Skip to main content
Course

HIPAA Security & Privacy Compliance

Turn the HIPAA rulebook into the everyday decisions that actually protect health data.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

5 hours

Estimated time

What you will be able to do

  • You will be able to determine whether an organization is a covered entity, a business associate, or neither, and identify what data is regulated PHI or ePHI.
  • You will be able to apply the Privacy Rule's permitted uses and disclosures and the minimum necessary standard to real access decisions.
  • You will be able to map the Security Rule's administrative, physical, and technical safeguards and distinguish required from addressable implementation specifications.
  • You will be able to plan and document a Security Rule risk analysis and a risk management plan that withstands an OCR review.
  • You will be able to identify when a business associate agreement is required and evaluate whether one contains the mandatory terms.
  • You will be able to run the four-factor breach risk assessment and determine the notifications and timelines the Breach Notification Rule requires.
  • You will be able to explain how HIPAA is enforced, the civil penalty tiers, and how to prepare for an OCR investigation or audit.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    HIPAA Scope: Who and What Is Regulated

    Before any safeguard makes sense you have to know who HIPAA binds and what data it protects. This module defines covered entities and business associates and pins down exactly what counts as PHI and ePHI.

    2 lessons · 5 quiz questions

  2. 02

    The Privacy Rule and Minimum Necessary

    The Privacy Rule governs how PHI may be used and disclosed and gives individuals rights over their information. This module covers permitted uses, the minimum necessary standard, and patient rights, then asks you to build a real disclosure decision aid.

    2 lessons · 5 quiz questions · assignment

  3. 03

    The Security Rule: Safeguards and Risk Analysis

    The Security Rule protects ePHI through administrative, physical, and technical safeguards anchored by a mandatory risk analysis. This module explains the safeguard structure, the required-versus-addressable distinction, and how to run a defensible risk analysis.

    2 lessons · 5 quiz questions

  4. 04

    BAAs, Breach Notification, and Enforcement

    This module closes the loop: how to paper vendor relationships with business associate agreements, how to run the four-factor breach analysis and meet notification deadlines, and how HIPAA is enforced. It ends with a capstone breach-response and notification exercise.

    2 lessons · 5 quiz questions · assignment