Compliance
Healthcare Privacy & Compliance Training
Microlearning for staff who handle patient information
- Format
- Scrolling microlearning module
- Audience
- Healthcare employees and contractors
- Length
- 20 minutes
- Sections
- 5
Portfolio demonstration. This course was designed and built by Kirsten Alburg to show instructional design capability. It was not created for a client and is not built in Articulate.
Lesson 1
Why privacy training usually fails

Almost every privacy incident is caused by a well-intentioned person moving quickly, not by someone deciding to break a rule.
This module focuses on the moments where the right action is genuinely unclear — hallway conversations, shared screens, forwarded messages, and helpful favors.
Learning objectives
0/4 tracked- Why it matters
- Nearly every real HIPAA breach starts as an ordinary helpful act under time pressure — not as misconduct. Recognizing the moment is the skill.
- Where you will use it
- Hallway conversations, shared workstations, phone requests from family members, and anything you are asked to look up as a favor.
Lesson 2
What counts as protected information
Click to reveal
Appointment schedules, sign-in sheets, voicemails, billing records, photographs, and even a whiteboard with room assignments can identify a patient. If it connects a person to care, treat it as protected.
The minimum necessary standard
Access
Look at the record only when your role requires it for this specific task.
Share
Send the smallest amount of information that answers the question.
Request
Ask for the field you need, not the full record, when requesting from another team.
Lesson 3
A favor at the front desk
Branching practice — the favor escalates
One request, three decision points. Each choice changes what the next moment looks like.
Moment 1
A long-time colleague from another department asks you to confirm whether a mutual friend was admitted last night. She is worried, not malicious.
What do you do?

Scenario
A patient's adult daughter calls. She is clearly worried, says her mother is confused about her discharge instructions, and asks you to read the medication list over the phone. There is no authorization on file.
What is the compliant and humane response?
Lesson 4
Near-misses and reporting
What to do in the first hour
Contain
Stop the disclosure from spreading. Recall the message, lock the screen, retrieve the document.
Report
Notify your privacy officer the same day, even if you believe no harm occurred.
Record
Write down what happened, when, and who was involved while the details are accurate.
Learn
Ask what in the workflow made the error easy, and propose the change.
Knowledge check
You realize you emailed a patient summary to the wrong internal colleague. No patient outside the organization saw it. What should you do?
Lesson 5
Final quiz and reflection
Final quiz
Which action best reflects the minimum necessary standard?
Reflection
0 wordsResponses stay in your browser — this is a portfolio demonstration, nothing is submitted.
Take these with you
- Minimum necessary quick cardOne page: access, share, request.
- Near-miss reporting stepsContain, report, record, learn.
- Script: declining a phone request kindlyWording that protects the record and the relationship.
Job aid
Privacy Decision Card
Six checks that fit on a badge card, for the moments when someone is standing in front of you asking for something reasonable.
Performance support like this is what keeps the behavior alive after the course ends.
Course complete
Module complete. You can now recognize protected information across formats, apply the minimum necessary standard, and report a near-miss correctly.
Your scorecard
Curious0
XP earned
0
Interactions
0
Best streak
Badges
Points, streaks, and badges are part of the demonstration — they model how light gamification can keep adult learners moving without turning training into a game show.
Behind the build
Design Decisions
The instructional thinking behind this learning experience. Every interaction has a purpose; every design decision supports a learning objective.
Learning challenge
Privacy training is completed annually and forgotten immediately because it teaches the regulation rather than the thirty seconds in a hallway when someone asks for information they should not have.
Audience
- Primary learners
- Clinical and administrative staff in a healthcare setting.
- Prior knowledge
- Aware that HIPAA exists; unsure how it applies to a specific request under time pressure.
- Learning need
- Recognition speed — spotting a disclosure risk before answering, not afterwards.
- Context of use
- Recalled mid-shift, in a corridor, with a person waiting for an answer.
Learning objectives
- Recognise a protected-information request in an everyday interaction.
- Choose a response that protects privacy without damaging the relationship.
- Apply the minimum-necessary standard to a real disclosure decision.
- Report a suspected breach through the correct path and timeline.
Design case study
Read the full breakdownChallenge
Annual compliance training is widely disliked and poorly transferred. Staff can pass a rules quiz and still make the same three mistakes in practice.
Instructional strategy
Microlearning sections of three to four minutes each, built for interrupted completion. Rules are introduced only after the situation that makes them necessary, so the learner has a reason to care before receiving the standard.
Reflection
The strongest change during design was moving the reporting lesson before the final quiz. In the first draft, reporting felt like an appendix; learners need it framed as the recovery skill, not the paperwork.
Keep exploring
- Conservation & environmental educationConservation Learning ExperiencePlace-based stewardship training for visitors, volunteers, and seasonal staff
- Workforce DevelopmentAI Workplace EssentialsPractical, responsible AI use for everyday knowledge work
- Corporate L&DEmployee Onboarding ExperienceA guided first-week experience for new corporate hires