Appearance
Security Awareness Training Completion Log
Requirement: HIPAA §164.308(a)(5)(i) — Security Awareness and Training. SOC2 CC2.2 — evidence of security awareness training for all personnel.
Owner: Rory (coordination), Adriana (HR records) Update frequency: After each training event — do not batch; update within 5 business days Auditor use: This log is provided as-is to auditors as evidence of training completion.
Training Programs in Scope
| Program | Frequency | Format | Provider |
|---|---|---|---|
| Security Awareness — Annual Refresher | Annual (Q1) | Online course + quiz | KnowBe4 |
| HIPAA Privacy & Security | Annual (Q1) | Online course + quiz | KnowBe4 |
| Phishing Simulation | Monthly | Live phishing email + training if clicked | KnowBe4 |
| Incident Response Tabletop | Annual | Live facilitated exercise | Internal — Rory |
| New Employee Security Onboarding | At hire | Checklist + policy acknowledgment | Rory + Adriana |
How to Update This Log
After any training event:
- Add a row to the relevant table below
- Record: employee name, training name, completion date, method, pass/fail (for quizzes)
- Commit and push — this file is audit evidence, keep it current
- For phishing simulations: record results in the Phishing Simulations section; individual click data is in KnowBe4 portal (do not put names of who clicked in this file — summary only)
Annual Security Awareness Training — 2026
| Employee | Role | Training | Completed | Method | Result |
|---|---|---|---|---|---|
| Rory | Security Engineer / IT Lead | Security Awareness Annual Refresher | (pending) | KnowBe4 online | — |
| Rory | Security Engineer / IT Lead | HIPAA Privacy & Security | (pending) | KnowBe4 online | — |
| Kevin | T1 Domain Admin | Security Awareness Annual Refresher | (pending) | KnowBe4 online | — |
| Kevin | T1 Domain Admin | HIPAA Privacy & Security | (pending) | KnowBe4 online | — |
| Greg | T1 Domain Admin | Security Awareness Annual Refresher | (pending) | KnowBe4 online | — |
| Greg | T1 Domain Admin | HIPAA Privacy & Security | (pending) | KnowBe4 online | — |
| Adriana | Compliance Coordinator | Security Awareness Annual Refresher | (pending) | KnowBe4 online | — |
| Adriana | Compliance Coordinator | HIPAA Privacy & Security | (pending) | KnowBe4 online | — |
Add remaining employees as rows above. Every person with access to PHI systems must have an entry.
Target completion date: March 31, 2026 (Q1 deadline — MISSED) Revised deadline: August 31, 2026 — must complete before September SOC2 fieldwork Completion rate: 0/4 as of 2026-06-27 — ACTION REQUIRED: Rory + Adriana assign and complete KnowBe4 courses
New Employee Security Onboarding
| Employee | Start Date | Onboarding Checklist Completed | Policy Acknowledged | Completed By |
|---|---|---|---|---|
| (add at hire) |
Policy acknowledgment means the employee has read and signed the Acceptable Use Policy and Information Security Policy. Paper or digital signature both acceptable — retain copy. See Onboarding Security Checklist.
Phishing Simulation Results — 2026
Detailed click-through data is in the KnowBe4 portal. This table records summary results for audit evidence. Do not record individual names of who clicked.
| Month | Emails Sent | Click Rate | Training Assigned to Clickers | Notes |
|---|---|---|---|---|
| January 2026 | — | — | — | (pending — populate from KnowBe4) |
| February 2026 | — | — | — | |
| March 2026 | — | — | — | |
| April 2026 | — | — | — | |
| May 2026 | — | — | — | |
| June 2026 | — | — | — | |
| July 2026 | — | — | — | |
| August 2026 | — | — | — |
See Phishing Simulation Schedule for campaign configuration.
IR Tabletop Exercise — 2026
| Date | Participants | Scenario | Facilitator | Findings Documented |
|---|---|---|---|---|
(scheduled — see compliance/ir-tabletop-scenario-2026.md) | Rory, Kevin, Greg, Adriana | Ransomware | Rory | compliance/ir-tabletop-findings-template.md |
Annual Training — 2025 (Historical Reference)
| Employee | Training | Completed | Result |
|---|---|---|---|
| (populate from 2025 KnowBe4 records before audit) |
2025 records should be exported from KnowBe4 and added here before the September 2026 audit. Auditors will ask to see the prior year as part of Type II coverage.
Auditor Notes
If an auditor asks for training evidence:
- Point to this document for completion summary
- Offer KnowBe4 portal access (or export) for quiz scores and completion certificates
- For phishing simulations: KnowBe4 portal → Campaigns → export the campaign reports (summary view only — do not expose individual employee click data beyond what's needed)
- For policy acknowledgment: paper/digital signature files held by Adriana
Document History
| Date | Change | Author |
|---|---|---|
| May 2026 | Initial draft — establishes training completion log format for SOC2/HIPAA audit evidence | Rory |