This document is the actual training content referenced by the Workforce Training Policy (HIPAA-SEC-005) — that policy defines which topics must be covered; this is the material itself. It is scoped, as HIPAA-SEC-005 is, to EMStool LLC's own small team and its incidental PHI exposure while building and supporting Cadence — not to any client organization's own workforce.
HIPAA (the Health Insurance Portability and Accountability Act of 1996) sets national standards for protecting patient health information. Two rules matter most here:
EMStool LLC is a Business Associate: it provides software to Covered Entities (the client organizations using Cadence) and is bound by HIPAA's Business Associate provisions, not the full Covered Entity rule set.
Protected Health Information is any individually identifiable health information — combined with any of 18 identifiers (name, address, dates, phone, email, SSN, medical record number, photos, etc.) — that relates to a person's past, present, or future physical or mental health, healthcare received, or payment for healthcare. ePHI is PHI stored or transmitted electronically — which is what Cadence handles.
For EMStool's own team, PHI exposure is incidental: it happens only when auditing logs, troubleshooting a misbehaving server, or reviewing a bug report that happens to include real patient data — never as routine job function.
As a member of EMStool's team, your responsibility is to build, secure, and support Cadence without unnecessarily viewing, copying, or retaining PHI. When troubleshooting requires looking at real data, access only what's needed to resolve the specific issue, and do not discuss or share what you saw beyond what's needed to fix the problem.
Covered in full in the Acceptable Use Policy (HIPAA-SEC-011). Key points: don't share credentials, don't access records outside what your task requires, don't export or copy PHI outside approved workflows, and report anything suspicious immediately.
Use unique, strong passwords for every system that could expose PHI. Enable multi-factor authentication wherever it's offered. Never write down or share credentials. If you suspect a credential has been compromised, rotate it immediately and report it per Section 6 below.
Any suspected security incident — unauthorized access, a lost or stolen device, unusual system behavior, or an accidental disclosure — must be reported immediately per the Incident Response Runbook (IRP-2026-01). For a one-person team, this means documenting the incident (what happened, when, what data was involved) and following the runbook's containment/assessment/notification steps directly — there is no separate person to escalate to, so acting on it yourself, promptly, is the reporting.
Per the Sanctions Policy, violations of these practices — even unintentional ones — carry consequences proportionate to the violation, up to and including termination of access or employment. For a business owner, this section is about personal accountability to the standard, not a disciplinary process applied to someone else.
Patients have the right to access their own records (§164.524), request corrections, receive an accounting of certain disclosures, and be notified of a breach affecting their data. EMStool supports these rights at the tooling level (see the Patient Records Request Procedure, HIPAA-SEC-008, and the Breach Notification Procedure) — the client organization is responsible for handling the actual patient-facing request, since they are the Covered Entity with the direct patient relationship.
Review any new or revised HIPAA policy documents published in hipaa/index.html since the last training date, and any material changes to Cadence's own security posture (new encryption, new monitoring, new vendors) — the Vendor Security Register and the SOC2/ISO27001 gap-analysis tracker are the fastest way to see what's changed.
Phishing (fraudulent emails/messages trying to steal credentials), social engineering (someone impersonating a legitimate requester to extract access or information), and lost/stolen devices remain the most common real-world causes of breaches — more often than a direct technical exploit. Be skeptical of unexpected credential-reset requests, unusual login prompts, and any request to bypass normal access procedures "just this once."
Covered in full in the PHI Retention & Deletion Policy (HIPAA-SEC-009) and the Vendor Security Register's disposal section. In short: data deletion is manual and client-directed, and hardware/media disposal is the responsibility of whoever owns the physical hardware (the client, for their own deployment; EMStool for its own non-client infrastructure, which holds no real PHI).
Review the Internal Audit Program's (IAP-2026-01) quarterly findings logs and any anomaly alerts fired by audit_anomaly_check.php over the past year. De-identify any specifics before discussing (no need to reference real patient or user names when the point is the pattern, not the individual).
Same as Initial Training items 6 and 7 above — worth an annual re-read since these are the sections most likely to be forgotten under day-to-day pressure.
Each row below represents one workforce member completing either the Initial or an Annual Refresher training cycle.
| Name | Training Type | Date Completed | Notes |
|---|---|---|---|
| Jacob Russell | Initial | July 16, 2026 | Read in full — Initial Training Curriculum (8 topics) and Annual Refresher Curriculum (5 topics) above. |
By signing below, I confirm I have read and understood all sections of this curriculum.