AT-2 Awareness and Training

Security Awareness Training

Medium Risk Easy Low Cost

AT-2 requires providing basic security awareness training to system users as part of initial training, when required by information system changes, and at least annually thereafter; and incorporating insider-threat and practical awareness content. It is the broad workforce program that complements HIPAA security awareness and training requirements.

Control Objective

Ensure every workforce member who can affect ePHI understands practical security expectations — how to spot threats, protect data, and report incidents.

Implementation Guidance

  1. Cover all workforce categories: clinical, billing, IT, students, volunteers, and contractors with system access.
  2. Deliver training at hire, at least annually, and when major threats/systems change.
  3. Include phishing, passwords/MFA, workstation locking, clean desk/screen, removable media, social engineering, and incident reporting.
  4. Add insider-threat awareness appropriate to healthcare (snooping, inappropriate access).
  5. Track completion in an LMS; escalate delinquents before access reviews fail.
  6. Reinforce with simulations (phish tests) and micro-learning — not only a yearly video.
  7. Tailor examples to EHR and clinic workflows so staff see relevance.
  8. Retain training records for HIPAA documentation periods.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Phishing simulation after a real campaign

Finance staff click a fake invoice. AT-2 program increases phishing modules and monthly simulations; click rates drop and reporting rates rise.

New EHR go-live

Before go-live, awareness refresh covers secure login, no shared passwords, and how to report chart-access issues — reducing bad habits on day one.

Contractor onboarding gap

Traveling coders skipped annual training. AT-2 enrollment is gated to badge/EHR activation so no access without completion.

Best Practices

  • Role-relevant scenarios, not generic slides only.
  • Measure completion and phishing report rates.
  • Include insider threat / patient privacy snooping.
  • Short reinforcements through the year.
  • Leadership messages supporting reporting culture.
  • Align AT-2 with AT-3 role-based training for privileged users.

Common Gaps & Violations

  • Training only for clinical staff, not billing/IT contractors.
  • One-time hire training with no annual refresh.
  • No records of who completed what.
  • Content never mentions EHR or phishing realities.
  • Punitive culture that discourages reporting mistakes.

Required Documentation

  • Security awareness training policy/curriculum
  • LMS completion reports
  • Training materials version history
  • Phishing simulation metrics (if used)
  • New-hire training checklist

How to Test & Validate

  1. Sample new hires for training before system access.
  2. Verify annual completion rate meets policy threshold.
  3. Review curriculum for required topics including insider threat.
  4. Confirm contractors are included.
  5. Spot-check retention of training records.

Audit Considerations

HIPAA assessors sample workforce training records. AT-2 evidence should show currency, coverage, and content relevant to ePHI risks.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5) Security Awareness and Training — implement a security awareness and training program for all workforce members.
  • 164.308(a)(5)(ii)(A)–(D) — security reminders, malware protection, log-in monitoring, and password management topics map into AT-2 content.
  • 164.530(b) Training (Privacy Rule) — privacy training complements security awareness for PHI handling.
  • 164.316 Documentation — retain training documentation.

Compliance Tips

  • Gate EHR access on training completion for new hires.
  • Keep a short 'security reminder' cadence to satisfy ongoing awareness.
  • Use real (redacted) local incidents as teaching examples.

Frequently Asked Questions

Does AT-2 replace HIPAA privacy training?

No. AT-2 is security awareness; HIPAA also requires privacy training. Run complementary programs.

How does AT-2 differ from AT-3?

AT-2 is baseline awareness for all users; AT-3 is additional role-based training (e.g., admins, developers, clinicians with special duties).

Are phishing simulations required?

Not explicitly by name, but they are a strong way to reinforce AT-2 objectives and measure effectiveness.

References & Resources

  • NIST SP 800-53 Rev. 5 — AT-2
  • NIST SP 800-50 Building an Information Technology Security Awareness and Training Program
  • HIPAA § 164.308(a)(5)
  • Related controls: AT-3, IR-6, AC-8, IA-5

Need Help Implementing AT-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.