SA-16 System Acquisition

Developer-Provided Training

Medium Risk Moderate Low Cost

SA-16 requires requiring the developer of the system to provide training on correct use and operation of the security and privacy functions. For healthcare, this includes vendor training on EHR security features and internal training for staff who develop interfaces — so break-glass, audit, and encryption features are actually used.

Control Objective

Ensure developers and operational staff receive training on security/privacy functions of ePHI systems so advanced safeguards are configured and used correctly — not left at insecure defaults.

Implementation Guidance

  1. Contractually require vendors to train admin/security staff on security features of EHR and major clinical systems.
  2. Provide secure coding/privacy training for internal developers of ePHI integrations.
  3. Cover emergency access, audit configuration, encryption, and role design.
  4. Record attendance and materials for assessors.
  5. Retrain on major version upgrades that change security UX.
  6. Include BA developers who customize forms/workflows.
  7. Measure whether trained features are actually enabled post-training.
  8. Align with AT-2/AT-3 workforce training programs.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR security console unused

Admins never trained on audit policy UI. SA-16 vendor course precedes enabling detailed ePHI access logging.

Interface engine upgrade

New TLS options exist but team uses cleartext. Developer-provided training and checklist fix the configuration gap.

Custom app team

Internal FHIR developers complete annual secure coding/privacy training focused on IDOR and minimum necessary.

Best Practices

  • Vendor security feature training in contracts.
  • Internal secure development training.
  • Training on upgrades.
  • Attendance records.
  • Verify features enabled after training.
  • Include customizing BAs.

Common Gaps & Violations

  • Only end-user EHR training — no security admin training.
  • Developers learn by breaking production.
  • No training when major security features ship.
  • BA customizers untrained on privacy.
  • Training slides without hands-on labs for critical controls.

Required Documentation

  • Developer/admin security training requirements (SA-16)
  • Vendor training deliverables in contracts
  • Curriculum for internal developers
  • Attendance and completion records
  • Post-training configuration verification samples

How to Test & Validate

  1. Sample contracts for SA-16 training clauses.
  2. Verify recent admin training on EHR security functions.
  3. Check internal developer training completion.
  4. Confirm upgrade-related retraining occurred.
  5. Spot-check that trained features are configured.

Audit Considerations

Unused security features are common audit findings. SA-16 evidence shows people were taught how to operate the safeguards you already bought.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5) Security Awareness and Training — workforce training includes those administering technical safeguards.
  • 164.308(a)(1) Risk Management — correct use of security functions reduces residual risk.
  • 164.312 Technical safeguards — effective only when configured by trained personnel.
  • 164.530(b) Training — privacy training complements security function training for developers handling PHI workflows.

Compliance Tips

  • Put SA-16 deliverables in EHR SOWs.
  • Pair training with a configuration checklist sign-off.
  • Offer short just-in-time modules when enabling new audit features.

Frequently Asked Questions

Is general HIPAA training enough for SA-16?

No. SA-16 targets training on the system's security/privacy functions — product-specific, not only regulatory overview.

Who is the developer?

The EHR vendor, interface vendor, or internal team that provides the system — require training from the party that knows the security functions.

Does SA-16 apply to SaaS?

Yes — require admin training on the SaaS security console and shared-responsibility tasks.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-16
  • Related controls: AT-2, AT-3, SA-5, CM-1

Need Help Implementing SA-16?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.