Employer guide · Scope, supervision and clinical compliance

HIPAA Training for New Dental Employees

What HIPAA requires you to train new dental hires on, when each piece is due, and the records and policies behind it.

Founder, DentistryHires
Updated October 7, 2026

New dental hires need two kinds of HIPAA training: privacy training on the policies that protect patient information, due within a reasonable period of time after they join, and a security awareness and training program that reaches all workforce members, management included.

The rule sets no fixed number of days, requires you to document that the training happened and to apply sanctions when staff do not follow the policies, and expects a documented answer on cutting a leaver's access to records.

Here is what each requirement covers and the records to keep.

Rules vary by state and change

This guide explains federal rules and the state rules it names, as of the date above.

Employment law and dental-practice rules differ by state and are revised often, so confirm current requirements with your state dental board, labor agency or employment counsel before you act on them.

It is general information, not legal advice.

Who counts as workforce at a dental practice

HIPAA's definition is broader than your payroll: workforce means employees, volunteers, trainees and other persons whose conduct, in the performance of work for the practice, is under its direct control — whether or not they are paid.

Every training duty on this page attaches to that group, so it is worth reading literally.

Day to day it pulls in the obvious staff — the dentist, any associates, hygienists, assistants, the sterilization tech, front desk and billing — and the people who are easy to miss: a volunteer covering a front-desk shift, a dental assisting student on a rotation you supervise, an intern sitting in on treatment without pay.

If their work happens under your direction, they are workforce for HIPAA's purposes, and "we don't pay them" is not a line around the requirement.

Two consequences follow.

The training duties below reach all of them, scaled to what each person actually does.

And the definition matters again at the exit: the Security Rule's termination procedures are written for the end of "the employment of, or other arrangement with, a workforce member" — an arrangement ending is enough to trigger them, not just a job ending.

One scope note: this page covers the training slice.

The program around it — the written policies, the risk analysis, the documentation discipline — is the manager's side, and HIPAA in the dental office takes it from the practice-manager's angle.

Keep the two straight and neither gets improvised.

The privacy training requirement, and when it is due

The Privacy Rule requires a covered entity to train all members of its workforce on the policies and procedures that protect patient information, as necessary and appropriate for their functions.

Two timing rules sit inside that sentence.

First, new members of the workforce must be trained within a reasonable period of time after the person joins.

The rule sets no specific number of days — the window is yours to set and defend.

Write it into your own policy (before the end of the first week; before a front-desk hire works a shift unsupervised) and hold every hire to it, because "reasonable" is much easier to show when your policy named a deadline up front.

Second, workforce members whose functions are affected by a material change in those policies must be retrained within a reasonable period after the change takes effect.

Not every edit qualifies — the rule says material — but a new records-release workflow or a switch of practice software is the kind of change that should have you checking who needs retraining.

You must also document that the training was provided.

The record is part of the compliance file, not a courtesy — how long to keep it and what it should show are covered further down this page.

What the rule does not name is an annual cycle: its text requires training for new workforce members and retraining after material policy changes, with no annual frequency.

Annual refreshers are a common best practice rather than a requirement written into the current rule — the retraining that is mandatory is the one triggered by material changes.

What to cover with front-desk and clinical staff

The content scales to the job: training must be as necessary and appropriate for each member's functions.

Since the rule requires training on your policies and procedures, your policy manual is the curriculum — which is also why the two cannot drift apart.

If a material change to your policies alters what the front desk is supposed to do about a caller asking about a patient, it affects their functions — that is a retraining event, not just a policy edit.

For the front desk, train the situations where patient information walks out the door in ordinary traffic: a family member calling for appointment times, paperwork left on the counter within sight of the waiting room, screens angled toward the door, what may be said in a voicemail, who signs for a records request.

The useful version of the session is your actual script for each one — identity verified before a patient is discussed, and so on — not a definition of protected health information read off a slide.

For clinical staff, cover the operatory versions: charts and screens left open between patients, conversations that carry through the wall, and the position your policies take on who may open a chart and why — settle whether curiosity counts as a reason before the session, and have staff hear it from you there rather than discover it in a write-up.

Then document who was trained on what.

Fold the session into your onboarding checklist so the slot exists before the hire does, and note which version of the policies each person was trained on.

Security awareness training: the second requirement

The Privacy Rule is not the only training duty.

The Security Rule separately requires a security awareness and training program for all members of the workforce, including management — a program aimed at the electronic side of the practice: practice-management software, imaging files, email, backups.

Within that program the rule names four specifications, each addressable: security reminders (periodic security updates), procedures for guarding against, detecting and reporting malicious software, procedures for monitoring log-in attempts and reporting discrepancies, and password management.

"Addressable" does not mean optional.

It means you assess whether the specification is reasonable and appropriate for your practice and then implement it — or document why an equivalent alternative works for the practice instead.

Someone has to own this.

The Security Rule requires covered entities to identify the security official responsible for developing and implementing security policies.

In a small practice that can be the office manager or the dentist; whoever it is should own the training program too, so reminders, log-in monitoring and password rules come from one place.

A timing note on rule changes: HHS published a proposed update of the Security Rule on January 6, 2025 — the "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information".

As of October 7, 2026 it remains a proposed rule, with no final rule found.

Its proposals are not current law, so train to the rule as it stands and re-check the status before restructuring your program around what was proposed.

Documentation and how long to keep it

The rule requires you to document that privacy training was provided.

What a defensible record shows is up to you, but "who, when, on which version of the policies, delivered by whom" answers the questions an auditor is likely to ask.

Keep it six years.

HIPAA privacy documentation — the required policies and writings and the documented actions such as training — must be retained for six years from the date of its creation or the date when it last was in effect, whichever is later.

That second date matters: a policy you replaced this year keeps its clock running from its last effective date, and the training records attached to that version go with it.

The Security Rule mirrors the arrangement for its side: security policies and procedures must be documented in writing (electronic form is allowed), retained for six years from creation or last effective date, made available to the people who implement them, and reviewed periodically and updated as needed.

Practically, store each training record beside the version of the policies it trained on.

The clocks run in parallel, and a training log detached from the policy it taught is much harder to connect to anything later.

Sanctions, and cutting access when someone leaves

Two sanction duties sit behind the training.

Under the Privacy Rule you must have and apply appropriate sanctions against workforce members who fail to comply with your privacy policies, and document the sanctions you apply.

The Security Rule separately requires a sanction policy for workforce members who fail to comply with security policies — a required specification, not an addressable one.

"Have and apply" means the consequence ladder exists in your policies before anything happens — a reminder, retraining, a write-up, termination for the serious end — and that you follow it the same way for the dentist as for the newest assistant, documenting what you did each time.

A sanction policy that has never been applied to anyone is a policy, not a program.

Departures are their own specification: the Security Rule includes an addressable specification to implement procedures for terminating access to electronic PHI when the employment of, or other arrangement with, a workforce member ends.

Addressable, as above, means decide and document — not skip.

The electronic piece of that decision, for a departing hygienist or front-desk hire, is the logins: practice-software accounts disabled the day the arrangement ends and shared-account passwords changed.

Alongside it sit the physical and operational steps a practice adds on its own account — badges and keys collected, the person off reminder lists and schedules — which are good housekeeping, not the specification itself.

The employment-law side of the exit — final pay, paperwork, the conversation itself — is its own topic, and our guide to terminating an employee walks it step by step.

The HIPAA piece above should be a standing item on that day's list.

New-hire training is one line on a longer onboarding sheet.

The dental hiring hub collects the employer guides around it, from screening to retention.

A new hire's HIPAA file

  • Privacy training given within the window your own policy sets — the rule requires it within a reasonable period of the hire joining.
  • Content matched to the role: front-desk scripts for the front desk, operatory situations for clinical staff.
  • Security awareness covered for the whole team, management included: security reminders, malicious software, log-in monitoring, password management.
  • Training documented: who, when, on which version of the policies, delivered by whom.
  • Record stored to last six years from creation or the date it last was in effect, whichever is later.
  • Material policy changes flagged for retraining of everyone whose functions they touch.
  • A departure procedure decided and documented: how access to electronic PHI ends when a workforce member's employment or other arrangement ends — the Security Rule's addressable termination-procedures specification.

Questions employers ask

Do volunteers and unpaid trainees count as workforce who need HIPAA training?

Yes.

HIPAA defines workforce to include employees, volunteers, trainees and others whose work for the practice is under its direct control, whether or not they are paid.

A volunteer covering the front desk or a student on a chairside rotation you supervise is workforce, so the training duty reaches them, scaled to what they actually do.

Does HIPAA require annual privacy training for dental staff?

No annual frequency appears in the Privacy Rule's text.

It requires training for each new workforce member within a reasonable period of joining, and retraining when a material policy change affects someone's functions.

Annual refreshers are a common best practice rather than a written requirement — but retraining after material changes is not optional.

Did the 2025 HIPAA Security Rule proposal change the training rules?

Not yet.

HHS's proposed Security Rule update was published on January 6, 2025, and as of October 7, 2026 it was still listed as a proposed rule, with no final rule found.

Its proposals are not current law, so train to the rule as it stands and check the status again before rebuilding your program around what was proposed.

Does HIPAA training cover OSHA's bloodborne pathogens training too?

No — they are separate duties with separate subjects.

HIPAA training covers privacy and security of patient information.

OSHA's bloodborne pathogens training is due at the time of initial assignment to tasks where occupational exposure may take place and at least annually thereafter.

Schedule both in a new chairside hire's first days.

Sources

More hiring resources

Hiring staff who will handle patient records?

Post your opening on DentistryHires and reach dental assistants, hygienists and front-office staff looking for their next role.