
Explore HIPAA's origins, its five titles, and the Title II privacy and security rules, then learn how HITECH and Omnibus tightened enforcement, breach standards, and business associate liability.
Apply the two-part PHI test—health information plus an identifier—to determine what falls under HIPAA. Identify the 18 identifiers and recognize PHI across paper, electronic, and spoken formats to prevent breaches.
Identify the three HIPAA covered entities—healthcare providers who transmit electronically, health plans, and healthcare clearinghouses—and explain business associates, BAAs, and the Omnibus Rule's direct enforcement.
Explore how the privacy rule governs use and disclosure of PHI, detailing TPO, written authorization, minimum necessary, and public interest exceptions. Apply role-based access controls and safeguard against incidental disclosures.
Navigate how HIPAA governs access for minors, spouses, personal representatives, and deceased individuals, detailing state law carve-outs, documentation verification, and the 50-year rule.
Explain the notice of privacy practices and the six HIPAA rights, with emphasis on the right of access, 30-day timelines, format requests, permissible fees, and the mandatory self-pay restriction.
Explore the HIPAA security rule foundations, covering ePHI protections across administrative, physical, and technical safeguards, risk analysis, encryption, unique user IDs, MFA, automatic logoff, and audit logs.
Identify the four major breach drivers—ransomware and phishing, mobile BYOD, telehealth and remote work, cloud and social media risks—and follow OCR's presumed breach guidance.
Identify fraud, waste, and abuse within the billing pipeline, spot upcoding and services not rendered, and learn reporting obligations under the False Claims Act.
Explore the five fraud and abuse laws: the false claims act, anti-kickback statute, Stark law, exclusion statute, and civil monetary penalties law, and how their overlap drives penalties and compliance.
Explore how the Stark Law and Anti-Kickback Statute govern financial relationships in health care, covering ownership, family ties, safe harbors, and disclosure.
Assess and respond to HIPAA breaches using a four-factor risk assessment, manage ransomware as a presumed breach, and implement proper notification, encryption, and risk analysis to meet OCR expectations.
Discover how HIPAA sets a federal floor, while state laws add stricter protections; learn breach notification timelines and build a state compliance habit across California, Texas, New York, and Florida.
Spot and respond to privacy, security, and fraud violations in 10 realistic healthcare scenarios, from unattended screens and misaddressed emails to upcoding, anti-kickback risks, and co-pay waivers.
Review HIPAA foundations and rules, access downloadable resources and templates, and follow the five things to do when you get back to your desk to prepare for the final assessment.
HIPAA, Fraud, Waste, and Abuse Compliance Training - This course contains the use of artificial intelligence.
Ensure your organization stays fully compliant with HIPAA regulations and federal requirements for fraud, waste, and abuse prevention. This complete training course is designed specifically for healthcare providers, employees, business associates, and organizations that need to meet annual HIPAA and FWA training mandates.
This course covers both the legal obligations and the real-world application of HIPAA privacy, security, and fraud regulations. Whether you're onboarding new staff or providing annual re-training for your team, this course simplifies complex regulatory requirements into clear, actionable lessons that your employees will actually retain.
What you’ll learn:
The core components of the Health Insurance Portability and Accountability Act (HIPAA)
HIPAA Titles I-V explained: portability, privacy, security, tax provisions, and administrative simplification
Protected Health Information (PHI): what it is, who can access it, and how it's safeguarded
Understanding covered entities, business associates, and business associate agreements
Minimum necessary rule, authorization for disclosure, and patient rights
Special situations for minors, spouses, and family members requesting information
HIPAA security rule: administrative, physical, and technical safeguards
Facility controls, workstation access, device/media disposal, contingency plans, and risk management
Electronic claims transmission, clearinghouses, encryption, and secure communications
Fraud, waste, and abuse prevention: identifying and avoiding billing errors, unauthorized access, and data breaches
Phishing attacks, email threats, and staff awareness training to prevent cyber intrusions
Real-world case studies and examples to help staff apply compliance principles to daily work
Annual HIPAA and fraud training requirement fulfillment for federal program participation (Medicare, Medicaid, VA)
Who this course is for:
Healthcare providers and office staff
Business associates, vendors, and contractors
Medical billing companies and coders
Hospitals, clinics, private practices, and healthcare networks
HR, compliance officers, and training coordinators responsible for employee compliance programs
By the end of this course, your staff will have a full understanding of HIPAA regulations, how to properly handle PHI, how to stay compliant with fraud, waste, and abuse regulations, and how to avoid costly violations that can result in fines or criminal charges.
This course fulfills federal training requirements and can be used as part of your organization’s annual HIPAA and FWA compliance program.