Skip to content
Interdisciplinary CurriculumCurriculum

Your learning stays with you.

Purchase Terms

© 2026 Commensurate Ventures. All rights reserved.

Interdisciplinary CurriculumCurriculum
All Courses

HIPAA Compliance & Patient Data Security

Complete HIPAA training covering the Privacy Rule, Security Rule, breach notification, business associate requirements, patient rights, OCR enforcement, and emerging issues in telehealth, cloud services, and health apps.

8 Units
20 minutes per unit
Curriculum Map

What You Will Learn

Privacy & Security Rules

PHI definitions, permitted uses and disclosures, administrative/physical/technical safeguards, and the risk assessment requirement.

Enforcement & Penalties

OCR investigation process, civil penalty tiers, criminal penalties, and case studies of multi-million dollar settlements.

Emerging Issues

Telehealth privacy, cloud services, health apps, wearable devices, and AI/ML processing of protected health information.

All Units

1
20 minutes
HIPAA Privacy Rule: Covered Entities, PHI, and Minimum Necessary
Establishes the foundational framework of the HIPAA Privacy Rule, including covered entity definitions, PHI scope, and the minimum necessary principle.
  • •Define covered entities, business associates, and protected health information under the Privacy Rule
  • •Apply the minimum necessary standard to uses and disclosures of PHI
  • •Distinguish between HIPAA-protected communications and non-protected health information
Start learning
2
20 minutes
Permitted Uses and Disclosures: Treatment, Payment, Operations, and Authorizations
Analyzes the Privacy Rule's framework for permitted uses and disclosures, including TPO exceptions, required disclosures, and authorization requirements.
  • •Identify the six categories of permitted uses and disclosures without patient authorization
  • •Distinguish when a valid HIPAA authorization is required versus when disclosure is permitted without authorization
  • •Apply the treatment, payment, and healthcare operations framework to common disclosure scenarios
Start learning
3
20 minutes
Security Rule: Administrative, Physical, and Technical Safeguards
Examines the Security Rule's framework for protecting electronic PHI through administrative, physical, and technical safeguards and the required risk assessment process.
  • •Apply the Security Rule's required and addressable implementation specifications to electronic PHI
  • •Conduct a risk assessment that satisfies the Security Rule's risk analysis requirements
  • •Implement administrative, physical, and technical safeguards appropriate to organizational size and complexity
Start learning
4
20 minutes
Breach Notification: Definition, Risk Assessment, Timeline, and Penalties
Analyzes the Breach Notification Rule's requirements for identifying breaches, conducting risk assessments, notifying affected parties, and understanding enforcement penalties.
  • •Apply the four-factor risk assessment to determine whether an impermissible use or disclosure constitutes a breach
  • •Execute breach notification to individuals, HHS, and media within regulatory timeframes
  • •Calculate financial exposure based on breach size, harm, and OCR's penalty methodology
Start learning
5
20 minutes
Business Associate Agreements and Vendor Management
Examines business associate relationships, required BAA provisions, vendor due diligence, subcontractor requirements, and covered entity oversight obligations.
  • •Identify when a vendor relationship requires a business associate agreement under HIPAA
  • •Draft or evaluate a BAA that satisfies all required contractual provisions under 45 CFR § 164.504(e)
  • •Conduct due diligence on business associates to ensure adequate security and compliance capabilities
Start learning
6
20 minutes
Patient Rights: Access, Amendment, Accounting, Restrictions, and Confidential Communications
Examines the five categories of individual rights under the Privacy Rule, including implementation requirements, timelines, permitted denials, and enforcement trends.
  • •Process patient requests for access to PHI in compliance with the 30-day deadline and fee limitations
  • •Evaluate and respond to patient requests for amendment, restrictions, and accounting of disclosures
  • •Implement confidential communications accommodations that satisfy the Privacy Rule's reasonable accommodation requirement
Start learning
7
20 minutes
HIPAA Enforcement: OCR Investigation Process, Civil Penalties, Criminal Penalties, and Case Studies
Examines OCR's enforcement authority, investigation procedures, penalty methodology, criminal prosecution mechanisms, and case studies illustrating enforcement trends.
  • •Navigate OCR's investigation and audit process from complaint intake through resolution
  • •Calculate potential civil monetary penalty exposure using the four-tier penalty structure
  • •Distinguish compliance approaches that mitigate enforcement risk from practices that increase exposure
Start learning
8
20 minutes
Emerging Issues: Telehealth Privacy, Cloud Services, Health Apps, Wearables, and AI
Examines HIPAA compliance challenges posed by telehealth, cloud computing, consumer health apps, wearable devices, and artificial intelligence in healthcare.
  • •Apply HIPAA requirements to telehealth platforms, remote patient monitoring, and virtual care technologies
  • •Distinguish HIPAA-covered health apps from non-covered consumer wellness apps and assess privacy implications
  • •Evaluate AI and machine learning applications for HIPAA compliance risks and mitigation strategies
Start learning

Continuing medical education. 3 credit hours (Compliance). Accepted for physicians, nurses, and pharmacists.