The HIPAA Security Rule requires a security awareness and training program for every workforce member who touches electronic protected health information. HACKIN'GAMES delivers that training as hands-on games — phishing, malware defense, password hygiene and more — and produces the per-employee completion records you keep in your audit file. It satisfies the HIPAA training safeguard at 45 CFR § 164.308(a)(5)(i); it does not make your whole organization "HIPAA compliant."
No credit card to start. Completion records are generated as your team plays.
Yes. The HIPAA Security Rule names "Security awareness and training" as a required administrative safeguard at 45 CFR § 164.308(a)(5)(i). Every covered entity and business associate must "implement a security awareness and training program for all members of its workforce (including management)." This is not optional boilerplate — it is one of the named standards the U.S. Department of Health and Human Services (HHS) holds you to.
The standard carries four addressable implementation specifications that describe what the program should cover: (A) security reminders, (B) protection from malicious software, (C) log-in monitoring, and (D) password management. "Addressable" does not mean optional — it means you must assess each one and either implement it or document why an alternative is reasonable and appropriate for your environment. In practice, awareness of phishing, malware, suspicious log-ins and good password habits maps directly onto these four areas.
Just as important: HIPAA requires you to document the training and keep that documentation. Under 45 CFR § 164.316(b)(2), records of your safeguards — including who was trained and when — must be retained for six years. When HHS Office for Civil Rights (OCR) investigates a complaint or breach, training records are among the first things they ask to see. Training you can't prove is, for audit purposes, training that didn't happen.
HACKIN'GAMES is security awareness training plus the completion evidence an OCR investigator looks for — not a GRC platform and not a guarantee of overall HIPAA compliance.
We focus on one job and do it well: train your workforce on the threats § 164.308(a)(5) is about, and give you records you can keep for the six-year retention window and hand to an auditor.
The modules map to the everyday ways protected health information gets exposed — the same threats HIPAA's addressable specifications point at. Your workforce trains by doing, then their completions roll up into the records you retain.
Start with the core HIPAA-relevant games: phishing email triage and social-engineering defense (the human-error vectors behind most PHI breaches), cloud security misconfiguration (where ePHI actually lives), injection and AppSec attacks, and AI prompt-injection threats for teams adopting new tooling. Browse the full lineup on the games page.
Yes. "Security awareness and training" is a named administrative safeguard in the HIPAA Security Rule at 45 CFR § 164.308(a)(5)(i). Every covered entity and business associate must implement a security awareness and training program for all workforce members, including management. The standard includes four addressable implementation specifications: security reminders (A), protection from malicious software (B), log-in monitoring (C), and password management (D).
HACKIN'GAMES keeps per-employee, per-module completion records with dates and lets you export a one-click "Security Awareness Training Record" transcript. That shows exactly which workforce member completed which training and when — the kind of documentation HHS OCR looks for. HIPAA requires you to retain such records for six years under § 164.316(b)(2), and the exported transcript is built to live in that audit file.
HIPAA does not prescribe a format. § 164.308(a)(5)(i) requires a security awareness and training program; it does not mandate slideshows, videos, or any specific delivery method. Interactive, gamified training that covers the relevant topics — phishing, malware, password hygiene — and produces dated completion records is a reasonable way to meet the standard. As always, your privacy/security officer or assessor makes the final determination for your organization.
HIPAA does not state a fixed interval. The Security Rule treats awareness as ongoing — note the "security reminders" addressable specification — and requires training for new workforce members and periodic refreshers, with retraining when there are material changes affecting security. Most organizations train at onboarding and at least annually. Ongoing modules let you run recurring reminders rather than a single yearly session, and every completion is dated for your records.
No. HACKIN'GAMES delivers the security awareness training required by § 164.308(a)(5)(i) and produces completion evidence for it — it satisfies one specific safeguard, not the entire Security Rule. It is not a GRC platform and does not cover risk analysis, access controls, encryption, business-associate agreements, or your other HIPAA obligations. Your compliance officer or assessor makes the final determination on overall compliance.