Nationally recognized, comprehensive, Code of Federal Regulation (CFR) mapped compliance courses for Covered Entities and Business Associates. Ensure your workforce meets federal mandates, protects ePHI, and passes OCR audits.
HIPAA compliance isn't optional—it is strictly enforced by the Office for Civil Rights (OCR). Under the Code of Federal Regulations (CFR), your workforce must be trained to safeguard Protected Health Information (PHI).
45 CFR § 164.530(b) — Requires all Covered Entities to train every member of their workforce on the specific policies and procedures regarding PHI as "necessary and appropriate for them to carry out their functions."
45 CFR § 164.308(a)(5) — Mandates that both Covered Entities and Business Associates implement an ongoing security awareness and training program for the entire workforce, including management.
45 CFR § 164.530(b)(2) — New workforce members must be trained within a "reasonable period" after joining. Retraining must occur immediately following any "material change" to your organization’s policies or procedures. Based on healthcare sector best practices, HIPAA Security Awareness & Privacy Training should be provided on an annual basis.
Backed by over 100 years of combined experience in law enforcement, regulatory compliance, inspections, and health information privacy, Colington Consulting delivers modern courses updated for the latest OCR enforcement trends.
Gain unlimited, 24/7 digital access to our comprehensive training courses. Tiered pricing is determined entirely by the number of users in your organization. Keep your staff continuously updated on electronic security and privacy protocols.
Need your entire workforce certified simultaneously? We deliver live, interactive training sessions via Microsoft Teams or onsite, complete with a dedicated Q&A session. Can be scheduled and deployed with just a few days' notice.
We develop tailored HIPAA training curriculum that integrates your organization's specific internal security policies, data escalation procedures, and operational workflows.
Our courses ensure your team handles data correctly, minimizing the operational and financial risks of data breaches, medical identity theft, and severe regulatory fines.
When the government reviews your compliance, missing or lax training records trigger immediate penalties. Colington Consulting was founded by Jay Hodes, the former HIPAA Compliance Officer for Fairfax County, VA. Jay designed a massive, county-wide training framework and leverages that exact primary-source regulatory experience to build ironclad training programs for your healthcare practice or business.

Please reach us at info@cchipaa.com if you cannot find an answer to your question.
While the text of 45 CFR § 164.530(b) and 45 CFR § 164.308(a)(5) uses terms like "periodic updates" and training upon "material changes" rather than an explicit "annual" timeline, federal regulators (OCR) and industry best practices dictate that comprehensive training be conducted at least annually to satisfy continuous compliance and mitigate data breach liabilities.
Yes. Under 45 CFR § 164.308(a)(5), the Security Awareness and Training standard applies directly to Business Associates and their entire workforce to ensure the confidentiality, integrity, and availability of electronic PHI (ePHI).
In accordance with 45 CFR § 164.530(j), all compliance documentation, including employee training rosters, completion certificates, and curriculum records, must be securely retained for a minimum of 6 years from the date of creation or the date it was last in effect.
Schedule a call with Jay Hodes to discuss training options for your practice or company.
Colington Consulting
Burke, Fairfax County, VA USA