Applying the HIPAA Privacy, Security and Breach Notification Rules, 42 CFR Part 2 and state law in everyday practice
3CPD hours
20final questions
80%pass mark
PDFcertificate
What you will learn
Identify covered entities, business associates and workforce members, and determine whether information is PHI or de-identified.
Apply the TPO permission and the minimum necessary standard, including its exceptions, to everyday disclosures.
Decide when and how to involve family members, friends and personal representatives, including parents of minors, under 164.510(b) and 164.502(g).
Recognize when a valid authorization is required and identify its core elements, including for psychotherapy notes and marketing.
Analyze requests from law enforcement, attorneys and courts using 164.512(e) and (f), and respond with a documented legal basis.
Apply 164.512(j) and your state's duty-to-protect rules to a patient's threat of violence, and document a defensible decision.
Explain HIPAA preemption, give examples of more stringent state laws, and describe the 2024 changes to 42 CFR Part 2.
Respond correctly to patient requests for access, amendment, accounting, restrictions and confidential communications.
Use safe practices for conversations, EHR access, messaging, telehealth, AI tools, social media and online reviews.
Apply the Breach Notification Rule, describe OCR and board enforcement, and plan a credible response that demonstrates accountability and remediation.
About this course
This course explains how licensed health professionals in the United States should protect, use and share patient information. It works through the HIPAA Privacy Rule in practical terms: covered entities and business associates, protected health information, treatment, payment and health care operations, the minimum necessary standard, family involvement, authorizations and the public interest disclosures in 45 CFR 164.512, including law enforcement requests, subpoenas and serious threats. It also covers patients' rights, the Security Rule basics, the Breach Notification Rule and OCR enforcement.
It is written for licensees across professions: physicians, nurses and APRNs, PAs, pharmacists, dentists and dental hygienists, psychologists, counselors, social workers, therapists and other licensed health care professionals. It is suitable for routine professional development, for clinicians moving into new roles or states, and for licensees responding to a privacy complaint, an employer investigation or a state board inquiry.
Confidentiality in the U.S. is shaped by a federal floor and fifty different state layers. The course explains when stricter state law applies, the 2024 changes to 42 CFR Part 2 for substance use disorder records, the current status of reproductive health privacy rules after the 2025 court decision, the duty to warn or protect after Tarasoff, snooping, social media and online reviews, and how state boards treat confidentiality failures. It ends with practical guidance on responding to a lapse with honesty, understanding and evidenced remediation.
Course facts
CPD value
Approximately 3 CPD hours (estimated learning time including knowledge checks, reflection and assessment)
Audience
U.S. licensed health professionals: physicians (MD/DO), nurses and APRNs, PAs, pharmacists, dentists and dental hygienists, psychologists, counselors, social workers and other licensees
Standards covered
HIPAA Privacy, Security, Breach Notification and Enforcement Rules (45 CFR Parts 160 and 164, including 164.502, 164.506, 164.508, 164.510, 164.512, 164.514, 164.520 to 164.530); 42 CFR Part 2 (2024 final rule); 42 U.S.C. 1320d-6; 45 CFR Part 171 (information blocking); state law examples (California Civil Code 43.92 and CMIA, Texas Health and Safety Code chapter 181, New York Regents Rules Part 29)
Format
Self-paced, gated lessons with knowledge checks, case studies and reflection
Assessment
20 scenario-based questions, 80% to pass (16 of 20)
Outcome
Certificate of completion and a written reflection for your CPD record
Alignment
Mapped to HHS OCR requirements and to confidentiality standards in the AMA Code of Medical Ethics, ANA Code of Ethics for Nurses (2025), APhA Code of Ethics, ADA Principles of Ethics and Code of Professional Conduct, AAPA Guidelines, FSMB and NCSBN social media guidance, and state practice acts. Not board-approved.
Syllabus
10 sections, 3 CPD hours, 20-question final assessment
1Foundations of confidentiality and HIPAA3 lessons
Confidentiality, privacy and trust in U.S. health care
The HIPAA framework: who and what it covers
Protected health information and de-identification
2Permitted uses and disclosures3 lessons
Treatment, payment and health care operations, and the minimum necessary standard
Family, friends and personal representatives
Authorizations, psychotherapy notes and marketing
3Disclosures without authorization and the duty to protect3 lessons
Public interest disclosures under 45 CFR 164.512
Law enforcement, subpoenas and court orders
Serious threats and the duty to warn or protect
4State law and specially protected information3 lessons
State law, preemption and your license
Substance use disorder records: 42 CFR Part 2 after the 2024 final rule
Reproductive health information and other sensitive data
5Patient rights over their information2 lessons
The Notice of Privacy Practices and the right of access
Amendment, accounting, restrictions and confidential communications
6Confidentiality in everyday and digital practice3 lessons
Conversations, workspaces and snooping
Electronic PHI: Security Rule basics, messaging, telehealth and AI tools
Social media, the media and online reviews
7Breaches, enforcement and professional accountability3 lessons
The Breach Notification Rule
OCR enforcement and penalties
Board discipline, employer action and showing insight and remediation
8Conclusion and key points1 lesson
Conclusion and key points
9References and further reading1 lesson
References and further reading
10Your reflective account1 lesson
Your reflective account
Who this course is for
U.S. licensed health professionals: physicians (MD/DO), nurses and APRNs, PAs, pharmacists, dentists and dental hygienists, psychologists, counselors, social workers and other licensees.
Certificate of completion. Not CE or CME credit unless accepted by your board.
Your name, the course title and the CPD hours
Completion date and a unique certificate ID that can be verified
Downloads as a PDF; save it to your portfolio
Fitness To Practice
Certificate of Completion
This certifies that
Your Name
has successfully completed
HIPAA Privacy and Patient Confidentiality
Completed12 Oct 2026
3CPD hours
Certificate IDFTS-7Q4K-2M9X
Certificate of completion — United States
Questions about this course
How is this different from my employer's annual HIPAA training?
Workforce HIPAA training is usually a short compliance module. This course is written for licensed professionals making disclosure decisions: involving family, responding to law enforcement and attorneys, the duty to protect, 42 CFR Part 2 records and state laws stricter than HIPAA, plus how confidentiality breaches lead to board discipline.
How fast must patients be notified after a HIPAA breach?
Under the Breach Notification Rule, you must notify the people affected without unreasonable delay, and in any case within 60 days of discovering the breach. If 500 or more people are affected, HHS must also be told within 60 days, and the media where more than 500 residents of a state are affected. Smaller breaches go on an annual log to HHS.
What changed for substance use disorder records under 42 CFR Part 2?
The 2024 final rule, with compliance due by February 16, 2026, allows a single consent for future treatment, payment and health care operations disclosures, applies HIPAA breach notification, aligns penalties with HIPAA and creates a protected category of SUD counseling notes. Records still cannot be used in proceedings without consent or a court order.
How quickly must I respond to a patient's request for their records?
Under 45 CFR 164.524 a covered entity must act on a request for access within 30 days, with one 30-day extension. Psychotherapy notes and information compiled for legal proceedings are excluded. The course also covers amendment, accounting of disclosures, restrictions and confidential communications.
Does this HIPAA course give CE credit or a HIPAA certification?
No. The government offers no official HIPAA certification for individuals, and this independent course carries no CE or CME credit. What you do get, after scoring 80% on a 20-question test, is our certificate of completion. The course costs $89 for about 3 hours.
Accurate, timely, defensible records: CMS entry rules, medical necessity, cloned notes and AI scribes, corrections and addenda, access requests and retention.
Disclosing adverse events and errors: AMA Opinion 8.6, state disclosure and apology laws, communication-and-resolution programs and second-victim support.
What happens after a state board letter arrives: investigation, your written response, settlement conferences, consent orders, hearings and NPDB reporting.