HIPAA privacy and security for Aprendio staff and contractors
Aprendio builds automations and AI systems for healthcare practices. That means we sometimes handle their patients' information. This course covers what the law expects of you when we do, and the specific rules Aprendio holds everyone to.
Everyone who may touch protected health information completes this training before their first access and every 12 months after that. There are nine short modules, each with a practice question, then a 22-question exam. You need 80% to pass and you can retake it. When you pass you get a certificate.
Contractors: you'll need the certificate ID and completion date from the end of this course to sign Aprendio's Subcontractor Business Associate Agreement.
Your progress is saved in this browser only. Nothing is sent anywhere until you choose to email your certificate.
Why HIPAA applies to us
Aprendio isn't a clinic, but the moment we handle a client's patient data, federal law treats us as part of the healthcare system.
HIPAA protects health information held by covered entities: health care providers, health plans, and clearinghouses. An optometry practice, a medical billing company's provider clients, a spine surgeon's office: all covered entities.
When a covered entity lets a vendor handle its patients' information to do a job, that vendor is a business associate. When Aprendio builds a patient reminder workflow or cleans up a claims report, Aprendio is a business associate. And anyone Aprendio gives that information to is inside the same chain.
Where you sit in that chain
- Employees are part of Aprendio's workforce. You follow Aprendio's policies, and Aprendio answers for what you do.
- Contractors are subcontractor business associates. HIPAA requires you to sign a subcontractor BAA with Aprendio before you touch any patient data, and you are directly liable to the federal government for your own compliance, not only to Aprendio.
What's at stake
| Consequence | Scale |
|---|---|
| Civil penalties (HHS Office for Civil Rights) | Tiered by culpability, per violation, reaching more than $2 million per year for each type of violation |
| Criminal penalties (Department of Justice) | Knowingly obtaining or disclosing PHI: up to $50,000 and 1 year. Under false pretenses: up to $100,000 and 5 years. To sell it or cause harm: up to $250,000 and 10 years |
| State attorneys general | Can sue under HIPAA and under state privacy and breach laws |
| The business | One incident can end a client relationship. Contractors carry indemnity and insurance obligations under the subcontractor BAA |
Our clients trust us with their patients. Almost every incident in a firm like ours comes from someone taking a shortcut to get work done faster. This course is mostly about which shortcuts you can't take.
You're a contractor. A client's patient data leaks because of a mistake you made. Who can the federal government hold responsible?
What counts as PHI
Protected health information is any information that relates to a person's health, their care, or payment for their care, and identifies them or could be used to identify them. Its form doesn't matter: a spreadsheet, a voicemail, a log line and a sticky note all count.
The 18 identifiers
Health information linked to any of these is PHI:
- Names
- Geographic data smaller than a state (street, city, ZIP)
- Dates tied to a person (birth, admission, discharge, appointment, death) other than year
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and plate numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photos and comparable images
- Any other unique identifying number, code, or characteristic
What PHI looks like in our work
It rarely looks like a medical chart. In Aprendio's work, PHI shows up as:
Data
- An appointment export CSV
- A claims or billing spreadsheet
- An insurance eligibility response
- A database table or backup
- Test fixtures copied from real exports
Byproducts
- n8n execution history
- Error logs holding a request body
- A prompt or response sent to an AI model
- A screenshot or screen recording of a CRM
- A call recording or voicemail transcript
Even the fact that someone is a patient of a practice is PHI. A Slack message saying "Mrs. Alvarez called the Tampa office about her follow-up" contains PHI.
When it isn't PHI
Information that has been properly de-identified (all 18 identifiers removed, with no reasonable way to re-identify the person) is not PHI. Aggregate numbers like "412 appointments last month" aren't PHI either. But masking part of a name, dropping only the last name, or hashing an ID you can still look up is not de-identification.
When in doubt, treat it as PHI. You never get in trouble for over-protecting data.
A client sends a spreadsheet with names removed, but with appointment dates, ZIP codes, and visit type. Is it PHI?
Only what the job needs
HIPAA's minimum necessary standard means you use, share, and ask for the least PHI the task requires, and nothing for any other purpose.
In practice
- Build and test with synthetic data. Use real PHI only when the task can't be done without it, and only once Aprendio has confirmed you should.
- Pull the columns you need. A reminder workflow needs a name, phone number, and appointment time. It doesn't need diagnoses, insurance IDs, or the full chart.
- Don't browse. Never look up a patient out of curiosity: a neighbour, a public figure, someone you know. Access is logged, and "just looking" is a violation.
- Assigned work only. PHI is used only for the task Aprendio gave you. You may not keep it, reuse it for another client, or use it for anything of your own.
Things that are never allowed
Showing real client data in a portfolio, demo, case study, social post, or video. Use synthetic data or redact it completely.
Using PHI to train, fine-tune, or evaluate any AI model.
Selling, sharing, or marketing with PHI.
Handing PHI to anyone outside Aprendio and the client, including your own helpers, without Aprendio's written approval.
You're building a no-show reminder automation. The client's system can export the full patient record. What do you pull?
Approved tools only, especially AI
Most of our work runs through AI models, automation platforms, databases, and logs. Each one copies data somewhere. Sending PHI to a tool that isn't approved is a disclosure, even when you meant well.
Pasting a patient record into a consumer AI chat is a reportable breach. It doesn't matter that it was one record, that you deleted the chat afterwards, or that you turned off "improve the model".
What makes a tool approved
A tool may hold PHI only if Aprendio has approved it in writing and at least one of these is true:
- It is covered by a business associate agreement with Aprendio or the client, or
- It runs under a zero-data-retention arrangement Aprendio has confirmed, or
- It is self-hosted inside an environment Aprendio controls.
It must also run under an Aprendio or client account, never your personal account or personal API key. If a tool isn't on the approved list Aprendio gave you, it isn't approved. Ask before you use it.
Never with PHI
- ChatGPT, Claude.ai, Gemini, Copilot or any AI chat on a personal or non-approved account
- Your own API keys or subscriptions
- AI browser extensions and writing assistants
- Meeting recorders and note-takers (Otter, Fireflies, Fathom, and the like) on calls where patients may be discussed
- Personal Google Drive, Dropbox, iCloud, Gmail
- WhatsApp, SMS, or personal messaging
- Loom or screen recorders on personal accounts
Only when on Aprendio's approved list
- Aprendio's AI model accounts configured under a BAA or zero retention
- Aprendio's self-hosted automation platform (n8n)
- Databases and storage inside Aprendio's environment
- The client's own systems, with accounts the client issued you
- Communication channels Aprendio designates for PHI
The traps specific to our work
Coding agents
Claude Code, Cursor, Copilot and similar tools send what they read (files, query results, terminal output) to a model provider. If a repo, database, or log contains PHI, the agent is disclosing it. Point agents at synthetic data, or use them on PHI only under an Aprendio account that's approved for it.
Automation history
n8n saves the full input and output of every node in its execution history. A workflow that processes claims is quietly storing claims. Configure workflows so successful runs don't keep execution data, or prune it on the shortest schedule Aprendio approves, and never route PHI into an error notification that posts to Slack or email.
Logs and error tracking
Error trackers, analytics, and application logs often capture whole request bodies. Don't log PHI. Scrub fields before they're sent, and use only approved logging tools.
Source control
Never commit real exports, fixtures built from real data, or credentials that reach PHI. Git history is permanent and copied to every clone.
You pasted a failing n8n execution into your personal Claude.ai account to debug it, then noticed it contained a patient's name and insurance ID. What now?
Securing your accounts and devices
These are Aprendio's minimum requirements (Schedule A of the subcontractor BAA) for anyone who can reach PHI. Use the checklist to check your own setup now.
Accounts
- Multi-factor authentication everywhere that can reach PHI or an Aprendio system, including the email you use for the work. Use an authenticator app, passkey, or hardware key. SMS is a last resort.
- Your own account, always. Never share log-ins, and never let someone else work under your account.
- Unique passwords in a password manager.
- Aprendio-controlled access. You reach PHI only through accounts Aprendio or the client issued, which Aprendio can switch off on the first day your access ends. Don't create your own API keys, forwarding rules, webhooks, or integrations that touch PHI without approval.
Devices
- Full-disk encryption on: FileVault on Mac, BitLocker on Windows. Modern phones encrypt when a passcode is set.
- Automatic security updates on, on a supported operating system.
- Screen lock of 5 minutes or less, plus a password or biometric log-in.
- Anti-malware and firewall on.
- Not shared with family members or anyone else.
- Listed with Aprendio. Tell Aprendio every device you use to reach PHI, and update the list within 5 business days when that changes.
Where PHI may live
Not on your device. Don't download, sync, or save PHI locally, on USB drives, or in personal cloud storage or email. If a task genuinely needs a temporary local copy, get Aprendio's approval first, keep it encrypted, and delete it (trash included) the same day.
Where you work
- Use a VPN or Aprendio-approved connection on public or shared Wi-Fi.
- Position your screen so others can't read it, and lock it whenever you step away.
- Don't access PHI from outside the United States without Aprendio's written approval naming the country. Many client agreements forbid offshore access.
Self-check (for you only, not graded)
Anything unchecked: fix it before you touch PHI.
Encryption, testing, and the coming Security Rule
In January 2025, HHS proposed the biggest update to the HIPAA Security Rule since it was written. Aprendio holds itself and its contractors to the proposed standard now, so the final rule doesn't catch us out.
What the proposal changes
Today many safeguards are "addressable", which lets an organisation document why it skipped them. The proposal makes nearly all of them mandatory, including:
| Requirement | Standard Aprendio applies now |
|---|---|
| Encryption | ePHI encrypted at rest and in transit, everywhere |
| Multi-factor authentication | On every system that can reach ePHI |
| Asset inventory and network map | Every device and system that touches ePHI is listed and reviewed at least yearly |
| Vulnerability scanning | At least every 6 months |
| Penetration testing | At least every 12 months |
| Patching | Critical fixes within 15 days, high-risk within 30 |
| Recovery | Critical systems restorable within 72 hours |
| Business associate oversight | Business associates verify their safeguards in writing every year; 24-hour notice when a contingency plan is activated |
| Access termination | 24-hour notice when someone's access should end |
What that means for you
- Keep your device list current so Aprendio's inventory and risk analysis are accurate.
- Don't run your own servers or databases with PHI. Aprendio's environment carries the scanning and pen testing. If Aprendio approves a system you operate, it takes on all of the obligations above.
- Certify every year. Contractors sign a yearly statement that they still meet the requirements, and Aprendio relies on it when it verifies its own safeguards to clients.
- Tell Aprendio within 24 hours when anyone working through you should lose access.
Why encryption matters so much: if a properly encrypted laptop is stolen, the data on it is generally not "unsecured PHI", and the loss may not be a reportable breach. If the same laptop is unencrypted, it almost certainly is. Encryption turns a crisis into paperwork.
A client's workflow would be easier if you ran a small database on your own cloud account to cache patient records. What's the rule?
Incidents: tell Aprendio within 24 hours
Reporting quickly is always the right call. A late report does more damage than the original mistake.
What to report
Anything that might have exposed PHI or the accounts that reach it, even if you're not sure:
- PHI sent to the wrong person, or to a tool that isn't approved
- A lost or stolen laptop, phone, security key, or password
- Clicking a phishing link or entering your password on a fake page
- An MFA prompt you approved but didn't start
- A share link, bucket, or folder that was more open than it should have been
- Malware, ransomware, or odd behaviour on a device you work from
- Anyone accessing PHI they shouldn't, including someone working through you
- An outage or an emergency plan kicking in on a system that holds PHI
How to report
1. Email michael@aprendio.ai with SECURITY INCIDENT in the subject line.
2. Also message or call Michael directly.
3. Keep trying both until someone acknowledges it. The report isn't made until it's received.
The 24 hours start at discovery: the moment you knew, or would have known if you'd been reasonably careful. Give what you know: what happened, when, what data and systems, who might have received it, and what you've done so far. Details can follow.
Do
- Contain it if you safely can: revoke the link, disconnect the device, change the password
- Write down a timeline while it's fresh
- Preserve everything: logs, emails, the device
- Cooperate with Aprendio's investigation
Don't
- Delete evidence, chats, or logs
- Contact the client, the patients, or regulators yourself. Aprendio handles notification
- Wait until you're sure it's serious
- Try to fix it quietly
Why 24 hours?
A client practice has 60 days to notify patients after it learns of a breach, and less under some state laws (Florida allows 30). Many client agreements give Aprendio only a few days. Your 24 hours leave room for each link in the chain to do its part.
Your laptop is stolen from your car. FileVault was on and no PHI was stored on it. Do you report it?
Phishing and pretexting
Attackers go after vendors because vendors often have access to several healthcare organisations at once. You're a target because of what you can reach.
What it looks like
- An email from a "client" asking you to send the patient list to a new address because "our office email is down"
- A shared document link that opens a Google or Microsoft log-in page
- A flood of MFA prompts late at night, hoping you'll tap "approve" to make them stop
- A message that seems to come from Michael asking you urgently to buy gift cards, change payment details, or grant someone access
- A "support" call asking you to read out a code that was just texted to you
The rules
- Verify through a second channel you already know. Call the number you already have, or message the person on Slack. Never use the contact details in the suspicious message.
- Never approve an MFA prompt you didn't start. Deny it and report it.
- Never read out or forward a one-time code. Nobody legitimate asks for one.
- Urgency is the tell. Real requests can wait five minutes for you to verify.
- Report it, even if you didn't click. It helps Aprendio warn everyone else.
At 11pm you get three MFA push notifications for your Aprendio Google account. You weren't signing in. What do you do?
Outside requests and ending an assignment
If someone outside Aprendio asks for PHI
- A patient asks you for their records, a correction, or who has seen their data: forward it to Aprendio within 2 business days and don't reply. The client practice has legal deadlines for these requests, and they run through Aprendio.
- A subpoena, court order, or law enforcement request: tell Aprendio within 2 business days, before you disclose anything, unless the law forbids telling us.
- Anyone else, including a friendly vendor or another contractor: PHI goes only to the people Aprendio has approved.
Anyone working through you
If you're a contractor with your own staff or helpers, only people Aprendio has approved by name may touch PHI, and each must complete this training. You may not use your own subcontractors for PHI work without Aprendio's written approval and a BAA between you and them. You're responsible for everyone who works through you.
When an assignment ends
Access is switched off on the first day your assignment ends. Within 5 business days you:
- Sign out of and hand back every Aprendio and client account, credential, token, and device.
- Delete all PHI everywhere it may have ended up: Downloads, Desktop, trash, email, cloud drives, chat histories, AI tool histories, recordings.
- Confirm in writing to Aprendio that you've done it.
Every year
Retake this training every 12 months, and whenever Aprendio asks after a change in law or an incident. Contractors also sign a yearly statement that they still meet the security requirements.
A patient finds your email and asks you for a copy of everything the reminder system holds about them. What do you do?
Final exam
22 scenario questions. You need 80% (18 correct) to pass. The questions and answers are shuffled on each attempt, and you can retake the exam as often as you need.
Acknowledgement
Check each statement to confirm it, then type your name to sign.
You passed. Here's your certificate.
Save it as a PDF: choose Print, then Save as PDF as the destination.
- Certificate ID
- Completed
- Exam score
Valid through
Exam score
Chief Executive Officer, Aprendio, LLC
What happens next
- Save the certificate as a PDF and send it to michael@aprendio.ai. The email button above fills in your completion record; attach the PDF before you send.
- Contractors: Aprendio will send you the Subcontractor Business Associate Agreement through sign.aprendio.ai. Enter the certificate ID and completion date shown above when you sign it.
- Don't access any PHI until Aprendio confirms your agreement is signed and your accounts are set up.
- Your training expires in 12 months. You'll need to retake it before then.
Aprendio can check a certificate at the verification page.
Verify a certificate
Enter the details exactly as they appear on the certificate and in the completion email.