AT-1 Awareness and Training Policy and Procedures

Security Awareness and Training Policy and Procedures

Medium Risk Easy Low Cost

AT-1 requires an awareness and training policy and procedures addressing purpose, scope, roles, management commitment, coordination, and compliance, plus procedures to facilitate the Awareness and Training family. Healthcare organizations use AT-1 to mandate HIPAA privacy/security training, phishing awareness, and role-based education for clinicians, billing, IT admins, and researchers who touch ePHI.

Control Objective

Define and maintain policy and procedures that ensure all workforce members and relevant contractors receive timely, role-appropriate security and privacy awareness training for ePHI environments.

Implementation Guidance

  1. Publish AT-1 policy covering employees, volunteers, students, and on-site contractors who may encounter ePHI.
  2. Define mandatory curricula: HIPAA privacy/security basics, phishing, incident reporting, and role-based modules.
  3. Assign ownership (compliance/security/HR LMS) and completion tracking requirements.
  4. Set frequency: at hire, annually thereafter, and when duties or systems change materially.
  5. Require manager escalation for overdue training before continued elevated access.
  6. Disseminate policy; train trainers and content owners on update processes.
  7. Review content after incidents, EHR changes, or regulatory updates.
  8. Retain completion records per HIPAA documentation retention expectations.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Traveler nurse cohort

AT-1 procedures require agency attestation or LMS enrollment before EHR credentials activate — training is not deferred to “first quiet shift.”

Ransomware tabletop lessons

After a near-miss phishing campaign, AT-1 review adds a mandatory micro-module for revenue-cycle staff who handle attachments daily.

Research coordinators added to EHR

Role-based training under AT-1 covers minimum necessary, disclosure logs, and protocol-bound data pulls before research roles are granted.

Best Practices

  • Tie training completion to access provisioning gates.
  • Role-based paths for clinical, billing, IT, and research.
  • Annual plus event-driven updates.
  • Track contractors and students, not only W-2 staff.
  • Measure phishing simulation trends.
  • Keep curricula mapped to HIPAA topics.

Common Gaps & Violations

  • One generic slide deck never updated.
  • Contractors excluded from training requirements.
  • No link between overdue training and access.
  • Privacy training done; security awareness ignored (or vice versa).
  • Completion evidence missing for sampled workforce.

Required Documentation

  • Awareness and training policy (AT-1)
  • Training curricula and role matrix
  • LMS completion reports
  • New-hire and annual training procedures
  • Review/update history of policy and content

How to Test & Validate

  1. Review AT-1 policy currency and ownership.
  2. Sample new hires: training before or at access grant.
  3. Sample annual completions for clinical and IT roles.
  4. Verify contractor/student inclusion rules.
  5. Confirm content updated after a recent major change or incident.

Audit Considerations

HIPAA auditors routinely sample training records. AT-1 evidence shows the program is governed — not just a pile of certificates without a policy backbone.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5) Security Awareness and Training — implement a security awareness and training program for all workforce members.
  • 164.530(b) Training — train workforce on privacy policies and procedures as necessary for functions.
  • 164.308(a)(3) Workforce Security — training supports appropriate access and supervision.
  • 164.316 Policies and procedures — document and review the training policy framework.

Compliance Tips

  • Automate LMS reminders at 30/14/7 days before annual due dates.
  • Add AT-1 acknowledgment to onboarding checklists used by credentialing.
  • Keep a short mapping of modules to HIPAA citations for assessors.

Frequently Asked Questions

Does AT-1 replace role-based AT-3 training?

No. AT-1 is the policy/procedure control; AT-2/AT-3 deliver literacy and role-based content under that policy.

Are physicians employed by a medical group covered?

If they are workforce with EHR access under your entity, include them or obtain equivalent training assurance via agreement.

How long keep training records?

Retain documentation at least six years from creation or last effective date under HIPAA documentation rules, or longer if state/contract requires.

References & Resources

  • NIST SP 800-53 Rev. 5 — AT-1
  • HIPAA §§ 164.308(a)(5), 164.530(b), 164.316
  • Related controls: AT-2, AT-3, AT-4, IR-2, PS-1

Need Help Implementing AT-1?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.