I have spent twenty five years in network security and fifteen of those running a managed services company. In that time I have sat across the desk from more than one practice manager on the day a data request letter arrived from the HHS Office for Civil Rights, and from a few who had an OSHA compliance officer standing in the sterilization area asking to see the exposure control plan.
Here is the thing that surprises people every single time. Neither the OCR investigator nor the OSHA compliance officer asks whether you take privacy seriously. They do not ask whether your team is careful. They ask for documents. Specific documents, with names on them and dates on them, covering a specific period of time. What you believe about your practice culture is not evidence. A signed roster is evidence.
This post is written for the person who has to produce that paperwork, which in a small medical or dental practice is almost always the office manager or the person wearing the compliance officer hat on top of three other hats. My goal is to tell you what the two agencies actually require, what they actually ask for when they show up, where HIPAA and OSHA training overlap in ways that trip staff up, and where training honestly will not save you.
Two agencies, four separate training obligations
A small practice with clinical staff is subject to at least four distinct workforce training requirements. They live in different regulations, they run on different clocks, and they generate different records. Most practices I audit treat them as one blurry annual event, which is exactly how gaps form.
| Requirement | Citation | When it is due | Record retention |
|---|---|---|---|
| HIPAA Privacy Rule training on your policies and procedures | 45 CFR 164.530(b) | To each new workforce member within a reasonable time after hire, and to affected staff within a reasonable time after a material change to your policies | Six years |
| HIPAA Security Rule security awareness and training program | 45 CFR 164.308(a)(5) | Ongoing program for all workforce members including management, with security reminders, malware protection, log-in monitoring and password management addressed | Six years |
| OSHA bloodborne pathogens training | 29 CFR 1910.1030(g)(2) | At initial assignment to tasks with occupational exposure, then at least annually, within one year of the previous session | Three years |
| OSHA hazard communication training | 29 CFR 1910.1200(h) | At initial assignment, and whenever a new chemical hazard staff have not been trained on is introduced | No fixed federal interval |
Read that table again and notice which column is the surprising one. The word “annually” appears in the OSHA bloodborne pathogens standard. It does not appear in the text of either HIPAA training provision, and it does not appear in the hazard communication standard either.
That trips up practices in both directions. Some skip HIPAA refreshers because the rule never uses the word annual. Others burn budget on an annual hazard communication module the standard never asked for, while their bloodborne pathogens session quietly slides from January to March to the following June, which is a real violation because OSHA has interpreted the annual requirement as within one year of the previous training.
So why does everyone do HIPAA training annually anyway?
Because of the documentation rules, not the training rules. HIPAA requires you to retain the required documentation for six years from the date of creation or the date it was last in effect, whichever is later. When OCR opens an investigation, it asks for the training history covering the relevant period. If your last dated roster is from four years ago, you are not technically in violation of a training frequency requirement that does not exist, but you are handing an investigator a six year window with a four year hole in it. Nobody wins that argument.
An annual cadence is the defensible answer, not because the regulation demands it, but because it produces an unbroken evidence trail and it happens to line up with the bloodborne pathogens clock you are already required to keep.
What OCR actually asks for
On April 23, 2026, OCR announced settlements with four regulated entities following separate ransomware investigations, collectively affecting more than 427,000 individuals, with a total of $1,165,000 paid and two year corrective action plans across the board. One of those cases, a third party benefits administrator, traced back to a successful phishing attack in July 2020 that gave the attacker access to a server holding electronic protected health information.
What matters for our purposes is the list OCR published at the bottom of that release. It is the agency describing, in its own words, what it expects regulated entities to be doing. The last item on the list is the one to write on a sticky note.
OCR’s published recommendations following the April 2026 ransomware settlements:
- Identify where ePHI lives and how it enters, moves through, and leaves your systems.
- Periodically conduct and update a risk analysis, and implement a risk management plan that addresses what it found.
- Put audit controls in place and actually review system activity.
- Authenticate users so only authorized people reach ePHI.
- Encrypt ePHI in transit and at rest where appropriate.
- Feed lessons learned from incidents back into your security management process.
- Provide workforce members with regular HIPAA training that is specific to the organization and to each workforce member’s job duties.
Specific to the organization. Specific to job duties. That phrasing is deliberate and it is the single most useful sentence OCR has published about training in years.
It also happens to describe the opposite of what most small practices buy. The typical purchase is a generic twenty minute video that explains what PHI stands for, tells a story about a hospital in another state, issues a certificate, and gets filed. That module is not worthless. It is just not responsive to the question OCR is asking, because nothing in it mentions your practice management system, your patient portal, your fax workflow, your check-in desk layout, your after-hours answering service, or the specific vendors who touch your data.
What organization-specific and role-specific looks like in practice
- Your front desk staff train on your check-in workflow, your sign-in sheet policy, your portal enrollment steps, and what to do when a family member calls asking about a patient.
- Your clinical staff train on your EHR access rules, your minimum necessary standard as it applies to chart access, and the specific rule about looking up coworkers and neighbors.
- Your billing staff train on your clearinghouse, your statements vendor, and what a legitimate payer request looks like versus a pretext call.
- Everyone trains on your incident reporting path, by name. Who do they call, on what number, at 4:45 on a Friday.
- Everyone with a mailbox trains on the phishing patterns aimed at your practice, not at a Fortune 500.
You can absolutely use a purchased module as the base layer. Add fifteen minutes of practice-specific content on top of it, document that fifteen minutes with an agenda and a roster, and you have moved from generic to responsive. We went deeper on whether awareness training earns its keep in Does Employee Cybersecurity Training Actually Work?
What the breach data actually supports, and what it does not
Verizon’s 2026 Data Breach Investigations Report tracked 1,492 healthcare incidents, of which 1,438 were confirmed data disclosures. The human element was present in 54 percent of healthcare breaches. Phishing accounted for 14 percent of known initial access, behind exploitation of vulnerabilities at 20 percent and ahead of credential abuse at 11 percent. Third parties were involved in 32 percent of healthcare breaches.
The most durable finding in that report, and the one relevant to a training conversation, is that the Miscellaneous Errors pattern has been in healthcare’s top three every year Verizon has tracked it, going back to 2014. This year the leading error types were misdelivery, meaning information sent to the wrong recipient in any format, loss of devices and portable media, and misconfiguration.
One caveat, because this is where vendor marketing tends to overreach. The DBIR is a contributor-driven dataset, not a random sample of American medical and dental practices. Small independent practices are almost certainly underrepresented, because a two provider office that gets hit rarely retains a forensics firm that reports into the corpus. Read those percentages as a picture of the sector’s reported breaches, not as a prevalence rate for your office.
And be honest about what the error numbers mean. Misdelivery has sat near the top of healthcare’s list for over a decade despite an entire industry of annual awareness training. Sending a chart to the wrong fax number is only partly a knowledge problem. It is also a system design problem, fixed by a two person check on bulk records releases, a confirmation step before a portal message goes out, purging stale fax destinations from the address book, and encrypting devices so a loss stops being a reportable breach. Training makes those controls stick. It does not substitute for them.
Where HIPAA and OSHA collide, and why it matters at the front desk
This is the section I wish more practices asked about, because the mistake I see is not a security mistake. It is a confident misapplication of HIPAA to a situation HIPAA does not govern.
The HIPAA definition of protected health information at 45 CFR 160.103 expressly excludes employment records held by a covered entity in its role as employer. Your practice is a covered entity for your patients. For your own staff, you are an ordinary employer. That distinction has real consequences.
| Record | Is it PHI? | What that means in practice |
|---|---|---|
| OSHA 300 and 301 injury logs | No. Employment record. | HIPAA does not govern them. Staff should not refuse to complete or produce them citing HIPAA. |
| Hepatitis B vaccination status and declination forms for staff | No. Employment record held for workplace safety. | Still confidential under other law. Store separately from the general personnel file, restrict access. |
| Sharps injury log | No, but confidentiality is required by OSHA itself. | The log must be maintained so the injured employee’s identity is protected. |
| A staff member treated as a patient in your own office after an exposure | Yes. That is a treatment record. | This is the one that blurs. The clinical record is PHI. What goes into the employment file is not the same document. |
| Patient charts, portal messages, claims data | Yes. | Full Privacy and Security Rule obligations apply. |
The failure mode runs both ways, and both directions are common. In one direction, a staff member refuses to give the safety coordinator the information needed to complete an OSHA log because someone told them everything medical is HIPAA. In the other direction, employee exposure paperwork gets handled casually and left in an unlocked drawer, because someone concluded that if it is not PHI then nothing applies. Both are wrong. The employment records carve-out removes HIPAA from the picture. It does not remove the Americans with Disabilities Act, the Genetic Information Nondiscrimination Act, Florida law, or basic decency.
In a practice of eight people, the privacy officer and the safety officer are usually the same person. That is fine. It becomes a problem only when the two jobs run on separate calendars, in separate binders, with separate vendors, and nobody has ever sat down and mapped which record answers which agency.
The evidence file: what to be able to hand over in ten minutes
If you build nothing else out of this post, build this. One folder, digital or physical, that a covering staff member could produce without you in the building.
- A written training policy stating who gets trained, on what, on what schedule, and who signs off.
- Dated attendance rosters with printed names and job titles, not just a completion dashboard. OCR sample requests routinely go past the summary view to the underlying records.
- A copy or summary of the content delivered, with a version or date, so you can show what was actually taught in a given year.
- For bloodborne pathogens sessions, the trainer’s name and qualifications. The standard requires this and it is the detail most often missing.
- Evidence of the interactive component. The bloodborne pathogens standard requires an opportunity for interactive questions and answers with a knowledgeable person. A recorded video with no path to a live question does not satisfy it on its own.
- Records of material policy changes and the retraining that followed, which is what actually triggers HIPAA privacy retraining under 164.530(b).
- Your written exposure control plan, reviewed and updated at least annually, and your written hazard communication program.
- Your sanction policy, and any sanctions actually applied, which HIPAA requires you to document.
A practical simplification: OSHA wants bloodborne pathogens training records kept three years. HIPAA wants its documentation kept six. Do not run two retention clocks in a small office. Keep everything for six years and stop thinking about it.
On the OSHA side, the financial exposure is easy to look up. As published on OSHA’s penalties page, the maximum is $16,550 per serious or other than serious violation and $165,514 per willful or repeated violation, with failure to abate running up to $16,550 per day beyond the abatement date. Those are maximums, and OSHA applies substantial reductions for small employers and for demonstrated good faith. A complete, dated training file is a large part of what “good faith” looks like on paper.
What training does not fix
I sell security awareness training as part of what my company does, so take this section as the disclosure it is. I would rather you buy it with accurate expectations than buy it believing it does something it does not.
- Training does not patch a server. Exploitation of vulnerabilities is now the leading known initial access vector in the DBIR dataset overall, and accounted for 20 percent in healthcare. No amount of phishing awareness closes an unpatched perimeter appliance.
- Training does not govern your vendors. Third parties were involved in 32 percent of healthcare breaches. Your staff cannot be trained into your billing vendor having multifactor authentication.
- Phishing simulation scores measure recall, not resilience. They are useful as a trend and as a way to identify who needs a conversation. They are not a security metric. In the 2026 DBIR, click rates on mobile-centric lures such as voice and text ran about 40 percent higher than email, and most simulation programs never test that channel at all.
- Training will not, by itself, satisfy OCR. In all four of the April 2026 ransomware settlements, the root finding was failure to conduct an accurate and thorough risk analysis. Training appears in the corrective action plans, but risk analysis is what the agency leads with, every time. If you have a perfect training binder and no current written risk analysis, you have solved the wrong problem first.
- An annual module competes with everything else on a clinical calendar. Thirty focused minutes plus short quarterly reminders beats a ninety minute session that half the staff clicks through between patients.
Training is a control that makes other controls work. It is not the control. If you have a limited budget this quarter, the order I would spend it in is: a current written risk analysis, multifactor authentication on every mailbox and every remote access path, tested backups, patching discipline, and then training. Training moves up that list the moment the first four are genuinely in place, because at that point your remaining meaningful exposure really is the person reading email at the front desk. That layered view is the argument we made in HIPAA Compliance Is Not a Binder.
One more thing on the horizon
You have probably heard the HIPAA Security Rule is being rewritten. HHS published a notice of proposed rulemaking on January 6, 2025 covering the first substantive Security Rule update since 2013, with more prescriptive requirements around asset inventories, encryption, multifactor authentication, and periodic testing. As of this writing it remains proposed. HHS has moved final action on its regulatory agenda more than once, most recently to a 2027 target, and a final rule could differ meaningfully from the proposal. We wrote about that slip in The HIPAA Security Rule Update Slipped to 2027.
So: do not let a vendor sell you anything on the premise that the new rule is imminent law, because it is not. And do not treat the delay as a reprieve, because OCR is actively enforcing the current rule and the direction of travel is plain from the settlements it keeps announcing.
Questions worth asking your training vendor or IT provider
- Can you show me a dated roster with names and job titles, not just a completion percentage?
- How much of this content is specific to our practice, our systems, and each role, as opposed to generic sector content?
- Who is the knowledgeable person available for live questions during our bloodborne pathogens session, and what are their qualifications?
- If a staff member leaves in March, can I still produce their training record in year five?
- Does the platform export raw records, or only dashboards? What happens to my history if I change vendors?
- When our policies materially change, what triggers the retraining and who tracks completion?
- Do you also maintain our written risk analysis, or is that a separate engagement? If separate, who owns it?
That last question is the one I would ask first. A provider who sells you training but has never asked to see your risk analysis is selling you the visible half of the problem.
Where I sit on this
Harmony MSP bundles security awareness training, phishing simulation, policy documentation, and risk analysis support into our managed services agreements rather than selling them as separate line items. That is a business model choice and it benefits us. It means our clients do not skip training in a tight quarter, and it also means we are paid whether or not any individual practice would have chosen to buy it a la carte.
It is also a genuine position. In fifteen years I have never seen a practice keep a training program current when it lived in one person’s reminder list. The ones that stay current are the ones where it is somebody’s contractual job. I would rather say that plainly than pretend the recommendation is free of self interest.
If you want a second set of eyes on this
If you are not sure whether your training file would survive a records request, the fastest way to find out is to try producing it cold and see what is missing. If you would rather have someone walk it with you, we help small medical and dental practices across the Orlando and Central Florida area sort out exactly this, alongside the risk analysis that sits underneath it.
No pressure and no sales script. Call us at (407) 720-6540 and we can talk through where your practice stands.
Frequently asked questions
Does HIPAA actually require annual training?
No. The Privacy Rule requires training for new workforce members within a reasonable time after hire and for affected staff after a material policy change. The Security Rule requires an ongoing security awareness program without specifying a frequency. Annual is the practical standard because it produces a continuous documented history across HIPAA’s six year retention window.
We are a two provider dental office. Is OCR really going to look at us?
Enforcement is complaint and breach driven, so most small practices never see an investigator. But OCR has settled with solo and small practices, and its 2026 settlements include entities well under 10,000 affected individuals. Size does not exempt you from the standard, and a breach report is what starts the clock.
Can one session cover both HIPAA and OSHA?
You can hold them on the same day and often should, because it is one interruption to the schedule instead of two. Keep the records separate and clearly labeled. An OSHA compliance officer needs to see a bloodborne pathogens roster with a trainer name and qualifications on it, not a combined sign-in sheet that makes them hunt.
Is our OSHA 300 log protected health information?
No. HIPAA excludes employment records held by a covered entity in its role as employer. The log is an employment record. It still deserves careful handling under other law, but HIPAA is not the reason.
Does an online video satisfy the bloodborne pathogens requirement?
Only if there is an opportunity for interactive questions and answers with a person knowledgeable in the subject matter as it applies to your workplace. A video plus a documented live question session works. A video alone does not, and it is a common citation.
How long do we keep the records?
OSHA bloodborne pathogens training records for three years from the date of training. HIPAA documentation for six years from creation or last effective date. In a small office, keep everything six years and run one clock.
Sources
- eCFR, 45 CFR 164.530, Administrative requirements (Privacy Rule training and documentation)
- HHS, HIPAA Security Rule overview and guidance
- HHS, HIPAA Privacy Rule guidance
- HHS Office for Civil Rights, Settles Four HIPAA Security Rule Ransomware Investigations, April 23, 2026
- HHS Office for Civil Rights, Settles Ransomware Investigation with Health Plan, June 18, 2026
- HHS Office for Civil Rights, Settles Ransomware Investigation with Healthcare System, July 29, 2026
- HHS, Guidance on Risk Analysis under the HIPAA Security Rule
- OSHA, 29 CFR 1910.1030, Bloodborne pathogens
- OSHA, Standard Interpretation on annual bloodborne pathogens training, August 31, 1997
- OSHA, 29 CFR 1910.1200, Hazard communication
- OSHA, Penalties
- Verizon, 2026 Data Breach Investigations Report, Healthcare Snapshot
- Federal Register, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule), January 6, 2025
This article is general information for practice operations planning. It is not legal advice. Confirm your specific obligations with counsel or the relevant agency.



