurance details, or even a phone number tied to a patient record.

  • PHI includes obvious things (diagnosis, treatment notes) and less-obvious things (a name plus a date of an appointment, an email address tied to a patient account, or free-text notes typed into an intake field).
  • Electronic PHI (ePHI) is PHI in electronic form — which is the only kind we ever handle, since all data lives in our cloud.
  • De-identified data (with all 18 HIPAA identifiers removed) is not PHI — but de-identification must follow a specific standard, not just "removing the name."
In practice: if you're not sure whether something is PHI, treat it as PHI. When in doubt, ask the Security Officer rather than guess.

The minimum necessary standard means you only access, use, or view the PHI required to do your specific job — nothing more, out of nothing more than curiosity.

  • Every employee has a unique login. Sharing credentials, even with a coworker, is prohibited.
  • Access is role-based: your account can only see the client data your role actually requires.
  • Looking up a record you don't need for work — even if you technically have access — is a policy violation. This includes looking up your own family, friends, or anyone out of personal interest.
  • Multi-factor authentication (MFA) is required on every account with access to PHI.
Why it matters: the minimum necessary rule limits the damage of any single compromised account or mistake — it's one of the most-cited violations in real HIPAA enforcement actions.

Because we have no office, every device you use to access PHI is effectively "the office." That means the same safeguards a clinic would apply to a server room apply to your laptop.

  • Full-disk encryption must be enabled on any device used to access PHI.
  • Screens must auto-lock after a short idle period, and you must lock your screen manually when stepping away.
  • PHI may never be downloaded or stored locally outside the cloud-hosted application — no exporting to a personal spreadsheet, no screenshotting patient data, no copying into email or chat.
  • Public Wi-Fi (coffee shops, airports) requires a company-approved VPN before accessing PHI — or should be avoided for that work entirely.
  • All data is encrypted in transit (TLS) and at rest (AES-256 via our cloud servers) automatically — you don't configure this, but you should never do anything that routes PHI outside these encrypted channels (e.g., pasting patient data into an unapproved tool).

Our product includes an AI-assisted component, which raises a HIPAA question most software companies never have to answer: can PHI reach a third-party AI model?

  • PHI may only be sent to an AI/LLM provider that has signed a Business Associate Agreement (BAA) with us, or must be excluded from reaching the model entirely — check with the Security Officer if you're touching this part of the product.
  • The same rule applies to any other vendor that could touch PHI: our cloud servers, email/helpdesk tools, monitoring/logging tools. A signed BAA must exist before PHI reaches any of them.
  • Never connect a new tool, plugin, browser extension, or "quick automation" to any system that touches PHI without checking with the Security Officer first — this is the single most common way an untracked subcontractor ends up handling PHI without a BAA.
Rule of thumb: if a tool wasn't already reviewed and listed in our vendor/BAA inventory, don't feed it PHI.

A security incident is any attempted or actual unauthorized access, use, disclosure, or loss involving our systems or PHI — whether or not anything was ultimately viewed.

  • Examples: a lost or stolen laptop, a suspicious login alert, an email sent to the wrong recipient, a phishing attempt that may have captured your credentials, or noticing you can see data you shouldn't.
  • Report anything you notice to the Security Officer immediately — even if you're not sure it's serious. Reporting a false alarm has no downside; staying quiet about a real one does.
  • Do not try to "fix it quietly" yourself, and do not delete logs, emails, or files related to a possible incident — this can destroy evidence needed for the investigation.
  • Once reported, the Security Officer leads containment, investigation, a formal risk assessment, and — if it turns out to be a reportable breach — notifies the affected doctor's office client within the timeframe set in our BAA with them.

HIPAA compliance isn't just a company policy — individuals can face real consequences for violations, separate from what the company faces.

  • Violating this policy can result in disciplinary action up to and including termination, regardless of intent — though willful or repeated violations are treated more seriously than one-time accidental mistakes.
  • Some violations can also carry personal civil or criminal liability under HIPAA, particularly for willful neglect or knowing misuse of PHI.
  • You are required to complete this training annually, and immediately upon being granted access to any system with PHI.
  • Documentation of your training (this course) is retained for six years, along with a signed acknowledgment form.
Bottom line: when unsure, ask. Asking a "dumb question" about PHI handling is always the safer choice than guessing wrong.

Knowledge check

16 questions, one answer each. You need 80% (13 of 16) to pass. If you don't pass, you can retake it immediately — this isn't a one-shot test, it's a check that the material sank in.

HIPAA
TRAINED

Certificate of completion

Annual HIPAA security & privacy awareness training

This certificate documents completion of the training content. It does not replace the signed Workforce Training Acknowledgment Form — please also sign and return that form to your Security Officer so it can be filed with your six-year training records.

Built for healthcare

Patient trust starts with privacy. Ochatbot Health AI is designed to keep protected health information (PHI) secure at every step, so you can automate patient interactions with confidence.

HIPAA-compliant AI requires a signed Business Associate Agreement (BAA), and depending on your practice’s workflows, may also require additional custom development. Our team works with you to configure a compliant setup tailored to your needs.

HIPAA compliant. Your patients’ data, protected.

AI Agents built with

patients in mind

Patient safety and privacy are built into one easy-to-build and manage platform

Meet your digital front desk

An AI agent that works your website around the clock, delivering fast and reliable patient access and streamlining patient care.

Healthcare Agent Skills

Custom Forms for Intake, New Patient Meetings, and More

Walks prospective patients through your signup flow, captures their details, and routes them to your team as a qualified lead 24/7.

Lead Capture & Routing

Standard or fully custom lead forms, changing your website to a patient generation platform.

Current Patient Direction

Points existing patients to the right resource, form, or department instead of leaving them on hold.

Staff Escalation

Complex queries requiring human intervention are passed along to your team. 

FAQ Resolution

Instant answers on hours, location, insurance accepted, required documents, and what to expect. These are the questions eating up your staff’s day.

Controlled AI

Ochatbot Health AI does not provide medical advice or diagnoses. It handles scheduling, intake, and administrative questions. It always directs clinical concerns to your staff.

Responsible AI for patient conversations

Scoped

The agent answers from your practice’s own content. It doesn’t improvise, and it doesn’t provide medical advice or diagnoses.

Escalated

Clinical and sensitive questions route to your staff by design.

Ochatbot Logo

HIPAA-Compliant AI Chatbot

Ochatbot Health AI answers patient questions, signs up new patients, and points current patients to the right place — 24/7, without adding to your team’s workload. Built for medical practices and fully HIPAA compliant. A BAA is required.