Skip to content

Security Awareness Training Completion Log

Requirement: HIPAA §164.308(a)(5)(i) — Security Awareness and Training. SOC2 CC2.2 — evidence of security awareness training for all personnel.

Owner: Rory (coordination), Adriana (HR records) Update frequency: After each training event — do not batch; update within 5 business days Auditor use: This log is provided as-is to auditors as evidence of training completion.


Training Programs in Scope

ProgramFrequencyFormatProvider
Security Awareness — Annual RefresherAnnual (Q1)Online course + quizKnowBe4
HIPAA Privacy & SecurityAnnual (Q1)Online course + quizKnowBe4
Phishing SimulationMonthlyLive phishing email + training if clickedKnowBe4
Incident Response TabletopAnnualLive facilitated exerciseInternal — Rory
New Employee Security OnboardingAt hireChecklist + policy acknowledgmentRory + Adriana

How to Update This Log

After any training event:

  1. Add a row to the relevant table below
  2. Record: employee name, training name, completion date, method, pass/fail (for quizzes)
  3. Commit and push — this file is audit evidence, keep it current
  4. For phishing simulations: record results in the Phishing Simulations section; individual click data is in KnowBe4 portal (do not put names of who clicked in this file — summary only)

Annual Security Awareness Training — 2026

EmployeeRoleTrainingCompletedMethodResult
RorySecurity Engineer / IT LeadSecurity Awareness Annual Refresher(pending)KnowBe4 online
RorySecurity Engineer / IT LeadHIPAA Privacy & Security(pending)KnowBe4 online
KevinT1 Domain AdminSecurity Awareness Annual Refresher(pending)KnowBe4 online
KevinT1 Domain AdminHIPAA Privacy & Security(pending)KnowBe4 online
GregT1 Domain AdminSecurity Awareness Annual Refresher(pending)KnowBe4 online
GregT1 Domain AdminHIPAA Privacy & Security(pending)KnowBe4 online
AdrianaCompliance CoordinatorSecurity Awareness Annual Refresher(pending)KnowBe4 online
AdrianaCompliance CoordinatorHIPAA Privacy & Security(pending)KnowBe4 online

Add remaining employees as rows above. Every person with access to PHI systems must have an entry.

Target completion date: March 31, 2026 (Q1 deadline — MISSED) Revised deadline: August 31, 2026 — must complete before September SOC2 fieldwork Completion rate: 0/4 as of 2026-06-27 — ACTION REQUIRED: Rory + Adriana assign and complete KnowBe4 courses


New Employee Security Onboarding

EmployeeStart DateOnboarding Checklist CompletedPolicy AcknowledgedCompleted By
(add at hire)

Policy acknowledgment means the employee has read and signed the Acceptable Use Policy and Information Security Policy. Paper or digital signature both acceptable — retain copy. See Onboarding Security Checklist.


Phishing Simulation Results — 2026

Detailed click-through data is in the KnowBe4 portal. This table records summary results for audit evidence. Do not record individual names of who clicked.

MonthEmails SentClick RateTraining Assigned to ClickersNotes
January 2026(pending — populate from KnowBe4)
February 2026
March 2026
April 2026
May 2026
June 2026
July 2026
August 2026

See Phishing Simulation Schedule for campaign configuration.


IR Tabletop Exercise — 2026

DateParticipantsScenarioFacilitatorFindings Documented
(scheduled — see compliance/ir-tabletop-scenario-2026.md)Rory, Kevin, Greg, AdrianaRansomwareRorycompliance/ir-tabletop-findings-template.md

Annual Training — 2025 (Historical Reference)

EmployeeTrainingCompletedResult
(populate from 2025 KnowBe4 records before audit)

2025 records should be exported from KnowBe4 and added here before the September 2026 audit. Auditors will ask to see the prior year as part of Type II coverage.


Auditor Notes

If an auditor asks for training evidence:

  1. Point to this document for completion summary
  2. Offer KnowBe4 portal access (or export) for quiz scores and completion certificates
  3. For phishing simulations: KnowBe4 portal → Campaigns → export the campaign reports (summary view only — do not expose individual employee click data beyond what's needed)
  4. For policy acknowledgment: paper/digital signature files held by Adriana

Document History

DateChangeAuthor
May 2026Initial draft — establishes training completion log format for SOC2/HIPAA audit evidenceRory

Internal use only — Cirius Group