Health Insurance Portability and Accountability Act (HIPAA)

Health Insurance Portability and Accountability Act (HIPAA) | Yale University

Training

Training Modules

Who needs HIPAA Privacy training?

All faculty, staff, students in:

  • School of Medicine -

    (excluding the School of  Public Health, the Animal Resources Center, and the basic science departments: Cell Biology, Cellular and Molecular Physiology, Comparative Medicine, History of Medicine, Immunobiology, Microbial Pathogenesis, MolecularBiophysics & Biochemistry, Neurobiology, and Pharmacology),

  • Physician’s Associate Program
  • School of Nursing
  • Yale University Health Services
  • Department of Psychology clinics
  • Benefits Office staff
  • Research personnel who access PHI
  • ITS (Information Technology Services)

Everyone listed above needs to be trained, even if they don’t directly interact with protected health information. This is because anyone in these environments can come into incidental contact with protected health information or can encounter violations of HIPAA and so needs to know what to do in those instances.

Who needs HIPAA Security training?

All faculty, staff, students in:

  • School of Medicine -

    (excluding the School of  Public Health, the Animal Resources Center, and the basic science departments: Cell Biology, Cellular and Molecular Physiology, Comparative Medicine, History of Medicine, Immunobiology, Microbial Pathogenesis, MolecularBiophysics & Biochemistry, Neurobiology, and Pharmacology),

  • Physician’s Associate Program
  • School of Nursing
  • Yale University Health Services
  • Department of Psychology clinics.
  • Benefits Office staff
  • Yale University Health Services
  • ITS (Information Technology Services)

…who use computing or communications systems during the course of work at Yale University. This includes systems use on–campus as well as from remote locations, such as home, hotels and other off–campus locations.

Note: A General security training module is available for people who do not create, access or receive electronic protected health information (ePHI), or do not have oversight responsibilities or provide IT support for staff who do.

Yale–New Haven Hospital’s HIPAA training

  • Privacy: You only have to take Privacy training from one institution. Yale–New Haven Hospital’s policies and procedures are embedded in the Yale University training. If you’ve taken YNHH’s HIPAA training, you do not need to take the Yale University Privacy training.
  • Security: You must take the Yale University HIPAA Security training. Taking YNHH’s HIPAA training does NOT fulfill Yale University’s HIPAA Security training requirement.

How long does each online training course take?
Most people are able to complete each course in 30 to 45 minutes. If you need to stop before you finish you can save your work and complete the course in another session.

How can I print out a certificate proving I’ve taken the training?
The Training Management System (TMS) contains records of both your HIPAA Privacy and Security training. Select the “My Training Information” on the left hand side, you will then be prompted to enter your net id and password. Select Transcript from the left hand selection, select the completed course you want a certificate for and hit the print icon. Please allow 24 hours after completing the online training for your TMS profile to be updated.

Note: If you are accessing TMS outside of Yale's network (working from home, off campus, etc), you will need to connect to VPN prior to logging into TMS. If you need assistance with VPN, please contact ITS helpdesk at 203-432-9000 or helpdesk@yale.edu..

Will I ever need retraining for HIPAA Privacy and Security?
Yes, if you change jobs you must learn the new policies and procedures for the new job.

The frequency of HIPAA Security training is still being discussed. You may be required to take training or a refresher course on an ongoing basis.

To determine if there are other training requirements you must complete, please visit the Training and Certification website to take the Training Requirements Assessment.

Note: All faculty, staff, postdoctoral fellows and postdoctoral associates are required to complete the Training Requirements Assessment within 30 days of date of hire.