AT-4 Awareness and Training

Security Training Records

Medium Risk Easy Low Cost

AT-4 requires documenting and monitoring individual information system security training activities — including basic awareness and specific role-based training — and retaining training records for a defined period. Under HIPAA, training without records is hard to prove. AT-4 turns AT-2/AT-3 programs into auditable evidence for hire, annual, and role-change training.

Control Objective

Maintain complete, retrievable records showing who completed which security and privacy training, when, and retain them for the organization-defined period.

Implementation Guidance

  1. Use a centralized LMS or HRIS module as the system of record for security/privacy training.
  2. Capture identity, course, version, completion date/time, score if applicable, and delivery method.
  3. Cover new hire, periodic (e.g., annual), and role-based training (AT-3) in the same retention scheme.
  4. Include contractors and students when they receive ePHI access.
  5. Define retention (often 6+ years to align with HIPAA documentation practices) and backup the LMS exports.
  6. Produce exception reports for overdue training; escalate to managers and consider access suspension.
  7. Retain records of sanctions-related retraining (PS-8).
  8. Periodically reconcile active system users to training-complete status.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

OCR requests proof of security awareness

LMS export shows 98% annual completion with named exceptions and remediation dates — AT-4 evidence ready within hours.

Privileged EHR admin without role-based training

Reconciliation finds AT-3 course missing; access elevation is blocked until completion is recorded.

Contractor coder completes privacy modules remotely

Completion certificate and LMS record are stored before VPN provisioning.

Best Practices

  • Single system of record.
  • Capture course version.
  • Include non-employees with access.
  • Overdue escalation with teeth.
  • Reconcile users to completions.
  • Retain aligned with HIPAA documentation needs.

Common Gaps & Violations

  • Sign-in sheets only; illegible or lost.
  • Training done but not attributable to individuals.
  • Contractors omitted.
  • No retention after LMS vendor change.
  • Role-based training undocumented.

Required Documentation

  • Training records procedure
  • LMS reports / sample exports
  • Retention schedule for training records
  • Overdue escalation process
  • Contractor training evidence samples

How to Test & Validate

  1. Sample workforce for annual training completion records.
  2. Verify new-hire training before or at access grant.
  3. Check privileged roles for AT-3 records.
  4. Confirm retention and exportability.
  5. Review overdue list and escalation actions.

Audit Considerations

Training is one of the most sampled HIPAA administrative safeguards. AT-4 success is individual-level, dated evidence — not a slide saying "we train annually."

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5) Security Awareness and Training — implement a security awareness and training program; records prove it.
  • 164.530(b) Training — privacy training for workforce; retain documentation of training.
  • 164.316(b) Documentation — retain required documentation for 6 years from creation or last effective date.
  • 164.308(a)(3) Workforce Security — training records support appropriate workforce clearance/access decisions.

Compliance Tips

  • Export LMS completions quarterly to durable storage in case of vendor switch.
  • Make overdue >30 days an IAM risk flag.
  • Record training content version so you can show what people were taught after a policy change.

Frequently Asked Questions

Are attendance emails enough for AT-4?

Weak. Prefer LMS records with unique user ID, course ID, and timestamp.

How long must we keep training records?

Define organizational retention; many map to HIPAA's 6-year documentation retention for related policies and required docs.

Does AT-4 include phishing simulations?

If simulations are part of your awareness program, retain participation/results appropriately and link to remedial training records.

References & Resources

  • NIST SP 800-53 Rev. 5 — AT-4
  • HIPAA §§ 164.308(a)(5), 164.530(b), 164.316
  • Related controls: AT-2, AT-3, PS-6, PS-8, AC-2

Need Help Implementing AT-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.