EMStool LLC — Cadence MIH Scheduling Platform

Workforce HIPAA Training Curriculum

Companion to: HIPAA-SEC-005 Effective Date: July 16, 2026 Version: 1.0

This document is the actual training content referenced by the Workforce Training Policy (HIPAA-SEC-005) — that policy defines which topics must be covered; this is the material itself. It is scoped, as HIPAA-SEC-005 is, to EMStool LLC's own small team and its incidental PHI exposure while building and supporting Cadence — not to any client organization's own workforce.

Initial Training Curriculum

1. Overview of the HIPAA Privacy and Security Rules

HIPAA (the Health Insurance Portability and Accountability Act of 1996) sets national standards for protecting patient health information. Two rules matter most here:

EMStool LLC is a Business Associate: it provides software to Covered Entities (the client organizations using Cadence) and is bound by HIPAA's Business Associate provisions, not the full Covered Entity rule set.

2. What Constitutes PHI and ePHI

Protected Health Information is any individually identifiable health information — combined with any of 18 identifiers (name, address, dates, phone, email, SSN, medical record number, photos, etc.) — that relates to a person's past, present, or future physical or mental health, healthcare received, or payment for healthcare. ePHI is PHI stored or transmitted electronically — which is what Cadence handles.

For EMStool's own team, PHI exposure is incidental: it happens only when auditing logs, troubleshooting a misbehaving server, or reviewing a bug report that happens to include real patient data — never as routine job function.

3. Your Role and Responsibilities

As a member of EMStool's team, your responsibility is to build, secure, and support Cadence without unnecessarily viewing, copying, or retaining PHI. When troubleshooting requires looking at real data, access only what's needed to resolve the specific issue, and do not discuss or share what you saw beyond what's needed to fix the problem.

4. Acceptable Use of Cadence and Any System Containing PHI

Covered in full in the Acceptable Use Policy (HIPAA-SEC-011). Key points: don't share credentials, don't access records outside what your task requires, don't export or copy PHI outside approved workflows, and report anything suspicious immediately.

5. Password and Authentication Requirements

Use unique, strong passwords for every system that could expose PHI. Enable multi-factor authentication wherever it's offered. Never write down or share credentials. If you suspect a credential has been compromised, rotate it immediately and report it per Section 6 below.

6. Incident Reporting Procedures

Any suspected security incident — unauthorized access, a lost or stolen device, unusual system behavior, or an accidental disclosure — must be reported immediately per the Incident Response Runbook (IRP-2026-01). For a one-person team, this means documenting the incident (what happened, when, what data was involved) and following the runbook's containment/assessment/notification steps directly — there is no separate person to escalate to, so acting on it yourself, promptly, is the reporting.

7. Consequences of Non-Compliance

Per the Sanctions Policy, violations of these practices — even unintentional ones — carry consequences proportionate to the violation, up to and including termination of access or employment. For a business owner, this section is about personal accountability to the standard, not a disciplinary process applied to someone else.

8. Patient Rights Under HIPAA

Patients have the right to access their own records (§164.524), request corrections, receive an accounting of certain disclosures, and be notified of a breach affecting their data. EMStool supports these rights at the tooling level (see the Patient Records Request Procedure, HIPAA-SEC-008, and the Breach Notification Procedure) — the client organization is responsible for handling the actual patient-facing request, since they are the Covered Entity with the direct patient relationship.

Annual Refresher Curriculum

1. Changes Since Last Training

Review any new or revised HIPAA policy documents published in hipaa/index.html since the last training date, and any material changes to Cadence's own security posture (new encryption, new monitoring, new vendors) — the Vendor Security Register and the SOC2/ISO27001 gap-analysis tracker are the fastest way to see what's changed.

2. Common Threats and Vulnerabilities

Phishing (fraudulent emails/messages trying to steal credentials), social engineering (someone impersonating a legitimate requester to extract access or information), and lost/stolen devices remain the most common real-world causes of breaches — more often than a direct technical exploit. Be skeptical of unexpected credential-reset requests, unusual login prompts, and any request to bypass normal access procedures "just this once."

3. Proper Handling and Disposal of PHI

Covered in full in the PHI Retention & Deletion Policy (HIPAA-SEC-009) and the Vendor Security Register's disposal section. In short: data deletion is manual and client-directed, and hardware/media disposal is the responsibility of whoever owns the physical hardware (the client, for their own deployment; EMStool for its own non-client infrastructure, which holds no real PHI).

4. Review of Audit Log Findings or Incidents from the Prior Year

Review the Internal Audit Program's (IAP-2026-01) quarterly findings logs and any anomaly alerts fired by audit_anomaly_check.php over the past year. De-identify any specifics before discussing (no need to reference real patient or user names when the point is the pattern, not the individual).

5. Reminder of Reporting Obligations and Sanctions

Same as Initial Training items 6 and 7 above — worth an annual re-read since these are the sections most likely to be forgotten under day-to-day pressure.

Completion Log

Each row below represents one workforce member completing either the Initial or an Annual Refresher training cycle.

NameTraining TypeDate CompletedNotes
Jacob RussellInitialJuly 16, 2026Read in full — Initial Training Curriculum (8 topics) and Annual Refresher Curriculum (5 topics) above.

By signing below, I confirm I have read and understood all sections of this curriculum.

Signature
Date