HIPAA for MSPs Security Awareness Training: 2026 Rules

HIPAA for MSPs security awareness training needs 12-month retraining and 6-year record retention under 45 CFR 164.308(a)(5). See the 2026 requirements MSPs miss.

Security awareness training satisfies HIPAA for MSPs when it covers the Security Rule's required workforce training standard at 45 CFR 164.308(a)(5), documents completion for every user who touches PHI, and repeats at least once every 12 months with content split by role. The gap that trips up most managed service providers isn't the training content itself — it's the audit trail: OCR corrective action plans cite missing completion records almost as often as they cite missing training.

TL;DR

Why this matters for MSPs

MSPs servicing US healthcare clients — practices, billing companies, telehealth providers — sit inside the compliance chain as business associates. A business associate agreement doesn't cover you if the training you deliver can't be produced on demand with names, dates and completion status attached.

HIPAA doesn't name a specific vendor or platform. It names an outcome: a documented, periodic workforce training program addressing security reminders, protection from malicious software, login monitoring and password management. That's a low bar on paper and a high bar in an actual OCR review, because reviewers ask for records, not intentions.

What HIPAA requires for security awareness training

The Security Rule's administrative safeguards section splits training into four addressable implementation specifications under the awareness and training standard. None of them prescribe a vendor, format or price — they prescribe outcomes an MSP has to be able to evidence for every client tenant.

RequirementHIPAA citationWhat the MSP delivers
Periodic security reminders164.308(a)(5)(ii)(A)Ongoing micro-content, not a once-a-year module
Protection from malicious software164.308(a)(5)(ii)(B)Phishing and malware-recognition training
Login monitoring164.308(a)(5)(ii)(C)Training on reporting unusual account activity
Password management164.308(a)(5)(ii)(D)Password hygiene modules tied to the client's access policy

Each row needs its own completion record, timestamped and tied to an individual user — not a department-level attendance sheet. That's the detail most generic compliance-training vendors miss, and it's the detail an OCR reviewer asks for first.

Annual retraining: the 12-month clock MSPs must track

HIPAA doesn't state a fixed calendar cadence in the rule text, but the standard practice accepted across covered entities and business associates in 2026 is retraining at least every 12 months, with new-hire training completed before PHI access is granted. Waiting until an annual review cycle to catch a lapsed client is how MSPs end up with a six-month gap in the record the day an incident happens.

A rolling 12-month cycle, tracked per user rather than per client organisation, closes that gap. Cyber Aware's platform flags individual users approaching their 12-month expiry automatically, which matters more once you're running training across a dozen healthcare tenants instead of one.

Documentation retention: 6 years, not "until the next audit"

45 CFR 164.316(b)(2)(i) sets the retention period for HIPAA-related documentation, including training records, at six years from the date of creation or the date it was last in effect, whichever is later. Most MSPs default to keeping records for a year or two because that matches their own internal audit rhythm — that's not compliant for a healthcare client relationship.

A training platform that purges completion logs after 12 or 24 months forces the MSP to manually archive exports every year to stay inside the six-year window. Build that requirement into the vendor evaluation before signing, not after a client asks for a five-year-old record.

Why HIPAA training requirements vary by client

Not every healthcare client needs the same training depth. The factors that actually change the scope:

MSPs managing multiple healthcare tenants get this wrong by applying one generic module across every client instead of scoping training to the client's actual PHI exposure. The My Health Record framework guide walks through the same role-based scoping approach for Australian healthcare frameworks, which is a useful cross-check even for MSPs working primarily with US HIPAA clients.

Medical billing companies sit in a particularly exposed spot because they handle PHI without direct patient contact, which some staff assume lowers the training bar. It doesn't — the medical billing companies training guide covers the specific phishing and BEC patterns targeting that workforce segment.

Does HIPAA require phishing simulations specifically?

HIPAA does not name phishing simulations as a mandatory format, but the malicious software protection specification at 164.308(a)(5)(ii)(B) is most commonly satisfied through simulated phishing campaigns paired with reporting-behaviour training. Most healthcare compliance programs in 2026 treat simulated phishing as the de facto standard because it produces measurable, individually attributable completion and click-rate data that generic e-learning modules don't.

Is a signed business associate agreement enough without training?

A business associate agreement is not enough on its own — it establishes the legal relationship, but the Security Rule still requires the MSP's own workforce and the client's workforce to complete documented awareness training. A signed BAA with no training records behind it is one of the most common gaps OCR corrective action plans cite.

How often should MSPs re-run training after a client breach?

After a confirmed breach, retraining for the affected client's workforce should happen immediately, not on the next scheduled 12-month cycle, and the retraining content should address the specific attack vector involved. Document the retraining separately from the standard annual cycle so the incident-driven session is traceable on its own in a future audit.

For clients handling telehealth data specifically, exposure patterns differ again — the telehealth providers platform guide breaks down the vishing and video-call impersonation risks that come up more often in that segment than in standard clinical settings.

Build audit-ready HIPAA training now

See how Cyber Aware documents completion records healthcare clients can hand to OCR.

See the platform

FAQ

What does HIPAA require for security awareness training in 2026?

HIPAA requires documented workforce training addressing security reminders, malware protection, login monitoring and password management under 45 CFR 164.308(a)(5), repeated at least every 12 months in 2026 practice. Records must be retained for 6 years.

How often does HIPAA require security awareness retraining?

At least every 12 months is the accepted standard cadence, with new-hire training completed before PHI access is granted. Post-breach retraining should happen immediately rather than waiting for the next scheduled cycle.

How long do MSPs need to keep HIPAA training records?

HIPAA training documentation must be retained for 6 years under 45 CFR 164.316(b)(2)(i), counted from the creation date or the date it was last in effect. Many training platforms default to shorter retention windows, so this needs manual archiving.

Is generic compliance training enough for HIPAA business associates?

No — generic training that isn't tied to individual completion records and role-based PHI exposure typically fails an OCR review even if the content itself is accurate. Training has to be attributable to a specific user, date and role.

Do MSPs need separate HIPAA training for each healthcare client?

Yes, because PHI exposure differs by role and by client — a billing company's workforce faces different risk than a clinical front desk. Scoping training per client tenant, not applying one module across every account, is what audit reviewers expect to see.

Does a business associate agreement replace the need for training?

No, a signed BAA establishes the legal relationship but does not satisfy the Security Rule's separate training requirement. Missing training records behind a valid BAA is one of the most common findings in HIPAA corrective action plans.

One last thing

The detail that catches MSPs out most often in 2026 isn't the training content — it's that HIPAA's six-year retention clock runs from whichever is later: creation date or last-in-effect date. A training record created in 2020 that's still "in effect" because the employee hasn't been retrained resets that clock forward, which means gaps in retraining history compound retention obligations instead of shortening them.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.