Training a workforce of one — and the day you hire
Summary
Yes. HIPAA's training requirement applies to a solo practice — you are the covered entity's entire workforce, and the Privacy and Security Rules both require workforce training on your policies. In practice that means writing the policies, attesting that you know them, and documenting the training so you can produce it in an audit. The obligation becomes external the day you hire anyone: train them before they touch PHI.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
Does HIPAA training apply to a solo practice?
Yes. HIPAA does not exempt small practices, and you are the covered entity's entire workforce, so the training obligation lands on you personally. The Privacy Rule requires you to train workforce members on the policies and procedures that protect PHI, and the Security Rule requires a separate security awareness and training program 1Ref 1Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The Privacy Rule workforce-training requirement, the Security Rule's separate security-awareness program, and the six-year documentation retention under §164.316.. 'Workforce of one' changes how you satisfy the requirement, not whether it applies.
If you are unsure HIPAA even reaches you — a cash-only practice that never bills electronically may fall outside it — resolve the covered-entity test first, because it decides whether any of this applies. For everyone inside HIPAA, the training requirement is real, and the fact that no regulator is likely to watch you complete it does not make it optional 2Ref 2HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.That the Privacy Rule requires training the workforce on the practice's policies and procedures, with no small-practice exemption.. The point of the exercise is not the classroom; it is that you can show your policies exist and that you follow them.
What 'training' means when you're the whole workforce
For a solo practitioner, training collapses into three concrete acts: write the policies, learn them, and record that you did. HIPAA does not prescribe a course, a vendor, or a certificate — it requires that the workforce be trained on the entity's own policies and that the training be documented. So the useful work is producing the policy set your training is training on, not buying a generic module.
A workable solo cadence:
- Write the policy set once. Privacy, security, breach response, minimum necessary, patient access, and disclosures — including everyday judgment calls like talking to family members of a patient.
- Attest at the start and annually. A dated one-line attestation that you have read and will follow each policy is your training record.
- Re-train on change. A new EHR, a new telehealth platform, or a material policy change triggers a fresh attestation.
The minimum necessary standard is a good test of whether the training is real: if your policies say you limit access to the minimum PHI needed for a task, your systems and habits should actually reflect it.
The Security Rule's separate training
The Security Rule adds a training obligation the Privacy Rule does not: a security awareness and training program covering the electronic threats a modern practice faces 1Ref 1Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The Privacy Rule workforce-training requirement, the Security Rule's separate security-awareness program, and the six-year documentation retention under §164.316.. For a solo office that means periodic reminders to yourself on the things that actually cause breaches — phishing emails, weak or reused passwords, unpatched software, and ransomware. It is scaled to your size, but it is not waivable.
Anchor this to your risk analysis rather than a checklist. The Security Rule expects safeguards proportional to your practice, and the awareness program is where you close the human gaps the technology cannot — recognizing a fake login page, not opening an unexpected attachment, reporting a lost device immediately. Note the date each time you refresh it; a training program with no dates reads, to an investigator, like a program that never ran.
Documenting it — the file OCR asks for
When OCR investigates a complaint or a breach — and its record shows it does investigate very small practices — one of the first requests is your training documentation 3Ref 3HHS Office for Civil Rights (2026).HIPAA Compliance and Enforcement.That OCR investigates even very small practices and requests training documentation, so keeping the record is not optional.. If you cannot produce it, the failure is not just the missing training; it is the missing record, which HIPAA requires you to retain for six years. A one-page log is enough to satisfy it.
Keep a single training log with four columns: date, topic, who was trained, and a signature or initials. As a solo practice, every row is you — until you hire, at which point the same log carries your staff. Store it with your policies and your risk analysis so the whole compliance file lives in one place. The retention clock runs six years from the later of creation or last effective date, so do not discard old logs on a calendar year.
The day you hire: training a real workforce
The requirement stops being a paperwork exercise the moment you bring on anyone who touches PHI — a receptionist, a part-time biller, a covering clinician, even an unpaid intern. Each new workforce member must be trained on your policies before they access PHI, and within a reasonable time of joining. This is where solo onboarding has to become deliberate, because the person is now creating exposure you are responsible for.
Two distinctions decide what you owe:
- Workforce member vs. business associate. A person under your day-to-day control is workforce and gets trained. An outside vendor that handles PHI for you — a billing service, a transcription tool, an answering service — is a business associate and needs a signed BAA rather than your internal training 4Ref 4HHS Office for Civil Rights (2026).Business Associates.The distinction between a trained workforce member and an outside vendor handling PHI, who instead needs a signed BAA..
- Role-based scope. A front-desk hire needs the scheduling, check-in, and minimum-necessary pieces; a biller needs the disclosure and payment pieces. Train to the role, document it, and add the person to your log.
Build the training into a written onboarding checklist so it happens the same way every time, and so nothing PHI-facing goes live before the training is signed.
The other trainings a solo office may owe
HIPAA is not the only training mandate that can reach a small practice, so it helps to know where the others start. If your office uses hazardous chemicals — cleaning agents, certain lab reagents, sterilants — OSHA's Hazard Communication standard adds its own labeling, safety-data-sheet, and training duties 5Ref 5Occupational Safety and Health Administration (2026).Hazard Communication.That OSHA's Hazard Communication standard adds labeling, safety-data-sheet, and training duties where hazardous chemicals are used.. Most talk-therapy offices have little or no HazCom trigger; a procedural or lab-running practice has more.
The practical move is to separate the regimes so none surprises you: HIPAA training on privacy and security; OSHA training where hazardous chemicals or bloodborne exposure exist; and any state-specific requirements that sit in the state layer above HIPAA. Keeping them on one compliance calendar — each with its own cadence and its own record — turns the workforce-of-one review into a single afternoon a year rather than a scramble when a question arrives.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The Privacy Rule workforce-training requirement, the Security Rule's separate security-awareness program, and the six-year documentation retention under §164.316.
- 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThat the Privacy Rule requires training the workforce on the practice's policies and procedures, with no small-practice exemption.
- 3.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR investigates even very small practices and requests training documentation, so keeping the record is not optional.
- 4.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThe distinction between a trained workforce member and an outside vendor handling PHI, who instead needs a signed BAA.
- 5.Occupational Safety and Health Administration (2026). Hazard Communication. U.S. Occupational Safety and Health Administration. link ✓That OSHA's Hazard Communication standard adds labeling, safety-data-sheet, and training duties where hazardous chemicals are used.
https://www.gale.care/for-providers/hip-training-when-solo · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.