Course track
Healthcare Add-On
For clinics, dental offices, and healthcare teams handling patient information: PHI basics, safe handling on shared and mobile devices, breach reporting windows, verbal privacy, business associates, and patient rights.
Who takes this: Clinical and administrative staff who handle patient information
HIPAAISOSOC2FTCNIST
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| HIPAA Basics: Protecting Patient Information | 5 min | Define PHI and the minimum-necessary rule. | HIPAA |
| Safe Handling of PHI on Shared and Mobile Devices | 4 min | Apply encryption, auto-lock, and no-personal-device rules for PHI. | HIPAA |
| Reporting a Suspected PHI Breach | 3 min | Know the internal reporting window for a suspected PHI exposure. | HIPAA |
| Minimum Necessary: Only Access What You Need | 5 min | Apply the minimum necessary standard to decide which patient records you should and should not access during your normal work. | HIPAA, ISO |
| Verbal Privacy: Conversations That Protect Patients | 5 min | Identify the situations where spoken conversations create PHI risks and use practical steps to keep those conversations private. | HIPAA, ISO |
| Email, Messaging, and PHI: Sending Safely | 5 min | Choose the right channel and apply safe practices when sending patient information digitally so that PHI does not reach unintended recipients. | HIPAA, ISO, SOC2 |
| Third Parties and Business Associates: Sharing PHI Outside Your Organization | 5 min | Recognize when a third party requires a Business Associate Agreement before receiving PHI and explain why that agreement matters. | HIPAA, ISO, SOC2 |
| Patient Rights: Access, Amendment, and Requests | 5 min | Explain the key rights patients have over their own health information and describe how to handle a patient request correctly. | HIPAA, FTC |
| Social Engineering in Healthcare: When Attackers Pretend to Be Someone They Are Not | 5 min | Recognize common social engineering tactics used to extract PHI from healthcare staff and apply verification steps before sharing any patient information. | HIPAA, NIST, ISO |
| Building a Privacy-First Culture on Your Team | 5 min | Describe practical ways to reinforce privacy habits within your team so that protecting patient information becomes a shared, everyday norm rather than a solo effort. | HIPAA, ISO, SOC2 |
Compliance codes show which frameworks each module supports; they describe what the training content covers, not a guarantee of legal compliance. Confirm specific clause wording with your own compliance advisor before citing it to a regulator or auditor.