Most practices answer this question with a payroll report. HIPAA does not define it that way, and the gap between the two lists is where the untrained people are.
The definition, and the phrase that does the work
45 CFR 164.103 defines workforce as employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such entity, whether or not they are paid by the entity.
Four words carry the whole thing: whether or not paid. The test is control, not compensation and not employment status. If you direct how the work gets done, that person is workforce — and workforce members must be trained under 164.530(b) and are covered by your sanctions policy under 164.530(e).
People who are usually workforce and usually missed
Volunteers. Named explicitly in the definition. A volunteer who escorts patients, sits at a front desk, or files anything is workforce.
Students, residents, and trainees. Also named explicitly. A student on rotation is workforce for the site supervising them, regardless of who enrols or pays them.
Temps and per diem staff. A temp placed by an agency but supervised day to day by you is generally under your direct control. The agency’s own training does not automatically discharge your obligation, and it almost never covers your policies — which is what 164.530(b) actually asks for.
Scribes. Frequently engaged through a third party and functionally inside every encounter. Whether they are your workforce or a business associate’s turns on who controls their work; either way somebody owes them training, and it is worth settling in writing which of you it is.
Owners, partners, and practice managers. The Security Rule is explicit that the awareness program covers all workforce members including management. Leadership skipping training is common and is exactly backwards — they usually hold the broadest access.
Non-clinical staff with incidental exposure. Billing, scheduling, records, IT support you employ directly, and maintenance staff who work in areas where PHI is visible. Exposure does not have to be clinical to be exposure.
People who are usually not workforce
Business associates and their staff. Your billing company, cloud fax vendor, or outside IT firm are not your workforce. Their obligations come through the business associate agreement, and they are responsible for training their own people. You do not train them — you contract with them.
The line can blur. An outsourced IT technician who takes direction from you day to day starts to look like workforce; one who performs services under their own supervision looks like a business associate. It is a facts-and-circumstances judgement, and the right response to an ambiguous case is to write down the reasoning rather than to leave it unexamined.
Independent contractors not under your direct control. A covering physician who runs their own practice and sees patients under their own policies is generally not your workforce. One who works your schedule in your rooms under your procedures generally is.
Why the answer costs money in both directions
Training too few people is the compliance risk: an untrained volunteer with PHI access is a gap you cannot close retroactively after an incident, and it is a gap an investigator can find by asking one person a single question.
Training too many is a budget question, and it is the reason the definition gets quietly narrowed in practices that pay per seat. That is a bad reason to under-scope a legal obligation — and it is worth checking whether your training actually charges you that way before letting cost decide who gets trained.
How to build the list
Start from access rather than from payroll. Walk the question: who could see, hear, handle, or retrieve PHI in the course of doing something for this practice? Then ask, for each: do we direct how they do that work?
Anyone who is a yes on both is workforce. Anyone who is a yes on the first and a no on the second is probably a business associate relationship, and the follow-up question is whether you have a signed agreement.
Keep the list as a living document tied to onboarding and offboarding, not as a one-time exercise. The most common way this decays is a role that gets added — a new volunteer programme, a new scribe arrangement — without anyone revisiting who is in scope.
Frequently Asked Questions
Do unpaid volunteers really need HIPAA training?
Yes. The definition at 164.103 names volunteers explicitly and says the test applies whether or not the person is paid. If a volunteer performs work for you under your direction and could encounter PHI, they are workforce.
Does our staffing agency's training count for temps?
Not on its own. The Privacy Rule requires training on your policies and procedures, which an agency course will not cover. Treat agency training as useful background and provide practice-specific training, and settle in writing which party is responsible before the placement starts.
Do we train our billing company or IT vendor?
Generally no — they are business associates, obligated through the agreement you sign with them and responsible for their own workforce. If you are directing their staff's day-to-day work, though, the relationship may look more like workforce than vendor, and that is worth examining rather than assuming.
Does the owner have to take the training?
Yes. The Security Rule's awareness and training standard applies to all members of the workforce including management, and the Privacy Rule's training requirement has no carve-out for owners. Leadership typically holds the broadest access, which makes the exemption people assume exists the least defensible one.
What about someone who never touches records but works in clinical areas?
If they perform work for you under your control and could encounter PHI — overhearing it, seeing a screen, handling paper on the way to a shredder — they are workforce. Scope the training to what their role actually requires; the rule asks for training appropriate to the person's functions, not identical training for everyone.
How GuardWell handles this
GuardWell does not charge per seat on the HIPAA training plans, so scoping the workforce list correctly is a compliance decision rather than a budget one. Staff are added with a role, training follows from that role, and leaving the practice closes the assignment rather than leaving it open forever.
See the HIPAA training plans, or the business associate agreement module for the relationships that sit on the other side of this line.
Part of our guide to
Compliance TrainingSee how GuardWell helps medical practices manage compliance training end to end — checklists, policies, training, and audit-ready documentation in one platform.
Ready to simplify compliance?
GuardWell brings HIPAA, OSHA, OIG, and 14 more compliance modules into one affordable platform built for medical practices. Start your 7-day free trial today.
Start free trialRelated Articles
How Often Is HIPAA Training Required? The Rule Never Says Annually
HIPAA names no training interval. The Privacy Rule gives three triggers and the Security Rule asks for a periodic program — and knowing that changes what you should actually be documenting.
TrainingNew-Hire HIPAA Training: What “Reasonable Period of Time” Actually Means
HIPAA requires training new workforce members within a reasonable period and never defines it. The practical standard is narrower than the phrase sounds — and some states replace it with a real deadline.
ComplianceDo I Need a BAA With My Cloud Fax, IT Company, or Answering Service?
If a vendor touches patient information on your behalf, you probably need a Business Associate Agreement. Here is how to identify which vendors require BAAs and what to do if you are missing them.
HIPAATerminated Employee Still Has EHR Access: Immediate Steps to Contain the Risk
You discovered a terminated employee still has EHR access. Immediate containment steps, audit log review, breach analysis, and a real offboarding checklist.
