Traveler nurse cohort
AT-1 procedures require agency attestation or LMS enrollment before EHR credentials activate — training is not deferred to “first quiet shift.”
AT-1 requires an awareness and training policy and procedures addressing purpose, scope, roles, management commitment, coordination, and compliance, plus procedures to facilitate the Awareness and Training family. Healthcare organizations use AT-1 to mandate HIPAA privacy/security training, phishing awareness, and role-based education for clinicians, billing, IT admins, and researchers who touch ePHI.
Define and maintain policy and procedures that ensure all workforce members and relevant contractors receive timely, role-appropriate security and privacy awareness training for ePHI environments.
How this control shows up in healthcare and HIPAA-covered environments.
AT-1 procedures require agency attestation or LMS enrollment before EHR credentials activate — training is not deferred to “first quiet shift.”
After a near-miss phishing campaign, AT-1 review adds a mandatory micro-module for revenue-cycle staff who handle attachments daily.
Role-based training under AT-1 covers minimum necessary, disclosure logs, and protocol-bound data pulls before research roles are granted.
HIPAA auditors routinely sample training records. AT-1 evidence shows the program is governed — not just a pile of certificates without a policy backbone.
How this NIST control supports HIPAA Security Rule expectations.
No. AT-1 is the policy/procedure control; AT-2/AT-3 deliver literacy and role-based content under that policy.
If they are workforce with EHR access under your entity, include them or obtain equivalent training assurance via agreement.
Retain documentation at least six years from creation or last effective date under HIPAA documentation rules, or longer if state/contract requires.
Related controls that commonly accompany AT-1.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.