Open your policy binder and find the page that names your Privacy Official and your Security Official. If that page lists a person who left in 2023, or lists a job title instead of a human being, or does not exist, you have already failed the first of the HIPAA compliance officer duties — because the regulation does not ask you to have a compliance program in the abstract. It asks you to name someone and hold them accountable.

This article is for the person who holds that title, or the practice owner deciding who should. It walks through what the two required officials actually owe under 45 CFR Parts 160 and 164, what the deadlines are, and what the documented evidence looks like when a regulator asks. No theory. Dates, artifacts, and role assignments.

HIPAA Names Two Officials, Not One

The Privacy Rule at 45 CFR 164.530(a)(1) requires a covered entity to designate a privacy official responsible for developing and implementing privacy policies, plus a contact person for complaints. The Security Rule at 45 CFR 164.308(a)(2) separately requires a security official responsible for developing and implementing security policies and procedures.

Both are required implementation specifications. Neither is addressable. In a three-provider practice, the same person usually wears both hats — that is permitted, and it is what most small offices do. Write it down anyway, with a name, a date of designation, and a signature from ownership.

What is not permitted is leaving it implied. "Our office manager handles that" is not a designation. A one-page appointment memo, signed and dated, filed with your policies, is.

Who should not hold the role

Avoid appointing the person who also controls the IT budget and reports on IT performance without oversight. Avoid appointing a clinician who cannot get four uninterrupted hours a month. And avoid appointing your outside IT vendor as your Security Official — a business associate can advise, but the accountability under 164.308(a)(2) sits inside your organization.

HIPAA Compliance Officer Duties, Mapped to the Regulation

Here is the short answer for anyone searching this question. The core HIPAA compliance officer duties break into eight recurring obligations, each traceable to a specific citation:

  • Conduct and maintain a security risk analysis — 164.308(a)(1)(ii)(A). Accurate, thorough, organization-wide, covering all ePHI you create, receive, maintain, or transmit.
  • Run risk management — 164.308(a)(1)(ii)(B). Reduce identified risks to a reasonable level, with dated remediation decisions.
  • Write, approve, and revise policies — 164.316 and 164.530(i). Update when law or practice changes.
  • Train the workforce — 164.530(b) for privacy, 164.308(a)(5) for security awareness. New hires within a reasonable period; everyone after material changes.
  • Apply sanctions — 164.530(e) and 164.308(a)(1)(ii)(C). Documented discipline for workforce members who violate policy.
  • Execute and track business associate agreements — 164.308(b) and 164.502(e).
  • Handle patient rights requests — access, amendment, restriction, accounting of disclosures, and complaints under 164.520 through 164.528 and 164.530(d).
  • Run breach risk assessments and notifications — 164.400 through 164.414.

Everything else on your task list is a subroutine of one of those eight. The full regulatory text is on the HHS Security Rule page, and it is worth reading the actual citations rather than a vendor's summary.

The Calendar: What These Duties Look Like Across Twelve Months

Duties without dates become intentions. Put these on a real calendar with a named owner.

Annually, or whenever something material changes

Review and update the security risk analysis. HIPAA does not literally say "once a year" — it says the analysis must be accurate and current, and that you must review security measures periodically under 164.306(e). A new EHR module, a new location, a shift to remote scheduling staff, or a ransomware scare all trigger an update. In practice, annual review plus event-driven updates is the defensible cadence.

NIST's SP 800-66 Revision 2 remains the most useful free walkthrough of how to structure that analysis for a healthcare organization. It maps Security Rule standards to concrete assessment activities.

Also annually: review policies for accuracy, re-run workforce training, test your contingency plan under 164.308(a)(7), and reconcile your business associate list against your accounts payable ledger. That last one catches more gaps than any other single exercise.

By March 1 each year

Breaches affecting fewer than 500 individuals must be reported to HHS no later than 60 days after the end of the calendar year in which they were discovered. For 2025 discoveries, that filing window closes at the end of February 2026. Submit each one individually through the OCR breach reporting portal. If you had zero small breaches, document that determination too — a memo stating the log was reviewed and no reportable incidents occurred.

Quarterly

Pull user access reports from your EHR and any cloud systems. Verify terminated employees are gone. Review audit logs for after-hours access and same-surname record views. Document that you looked — a dated one-page summary with your initials is enough for a small practice, and its absence is what auditors notice.

Monthly and ongoing

New hire training before or shortly after system access. Offboarding checklist within 24 hours of separation. Complaint log entries. Incident log entries — including the ones you decide are not breaches, because that decision is itself the documentation required by 164.414(b).

The Vendor File Is Where Most Practices Lose

Every entity that creates, receives, maintains, or transmits PHI on your behalf needs a signed business associate agreement before it touches data. Your billing company. Your answering service. Your shredding vendor. Your cloud backup provider. Your transcription service. Your IT contractor with domain admin credentials.

Build the list from finance data, not memory. Export twelve months of vendor payments, and for each line ask one question: could this company see, store, or move patient information? Then check whether a signed BAA exists, when it was signed, and whether it addresses breach notification timelines, subcontractor flow-down, and return or destruction of PHI at termination.

The gap is almost always a small vendor onboarded quickly — the marketing agency running your appointment reminders, the new answering service. When you find one, close it before the next patient day. If drafting from scratch is what has stalled you, a six-step business associate agreement generator that exports signature-ready PDF and DOCX gets a compliant document in front of the vendor the same afternoon, with a one-time purchase rather than another subscription line item.

Track each agreement in a simple register: vendor name, service, PHI category, execution date, renewal or review date, and where the signed copy lives. That register is the first thing OCR asks for after a vendor-caused breach.

The Two Clocks Every Compliance Officer Must Know Cold

The 30-day access clock

When a patient requests a copy of their designated record set, you have 30 calendar days to act. One 30-day extension is permitted, but only with written notice to the patient stating the reason and the new date. Fees are limited to labor for copying, supplies, postage, and preparing an explanation if the patient asked for one — no per-page state schedule if it exceeds actual cost, no search fees.

OCR has pursued right-of-access cases against practices of every size, and most of those cases involve a records request that sat in someone's inbox. Review the HHS individual right of access guidance with your front desk, then log every request with its received date and fulfillment date.

The 60-day breach clock

Notification must go out without unreasonable delay and no later than 60 calendar days after discovery — not after your investigation concludes. Discovery is the first day any workforce member knew or reasonably should have known.

For breaches affecting 500 or more individuals in a single state or jurisdiction, you also notify prominent media outlets and HHS contemporaneously with individual notice. The HHS breach notification rule page lays out the content requirements for the notice itself — five elements, all mandatory.

Before any of that, you run the four-factor risk assessment: nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated. Impermissible use or disclosure is presumed to be a breach unless you document a low probability of compromise. Write that assessment down every time, even for the obvious non-events.

What "Documented" Actually Means

Under 164.316(b), policies, procedures, and any required action, activity, or assessment must be kept in writing for six years from creation or the date last in effect, whichever is later. The Privacy Rule imposes the same six-year retention at 164.530(j).

Six years is longer than most people's tenure in the role. That means your successor must be able to reconstruct your decisions from the file alone. Practically, your evidence set should include:

  1. Signed designation memos for the Privacy and Security Officials, with effective dates.
  2. The current risk analysis, plus every prior version.
  3. A risk management plan showing what you fixed, what you accepted, and why.
  4. Policy documents with version numbers and approval dates.
  5. Training rosters with individual names, dates, and content covered.
  6. The BAA register and every executed agreement.
  7. The incident log, including non-breach determinations.
  8. Sanction records, complaint records, and access request logs.

If assembling that set from scratch is the obstacle, platforms that generate risk analysis reports and the full policy document set shorten the drafting time considerably — but the review, approval, and ongoing maintenance still belong to you. No product confers HIPAA certification; HHS does not certify or endorse compliance tools, and any vendor claiming otherwise is selling you a badge, not a defense.

What Changed Recently, and What Is Still Pending

In January 2025, HHS published a proposed rule to substantially strengthen the Security Rule — removing the addressable/required distinction, mandating asset inventories and network maps, and imposing explicit encryption and multifactor authentication expectations. As of this writing in December 2025, it is a proposal, not law. Do not rewrite your program around it. Do read it, because it signals what OCR already believes reasonable practices should be doing.

Separately, the 2024 final rule aligning 42 CFR Part 2 substance use disorder records with HIPAA carries a compliance date of February 16, 2026. If your practice holds Part 2 records, your Notice of Privacy Practices, consent forms, and breach procedures need attention now, not in January.

Your First 90 Days If You Just Got the Job

Days 1–30: sign the designation memo. Inventory every system that holds ePHI, including phones and the scanner that emails PDFs. Pull the vendor payment list and start the BAA reconciliation.

Days 31–60: complete or refresh the risk analysis. Rank findings by likelihood and impact. Fix the free items immediately — disable dormant accounts, turn on full-disk encryption, enforce screen locks.

Days 61–90: build the risk management plan with owners and dates. Deliver workforce training tied to the findings, not generic slides. Set the recurring calendar entries so the next twelve months of HIPAA compliance officer duties arrive as scheduled tasks instead of emergencies.

The role is not exotic. It is a set of recurring obligations, each with a citation, a deadline, and a document that proves you did it. The practices that get hurt are rarely the ones with a bad program — they are the ones with no named owner and no paper trail.

Start with the vendor file. It is the fastest gap to close and the most common finding after a breach. Pull your payment list this week, identify every business associate without a current signed agreement, and generate a signature-ready BAA for each one before the next patient day.