Training

HIPAA Basics

What staff who handle patient health information need to know.

Talking points
  • Only access patient information you need for your specific job — "minimum necessary" is a legal requirement, not just good practice.
  • Never discuss patient information in public spaces, on personal devices, or over unsecured channels (personal email, text messages, unencrypted chat).
  • Lock your screen any time you step away from a device that can access patient data.
  • Report any suspected unauthorized access or loss of patient data immediately — HIPAA has strict, time-limited breach notification requirements.
  • Physical records (printouts, whiteboards, sticky notes) need the same care as digital records — shred, don't just discard.
Developed and supported by iConsulting — a working vCISO practice.Contact us for vCISO services →