GDPR & HIPAA training for life sciences

Compliance training that stands up as audit evidence

Privacy24 delivers data protection training written for pharmaceutical, biotech, CRO and medical device teams. Every module produces a per-employee record your quality function can produce on request.

Built and maintained by practising data protection officers.

Completion recordIllustrative example
Program
GDPR · Pharmaceutical
Modules
8
Progress
38%
  • Legal Foundations Completed
  • Consent Management Completed
  • Data Subject Rights Completed
  • Data MinimizationIn progress
  • Security MeasuresNot started

Certificate issued once all eight modules are complete.

EU regulationRegulation (EU) 2016/679
US healthcareHIPAA Privacy & Security Rules
SectorsPharma, biotech, CRO, medical devices
TenancySeparate environment per company

Curriculum

Two programs, sixteen modules, one record

Each program runs seven core modules and closes with a certificate module. Modules unlock in sequence, so nobody certifies without covering the ground.

GDPR · Pharmaceutical

8 modules
  1. 01Legal Foundations: GDPR BasicsThe six lawful bases applied to pharmaceutical operations
  2. 02Consent ManagementPatient data, research activities and marketing communications
  3. 03Data Subject RightsPatient, customer and employee requests, end to end
  4. 04Data MinimizationMinimization in research, manufacturing and marketing
  5. 05Security MeasuresTechnical and organizational controls for regulated data
  6. 06Data Breach ResponseIncident assessment, documentation and notification
  7. 07International Data TransfersGlobal transfers and regulatory submissions
  8. 08Certificate CenterProgram completion and certificate issue

HIPAA · Healthcare data

8 modules
  1. 01HIPAA FoundationsCovered entities, business associates and what counts as PHI
  2. 02The Privacy RulePermitted uses, disclosures and the minimum necessary standard
  3. 03Patient RightsAccess, amendment, accounting and restriction requests
  4. 04The Security RuleAdministrative, physical and technical safeguards for ePHI
  5. 05Business AssociatesVendor relationships and the agreements that govern them
  6. 06Breach Notification RuleAssessing and reporting breaches within required timelines
  7. 07Enforcement & PenaltiesOCR enforcement, penalty tiers and compliance culture
  8. 08HIPAA CertificateProgram completion and certificate issue

For administrators

From provisioning to evidence in four steps

  1. 01

    Provision

    Privacy24 creates your company environment and your first administrator account.

  2. 02

    Enroll

    Invite employees one by one or upload a CSV. Each person receives an activation link.

  3. 03

    Assign

    Assign the GDPR program, the HIPAA program or both, per employee.

  4. 04

    Evidence

    Track completion by person and download certificates when a program is finished.

Records & controls

What you can show an auditor

Per-employee completion

Module status, assessment score and completion date for every person, visible to the company administrator at any time.

Certificates on completion

A downloadable certificate is issued per program once all modules are complete, naming the employee and the date.

Separated access

Employee, company administrator and system administrator roles are distinct, and system administration is protected by multi-factor authentication.

Company isolation

Each company has its own employees, assignments and settings. No data is shared between tenants.

Access is provisioned by Privacy24

Employees and company administrators sign in with the credentials issued on activation. To set up an environment for your organization, speak to your Privacy24 engagement lead.

Sign in to the portal