Platform

Workforce built for HIPAA, not bolted onto it

Training, policy acknowledgement, and awareness — with per-person completion records you can hand an investigator.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Training, policy acknowledgement, and awareness — with per-person completion records you can hand an investigator.

What this module does

  • Role-based HIPAA training for clinical, engineering, billing, and front-desk staff
  • Policy acknowledgement tied to policy version, not just policy name
  • Phishing simulation with remediation training assignment
  • Onboarding and annual refresher automation via HRIS sync
  • Per-employee compliance record, exportable as a single PDF

What it replaces

  • A training video watched once at onboarding and never again
  • No proof of who acknowledged which version of which policy
  • Contractors and BAs who never went through training at all

How it maps to the rule

Every item above is linked to a specific implementation specification in 45 CFR §164. Open any control and you see the citation, whether it is required or addressable, what you have implemented, and the evidence proving it. If a specification is addressable and you chose not to implement it, the platform makes you record the rationale — because that rationale is the thing an investigator asks for.

Included in every plan

Starter, Growth, and Enterprise all include this module. We do not price HIPAA modules separately, because a partial Security Rule implementation is not a product, it is a liability.

What happens after you fill the form

  1. You get the deliverable immediately. No “a rep will contact you to unlock your download.”
  2. We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
  3. You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.

On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.

Questions

Does Workforce work if we are a business associate, not a covered entity?

Yes. The module ships with both scopes. Business associates get the subcontractor and downstream-BAA views turned on by default; covered entities get patient-rights workflows turned on.

Can we export everything if we leave?

Yes — policies as DOCX, evidence as a timestamped ZIP, registers as XLSX. No export fee, no lock-in clause.

Is this the same platform as LowerPlane?

It runs on the LowerPlane compliance engine. SuperHIPAA is the HIPAA-specific configuration of it, so you can add SOC 2, ISO 27001, or GDPR later without re-implementing anything.

How often does HIPAA actually require training?

45 CFR §164.308(a)(5) requires training for all workforce members plus periodic reminders. Training at hire, on material policy change, and an annual refresher is the defensible cadence the module schedules by default.

Do contractors and volunteers need training too?

Yes. HIPAA's definition of workforce covers employees, volunteers, trainees, and anyone under your direct control, paid or not. The module tracks them all the same way.

Can this run alongside our existing LMS?

Yes — it can stand alone or complement an LMS. The point is that completion records and policy acknowledgements land in the same evidence library as everything else, instead of a separate silo.

What evidence does it produce if we are audited?

Per-person completion records with dates, quiz scores, and policy acknowledgements tied to the exact document version acknowledged. All of it exports when an investigator or customer asks.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo