By Joseph Boyd, Licensed Virginia Insurance ConsultantLast updated
Direct answer
Several federal and state regulations require cybersecurity awareness training for employees, including HIPAA, the FTC Safeguards Rule, PCI DSS, New York's cybersecurity regulation, and Virginia's Insurance Data Security Act. Whether a specific requirement applies to your organization depends on your industry, location, and the type of data you handle.
Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check
Published · Last reviewed
Scope: Cybersecurity awareness training requirements in selected United States regulations · Jurisdiction: United States
General educational and informational content. Not legal, insurance, or coverage advice. Requirements depend on your facts, contracts, policy language, and applicable law.
Training requirements by regulation
| Regulation | What It Requires | Citation | Who It Generally Applies To |
|---|---|---|---|
| HIPAA Security Rule | Requires a security awareness and training program for all workforce members, including management | 45 CFR 164.308(a)(5)(i) | Healthcare providers, health plans, and their business associates that handle electronic protected health information |
| FTC Safeguards Rule | Requires security awareness training for all personnel, updated to reflect the organization's risk assessment | 16 CFR 314.4(e) | Non-bank financial institutions, including auto dealers, mortgage brokers, tax preparers, and retailers offering financing |
| PCI DSS v4.0 | Requires a formal, documented security awareness program, with training at hire and at least annually | Requirement 12.6 | Any organization that stores, processes, or transmits payment card data |
| New York DFS Cybersecurity Regulation | Requires regular cybersecurity awareness training for all personnel, updated to reflect identified risks | 23 NYCRR 500.14 | Banks, insurers, and other entities licensed by the New York Department of Financial Services |
| Virginia Insurance Data Security Act | Requires licensees to provide personnel with cybersecurity awareness training as part of a written information security program | Va. Code 38.2-623 | Insurance licensees operating in Virginia |
| NAIC Insurance Data Security Model Law | The model law that Virginia and a number of other states adopted, generally including a personnel training requirement | Varies by state adoption | Insurance licensees in states that have adopted the model law |
This table identifies training provisions that exist in the text of each regulation. It does not determine whether a specific regulation applies to your organization, which depends on your industry, the states you operate in, and the type of data you handle. Confirm applicability with counsel or another appropriate adviser before relying on this page for a compliance decision.
Frequently asked questions
Does completing security awareness training satisfy a specific regulation?
Training is one requirement among several under most of these regulations. Satisfying a specific regulation typically requires the training to meet that regulation's frequency, content, and documentation standards, in addition to other program elements the regulation requires.
Which regulation applies to my business?
Applicability depends on your industry, the states you operate in, and the type of data you handle. A regulatory applicability assessment can help identify which requirements are relevant to your specific situation.
