OCR requests proof of security awareness
LMS export shows 98% annual completion with named exceptions and remediation dates — AT-4 evidence ready within hours.
AT-4 requires documenting and monitoring individual information system security training activities — including basic awareness and specific role-based training — and retaining training records for a defined period. Under HIPAA, training without records is hard to prove. AT-4 turns AT-2/AT-3 programs into auditable evidence for hire, annual, and role-change training.
Maintain complete, retrievable records showing who completed which security and privacy training, when, and retain them for the organization-defined period.
How this control shows up in healthcare and HIPAA-covered environments.
LMS export shows 98% annual completion with named exceptions and remediation dates — AT-4 evidence ready within hours.
Reconciliation finds AT-3 course missing; access elevation is blocked until completion is recorded.
Completion certificate and LMS record are stored before VPN provisioning.
Training is one of the most sampled HIPAA administrative safeguards. AT-4 success is individual-level, dated evidence — not a slide saying "we train annually."
How this NIST control supports HIPAA Security Rule expectations.
Weak. Prefer LMS records with unique user ID, course ID, and timestamp.
Define organizational retention; many map to HIPAA's 6-year documentation retention for related policies and required docs.
If simulations are part of your awareness program, retain participation/results appropriately and link to remedial training records.
Related controls that commonly accompany AT-4.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.