| 45 CFR 164.530(b)(1) |
Train all workforce members on your policies and procedures for PHI, as necessary and appropriate for them to carry out their functions |
The subject is your policies, not HIPAA in the abstract. And "for their functions" is the sentence that pushes toward role specific question sets. |
| 45 CFR 164.530(b)(2)(i) |
Train by the compliance date, each new workforce member within a reasonable period after joining, and each affected member within a reasonable period after a material policy change |
Three triggers, and none of them is the calendar. Regenerate the quiz when the policy changes, and you have covered the third trigger properly. |
| 45 CFR 164.308(a)(5)(i) |
Implement a security awareness and training program for all workforce members, including management |
A separate obligation from privacy training, and it explicitly reaches executives. The security deck needs its own question set. |
| 45 CFR 164.308(a)(5)(ii)(A) to (D) |
Security reminders, protection from malicious software, log-in monitoring, and password management, all four labeled addressable |
Addressable is not optional. If you do not implement one, you document why and what you did instead. These four are the natural spine of a security awareness quiz. |
| 45 CFR 164.530(j)(2) |
Retain the required documentation for six years from creation or from the date it was last in effect, whichever is later |
Six years, and the clock can start at the end of a policy's life, not its beginning. Store the graded quiz next to the policy version it came from. |
| 45 CFR 164.316(b)(2)(i) |
The Security Rule's own six year retention for its required documentation |
Two rules, two retention clocks, same length. In practice you keep one training file for six years and stop thinking about which rule it answers. |