Healthcare administration: HIPAA Privacy Rule basics for front-office staff (US)
For receptionists, schedulers, patient-access and front-office staff at US health care providers that are HIPAA covered entities. No prerequisites. Covers what protected health information is, the minimum necessary standard, verifying who you're talking to, talking with family and friends, incidental disclosures at a busy desk, and how to take a patient's request for their own records. Jurisdiction: US federal (45 CFR Parts 160 and 164). This is awareness training: it is not legal advice and does not grant any licence or certification. Your privacy official and your organization's policies, which may add stricter state-law rules, decide what you do.
- Level
- Beginner
- Length
- About 70 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify protected health information at the front desk, including spoken and paper information
- Choose the minimum necessary information for a routine request and recognise the exceptions
- Verify the identity and authority of a requester you don't know before sharing information
- Decide what you may share with a family member or friend when the patient is present and when they are not
- Take a patient's request for access to their records and state the response deadline and permitted fee items
Course outline
- 1.What the Privacy Rule protects, and where you fitLesson · 12 min
- 2.Minimum necessary: choosing what a routine request needsLesson · 9 min
- 3.Verifying the identity and authority of a requester you don't knowLesson · 7 min
- 4.Family, friends and the busy front deskLesson · 14 min
- 5.When a patient asks for their recordsLesson · 14 min
- 6.Healthcare administration: HIPAA Privacy Rule basics for front-office staff (US): knowledge checkKnowledge check · 16 questions
- 7.Healthcare administration: HIPAA Privacy Rule basics for front-office staff (US): practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- 45 CFR 160.103 Definitions (covered entity, PHI, workforce), via Cornell LII
- 45 CFR 164.502 Uses and disclosures of PHI: general rules (incidental, required disclosures, minimum necessary), via Cornell LII
- 45 CFR 164.510 Uses and disclosures requiring an opportunity to agree or object (directories, family and friends), via Cornell LII
- 45 CFR 164.514 Other requirements (minimum necessary implementation, verification), via Cornell LII
- 45 CFR 164.524 Access of individuals to protected health information, via Cornell LII
- 45 CFR 164.530 Administrative requirements (privacy official, training, safeguards, retaliation), via Cornell LII
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.