Get HIPAA Guidance

HIPAA Compliance for Healthcare Volunteers

Comprehensive guide to volunteer management, training, and PHI access control in healthcare organizations

Quick Answer: Healthcare volunteers who access or may encounter PHI must complete HIPAA training, sign confidentiality agreements, pass background checks, and follow the same privacy and security practices as employees.

Volunteer Workforce Classification

Under HIPAA, volunteers are treated as workforce members if they are under the direct control and supervision of the organization, regardless of compensation status. This means:

Types of Healthcare Volunteers

Volunteer Screening and Background Check Requirements

Criminal Background Screening

Disqualifying Factors

Volunteers may be disqualified for:

  • Violent crime convictions (especially within 10 years)
  • Healthcare fraud or theft convictions
  • Drug trafficking or distribution convictions
  • Sex offenses or crimes against children
  • Any felony within past 5 years
  • OIG Exclusions List status
  • Healthcare licensing sanctions/revocations

OIG Exclusions List Screening

Reference Checks

Volunteer Orientation and HIPAA Training

Pre-Service Requirements

HIPAA Training Content (by Volunteer Type)

All Volunteers with PHI Access:

Patient-Facing Volunteers (additional):

EHR/Clinical Access Volunteers (additional):

Training Documentation

Volunteer Confidentiality Agreement Template

VOLUNTEER CONFIDENTIALITY AGREEMENT

I, _________________ (Volunteer Name), understand that as a volunteer at [ORGANIZATION NAME], I may have access to or become aware of Protected Health Information (PHI) concerning patients and their medical treatment.

I acknowledge and agree that:

  1. I will maintain the strict confidentiality of all patient information I encounter.
  2. I understand that patient information is protected by federal HIPAA regulations and organizational policy.
  3. I will not discuss, disclose, or share any patient information with any unauthorized person.
  4. I will not access patient information beyond what is necessary for my assigned duties.
  5. I will comply with all organizational security and confidentiality policies.
  6. I will immediately report any suspected unauthorized access to patient information.
  7. My confidentiality obligations continue even after my volunteer service ends.
  8. Violation of these confidentiality requirements may result in termination and legal action.

I have received training on HIPAA and organizational confidentiality policies and understand my responsibilities.

Volunteer Signature: _________________________

Volunteer Printed Name: _________________________

Date: _________________________

Volunteer Coordinator Signature: _________________________

Date: _________________________

Access Control and Monitoring

Limiting Access by Role

Physical Access Controls

Ongoing Monitoring

Volunteer Termination and Off-Boarding

At End of Service

Post-Termination Obligations

Record Retention

Common Volunteer Roles and PHI Risk Assessment

High PHI Risk Volunteers

Moderate PHI Risk Volunteers

Low PHI Risk Volunteers

Frequently Asked Questions

Q: Do volunteers need the same background checks as employees?
A: Yes. If volunteers access or may encounter PHI, they must have the same criminal background check, OIG Exclusions List screening, and documentation as employees. The standard doesn't differ based on compensation status.
Q: What if a volunteer refuses to sign the confidentiality agreement?
A: They cannot be granted access to PHI or assigned to any position involving patient contact or sensitive areas. The confidentiality agreement is a prerequisite for any volunteer role involving PHI. Without the signed agreement, they may only volunteer in areas with no possible PHI exposure.
Q: Can we use volunteers who are under 18?
A: Yes, but with restrictions. Minor volunteers should be placed only in roles with minimal PHI exposure. Background checks may be limited by state law for minors. Obtain parental consent and provide additional supervision. Avoid roles with direct EHR or medical record access.
Q: How often should we re-screen volunteers for OIG exclusion status?
A: At minimum quarterly for regular volunteers, and at least annually for all volunteers. Best practice is monthly screening. Document all screening dates and results in the volunteer file to demonstrate compliance.

Manage Compliant Volunteer Programs

Medcurity provides volunteer onboarding templates, screening checklists, and HIPAA training materials.

Access Volunteer Templates