Guide

Training a workforce of one — and the day you hire

Summary

Yes. HIPAA's training requirement applies to a solo practice — you are the covered entity's entire workforce, and the Privacy and Security Rules both require workforce training on your policies. In practice that means writing the policies, attesting that you know them, and documenting the training so you can produce it in an audit. The obligation becomes external the day you hire anyone: train them before they touch PHI.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

Does HIPAA training apply to a solo practice?

Yes. HIPAA does not exempt small practices, and you are the covered entity's entire workforce, so the training obligation lands on you personally. The Privacy Rule requires you to train workforce members on the policies and procedures that protect PHI, and the Security Rule requires a separate security awareness and training program 1. 'Workforce of one' changes how you satisfy the requirement, not whether it applies.

If you are unsure HIPAA even reaches you — a cash-only practice that never bills electronically may fall outside it — resolve the covered-entity test first, because it decides whether any of this applies. For everyone inside HIPAA, the training requirement is real, and the fact that no regulator is likely to watch you complete it does not make it optional 2. The point of the exercise is not the classroom; it is that you can show your policies exist and that you follow them.

What 'training' means when you're the whole workforce

For a solo practitioner, training collapses into three concrete acts: write the policies, learn them, and record that you did. HIPAA does not prescribe a course, a vendor, or a certificate — it requires that the workforce be trained on the entity's own policies and that the training be documented. So the useful work is producing the policy set your training is training on, not buying a generic module.

A workable solo cadence:

  • Write the policy set once. Privacy, security, breach response, minimum necessary, patient access, and disclosures — including everyday judgment calls like talking to family members of a patient.
  • Attest at the start and annually. A dated one-line attestation that you have read and will follow each policy is your training record.
  • Re-train on change. A new EHR, a new telehealth platform, or a material policy change triggers a fresh attestation.

The minimum necessary standard is a good test of whether the training is real: if your policies say you limit access to the minimum PHI needed for a task, your systems and habits should actually reflect it.

The Security Rule's separate training

The Security Rule adds a training obligation the Privacy Rule does not: a security awareness and training program covering the electronic threats a modern practice faces 1. For a solo office that means periodic reminders to yourself on the things that actually cause breaches — phishing emails, weak or reused passwords, unpatched software, and ransomware. It is scaled to your size, but it is not waivable.

Anchor this to your risk analysis rather than a checklist. The Security Rule expects safeguards proportional to your practice, and the awareness program is where you close the human gaps the technology cannot — recognizing a fake login page, not opening an unexpected attachment, reporting a lost device immediately. Note the date each time you refresh it; a training program with no dates reads, to an investigator, like a program that never ran.

Documenting it — the file OCR asks for

When OCR investigates a complaint or a breach — and its record shows it does investigate very small practices — one of the first requests is your training documentation 3. If you cannot produce it, the failure is not just the missing training; it is the missing record, which HIPAA requires you to retain for six years. A one-page log is enough to satisfy it.

Keep a single training log with four columns: date, topic, who was trained, and a signature or initials. As a solo practice, every row is you — until you hire, at which point the same log carries your staff. Store it with your policies and your risk analysis so the whole compliance file lives in one place. The retention clock runs six years from the later of creation or last effective date, so do not discard old logs on a calendar year.

The day you hire: training a real workforce

The requirement stops being a paperwork exercise the moment you bring on anyone who touches PHI — a receptionist, a part-time biller, a covering clinician, even an unpaid intern. Each new workforce member must be trained on your policies before they access PHI, and within a reasonable time of joining. This is where solo onboarding has to become deliberate, because the person is now creating exposure you are responsible for.

Two distinctions decide what you owe:

  • Workforce member vs. business associate. A person under your day-to-day control is workforce and gets trained. An outside vendor that handles PHI for you — a billing service, a transcription tool, an answering service — is a business associate and needs a signed BAA rather than your internal training 4.
  • Role-based scope. A front-desk hire needs the scheduling, check-in, and minimum-necessary pieces; a biller needs the disclosure and payment pieces. Train to the role, document it, and add the person to your log.

Build the training into a written onboarding checklist so it happens the same way every time, and so nothing PHI-facing goes live before the training is signed.

The other trainings a solo office may owe

HIPAA is not the only training mandate that can reach a small practice, so it helps to know where the others start. If your office uses hazardous chemicals — cleaning agents, certain lab reagents, sterilants — OSHA's Hazard Communication standard adds its own labeling, safety-data-sheet, and training duties 5. Most talk-therapy offices have little or no HazCom trigger; a procedural or lab-running practice has more.

The practical move is to separate the regimes so none surprises you: HIPAA training on privacy and security; OSHA training where hazardous chemicals or bloodborne exposure exist; and any state-specific requirements that sit in the state layer above HIPAA. Keeping them on one compliance calendar — each with its own cadence and its own record — turns the workforce-of-one review into a single afternoon a year rather than a scramble when a question arrives.

Common questions

Yes. You are the covered entity's entire workforce, and both the Privacy and Security Rules require workforce training with no small-practice exemption. For a solo practice the requirement is satisfied by writing your policies, attesting that you know and follow them, and documenting that attestation — but the obligation itself does not disappear because the workforce is one person.

HIPAA does not fix an interval, but an annual attestation is the widely used convention, plus a fresh one whenever something material changes — a new EHR, a new telehealth platform, or a revised policy. What matters more than the exact cadence is that each session is dated and recorded, so your training log shows a continuous, current program rather than a one-time event.

A dated training log is the standard proof: date, topic, who was trained, and a signature or initials. It does not require a certificate or an outside vendor. Store the log with your policies and risk analysis, and keep it for six years, because OCR asks for training documentation early in an investigation and the missing record is itself a finding.

Train them on your policies first. Each new workforce member must be trained before accessing PHI and within a reasonable time of joining, scoped to their role. If instead you are engaging an outside vendor that handles PHI, that relationship needs a business-associate agreement rather than internal training. Build the training step into a written onboarding checklist so it never gets skipped.

Yes. Privacy Rule training covers how you use and disclose PHI — minimum necessary, patient access, permitted disclosures. Security Rule training is a separate security awareness program covering electronic threats like phishing, weak passwords, and ransomware. A solo practice owes both, scaled to its size, and should document them together so the full training program is visible in one file.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe Privacy Rule workforce-training requirement, the Security Rule's separate security-awareness program, and the six-year documentation retention under §164.316.
  2. 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThat the Privacy Rule requires training the workforce on the practice's policies and procedures, with no small-practice exemption.
  3. 3.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR investigates even very small practices and requests training documentation, so keeping the record is not optional.
  4. 4.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThe distinction between a trained workforce member and an outside vendor handling PHI, who instead needs a signed BAA.
  5. 5.Occupational Safety and Health Administration (2026). Hazard Communication. U.S. Occupational Safety and Health Administration. linkThat OSHA's Hazard Communication standard adds labeling, safety-data-sheet, and training duties where hazardous chemicals are used.

https://www.gale.care/for-providers/hip-training-when-solo · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)