EMStool LLC — Cadence MIH Scheduling Platform

Workforce HIPAA Training Policy

Policy #: HIPAA-SEC-005 Effective Date: June 1, 2026 (rev. July 16, 2026) Version: 1.1 Next Review: June 1, 2027

1. Purpose

This policy establishes requirements for training all workforce members of EMStool LLC on HIPAA Privacy and Security Rules, organizational policies, and their individual responsibilities regarding the protection of Protected Health Information (PHI) and electronic PHI (ePHI).

The HIPAA Security Rule (45 CFR §164.308(a)(5)) requires covered entities and business associates to implement a security awareness and training program for all workforce members, including management. The Privacy Rule (45 CFR §164.530(b)) requires training for all workforce members on policies and procedures with respect to PHI as necessary and appropriate for them to carry out their functions.

2. Scope

EMStool LLC is a Business Associate — it builds and provides the Cadence software. EMStool does not host or operate the day-to-day clinical, scheduling, or care-coordination workforce that uses Cadence — each client organization (the Covered Entity) is solely responsible for training its own staff who use the platform operationally. This policy does not apply to, and is not a substitute for, that training obligation.

This policy applies only to EMStool LLC's own personnel — a small team whose access to PHI, when it happens at all, is incidental to providing and supporting the software (e.g. auditing or troubleshooting a server that isn't running correctly), not routine clinical or scheduling use. It applies to:

3. Training Requirements

3.1 Initial Training — New Workforce Members

All new workforce members must complete HIPAA training before being granted access to any system, application, or data that contains PHI or ePHI. Initial training must cover:

3.2 Annual Refresher Training

All workforce members must complete HIPAA refresher training at least once per calendar year. Annual training must cover:

3.3 Role-Based Training

Certain roles require additional training beyond the standard curriculum:

RoleAdditional Training Required
Security Officer (Jacob Russell) Risk analysis methodology; breach response procedures; HHS reporting; Business Associate Agreement management; annual HIPAA regulatory updates
System Administrators Server hardening; encryption key management; audit log review; incident response; access provisioning and de-provisioning
Customer Support / Onboarding Minimum Necessary standard; proper handling of customer PHI during support; escalation procedures for PHI-related issues
Developers / Engineers Secure coding practices; PHI handling in code; HIPAA-compliant API design; test data de-identification requirements

3.4 Triggered Training

Additional training is required when any of the following occur:

4. Training Content and Delivery

4.1 Acceptable Training Methods

All training must conclude with a written or electronic acknowledgment signed by the workforce member confirming they completed the training and understand their obligations.

4.2 Minimum Training Topics — All Workforce

#TopicCovered In
1What is HIPAA and who it applies toInitial + Annual
2What is PHI / ePHI — examples and non-examplesInitial + Annual
3Minimum Necessary standardInitial + Annual
4Password security and MFAInitial + Annual
5Workstation and device securityInitial + Annual
6Phishing and social engineering awarenessAnnual
7Incident and breach reporting procedureInitial + Annual
8Patient rights (access, amendment, accounting)Initial
9Consequences of non-complianceInitial + Annual
10Organizational HIPAA policies overviewInitial + Annual

5. Documentation and Records

The Security Officer is responsible for maintaining training records for all workforce members. Records must include:

Training records must be retained for a minimum of 6 years from the date of creation per 45 CFR §164.316(b)(2).

6. Training Acknowledgment Log

The following log documents completed HIPAA training for EMStool LLC workforce members:

Workforce Member Training Type Date Completed Signature / Initials
Jacob Russell — Security Officer Initial + Role-Based June 1, 2026 JR
    
    
    
    

7. Non-Compliance

Failure to complete required HIPAA training within the specified timeframe will result in:

8. Policy Maintenance

The Security Officer will review and update this policy and all training materials annually, or sooner if required by regulatory changes, security incidents, or significant organizational changes. Updates will be communicated to all workforce members and re-acknowledgment will be required if material changes are made.

Security Officer Signature
Jacob Russell, Security Officer
Date
June 1, 2026