1. Purpose
This policy establishes requirements for training all workforce members of EMStool LLC on HIPAA Privacy and Security Rules, organizational policies, and their individual responsibilities regarding the protection of Protected Health Information (PHI) and electronic PHI (ePHI).
The HIPAA Security Rule (45 CFR §164.308(a)(5)) requires covered entities and business associates to implement a security awareness and training program for all workforce members, including management. The Privacy Rule (45 CFR §164.530(b)) requires training for all workforce members on policies and procedures with respect to PHI as necessary and appropriate for them to carry out their functions.
2. Scope
EMStool LLC is a Business Associate — it builds and provides the Cadence software. EMStool does not host or operate the day-to-day clinical, scheduling, or care-coordination workforce that uses Cadence — each client organization (the Covered Entity) is solely responsible for training its own staff who use the platform operationally. This policy does not apply to, and is not a substitute for, that training obligation.
This policy applies only to EMStool LLC's own personnel — a small team whose access to PHI, when it happens at all, is incidental to providing and supporting the software (e.g. auditing or troubleshooting a server that isn't running correctly), not routine clinical or scheduling use. It applies to:
- Full-time and part-time employees
- Contractors and consultants who access PHI or ePHI
- New hires prior to being granted access to any system containing PHI
- Any individual whose role involves access to, management of, or support of systems containing ePHI
3. Training Requirements
3.1 Initial Training — New Workforce Members
All new workforce members must complete HIPAA training before being granted access to any system, application, or data that contains PHI or ePHI. Initial training must cover:
- Overview of HIPAA Privacy and Security Rules
- What constitutes PHI and ePHI
- Workforce member's specific role and responsibilities
- Acceptable use of the Cadence platform and any systems containing PHI
- Password and authentication requirements
- Incident reporting procedures
- Consequences of non-compliance (Sanctions Policy)
- Patient rights under HIPAA
3.2 Annual Refresher Training
All workforce members must complete HIPAA refresher training at least once per calendar year. Annual training must cover:
- Review of any changes to HIPAA regulations or organizational policies since the last training
- Common threats and vulnerabilities (phishing, social engineering, lost devices)
- Proper handling and disposal of PHI
- Review of audit log findings or incidents from the prior year (de-identified)
- Reminder of reporting obligations and sanctions
3.3 Role-Based Training
Certain roles require additional training beyond the standard curriculum:
| Role | Additional Training Required |
| Security Officer (Jacob Russell) |
Risk analysis methodology; breach response procedures; HHS reporting; Business Associate Agreement management; annual HIPAA regulatory updates |
| System Administrators |
Server hardening; encryption key management; audit log review; incident response; access provisioning and de-provisioning |
| Customer Support / Onboarding |
Minimum Necessary standard; proper handling of customer PHI during support; escalation procedures for PHI-related issues |
| Developers / Engineers |
Secure coding practices; PHI handling in code; HIPAA-compliant API design; test data de-identification requirements |
3.4 Triggered Training
Additional training is required when any of the following occur:
- A workforce member commits a Tier 1 HIPAA violation (see Sanctions Policy)
- A significant change is made to HIPAA regulations or organizational policies
- A security incident or breach occurs that reveals a training gap
- A workforce member transitions to a role with greater PHI access
- New technology or software handling ePHI is deployed
4. Training Content and Delivery
4.1 Acceptable Training Methods
- In-person instruction led by the Security Officer
- Written self-study materials reviewed and acknowledged in writing
- Online HIPAA training courses from accredited providers
- Video-based training with comprehension acknowledgment
All training must conclude with a written or electronic acknowledgment signed by the workforce member confirming they completed the training and understand their obligations.
4.2 Minimum Training Topics — All Workforce
| # | Topic | Covered In |
| 1 | What is HIPAA and who it applies to | Initial + Annual |
| 2 | What is PHI / ePHI — examples and non-examples | Initial + Annual |
| 3 | Minimum Necessary standard | Initial + Annual |
| 4 | Password security and MFA | Initial + Annual |
| 5 | Workstation and device security | Initial + Annual |
| 6 | Phishing and social engineering awareness | Annual |
| 7 | Incident and breach reporting procedure | Initial + Annual |
| 8 | Patient rights (access, amendment, accounting) | Initial |
| 9 | Consequences of non-compliance | Initial + Annual |
| 10 | Organizational HIPAA policies overview | Initial + Annual |
5. Documentation and Records
The Security Officer is responsible for maintaining training records for all workforce members. Records must include:
- Workforce member name and role
- Date training was completed
- Training topic(s) and method of delivery
- Signed acknowledgment from the workforce member
- Name of trainer or course provider
Training records must be retained for a minimum of 6 years from the date of creation per 45 CFR §164.316(b)(2).
6. Training Acknowledgment Log
The following log documents completed HIPAA training for EMStool LLC workforce members:
Jacob Russell — Security Officer
Initial + Role-Based
June 1, 2026
JR
7. Non-Compliance
Failure to complete required HIPAA training within the specified timeframe will result in:
- First offense: Suspension of system access until training is completed
- Second offense: Treated as a Tier 1 violation under the Sanctions Policy
- Ongoing non-compliance: Escalated to Tier 2 violation and potential termination of access privileges
8. Policy Maintenance
The Security Officer will review and update this policy and all training materials annually, or sooner if required by regulatory changes, security incidents, or significant organizational changes. Updates will be communicated to all workforce members and re-acknowledgment will be required if material changes are made.
Security Officer Signature
Jacob Russell, Security Officer