Open your policy binder and turn to the page that names your privacy official. If that page has a name on it, a signature, and a date, you have satisfied the most basic requirement of the HIPAA privacy officer role. If it says "Office Manager" with no name, or the name belongs to someone who left in 2023, you have a documentation gap that an OCR investigator will find in the first fifteen minutes of a records request.

This article is for the person who has to fill that page and then live up to it. It covers what 45 CFR 164.530 actually obligates, which deadlines the privacy official personally owns, what the evidence looks like when someone asks, and how small practices staff the job without pretending they have a full-time compliance department.

What Does a HIPAA Privacy Officer Do?

A HIPAA privacy officer is the workforce member a covered entity designates in writing to develop and implement its privacy policies and procedures. The core duties are:

  • Write, approve, and update the practice's privacy policies and Notice of Privacy Practices
  • Train workforce members on those policies and document each session
  • Receive and resolve patient privacy complaints, and log the disposition of each
  • Run the risk analysis and breach risk assessment when PHI is disclosed improperly
  • Meet the 30-day clock on records requests and the 60-day clock on breach notification
  • Confirm every vendor touching PHI has a signed business associate agreement on file
  • Apply sanctions when staff violate policy, and document what sanction was applied
  • Retain all of the above for six years from creation or last effective date

The designation itself must be documented. That is not a best practice — it is 164.530(a)(2), and the six-year retention rule at 164.530(j) applies to the designation document the same way it applies to everything else.

Two Names, Not One: Privacy Official and Security Official

The Privacy Rule at 164.530(a)(1) requires a privacy official. It separately requires a contact person or office to receive complaints and provide information about the Notice of Privacy Practices. The Security Rule at 164.308(a)(2) requires a security official responsible for the safeguards protecting electronic PHI.

In a 40-provider group these are three different people. In a six-person dental practice they are frequently the same person wearing three hats, which the rule permits. What the rule does not permit is leaving any of them unassigned.

Write all three designations into one signed memo. Date it, have the owner or governing body sign it, and re-sign it whenever the person changes. When your Privacy Rule obligations get audited, that memo is the first exhibit.

Independence Matters More Than Title

The privacy official needs authority to stop a process. If your billing lead is also the privacy official, and the practice owner tells her to keep sending statements to an address a patient disputed, she needs a path to escalate. Put that path in writing — usually direct access to the owner or the board, bypassing her normal supervisor on privacy matters.

The Deadlines the HIPAA Privacy Officer Role Owns Personally

These are the clocks that start without warning. Every one of them has landed a practice in an OCR resolution agreement.

30 Days for a Records Request

A patient asks for a copy of their chart. You have 30 calendar days to provide it, with one 30-day extension available if you notify the patient in writing of the reason and the new date. That is one extension, not a rolling series. OCR's right of access guidance is explicit about form and format, third-party directives, and fee limits — fees must be reasonable and cost-based, and you cannot charge for search and retrieval time.

OCR's Right of Access Initiative has produced dozens of settlements since 2019, most involving small practices that simply did not respond. The dollar amounts are usually modest. The corrective action plans are not — they typically run two years with reporting obligations.

Your privacy official should keep a simple log: date requested, requester, what was asked for, date fulfilled, format delivered, fee charged. Six columns. That log is your defense.

60 Days from Discovery for Breach Notification

Notification to affected individuals goes out without unreasonable delay and no later than 60 calendar days after discovery. Discovery means the first day the incident is known — or should reasonably have been known — to any workforce member, not the day the privacy official was told.

For breaches affecting 500 or more residents of a state or jurisdiction, you also notify prominent media and HHS within that same 60 days. For breaches under 500, you log them and submit to HHS no later than 60 days after the end of the calendar year. For any small breach that occurred during 2025, that filing is due by March 1, 2026. If you had three lost-fax incidents in July, they go on that submission.

Every submitted breach lands in the public HHS breach reporting portal. Read the entries for practices your size before you decide your risk is theoretical.

60 Days for Amendments, 60 Days for Accountings

Requests to amend the record get 60 days with one 30-day extension. Requests for an accounting of disclosures cover a six-year lookback and also get 60 days with one 30-day extension. Most practices receive very few of these, which is exactly why staff do not recognize them when they arrive. Train the front desk to route anything that looks like a request straight to the privacy official the same day.

Training: Who, When, and What You Keep

Section 164.530(b) requires training for all workforce members on the policies and procedures relevant to their functions. New workforce members get trained within a reasonable time after joining. When a policy materially changes, affected staff get retrained within a reasonable time after the change takes effect.

The Privacy Rule does not name an annual interval. The Security Rule's security awareness requirement at 164.308(a)(5) contemplates ongoing reminders. Annual training plus event-driven refreshers is the practical standard, and it is what most business associates and cyber insurers will ask you to attest to.

What you keep: the date, the roster with signatures or system-logged completions, the materials used, and the version number of the policies covered. "We do training every January" is not evidence. A signed roster from January 14, 2025 covering Policy Set v4.2 is.

Vendor Contracts: The Duty That Quietly Consumes the Most Time

Your privacy official owns the vendor inventory. Every entity that creates, receives, maintains, or transmits PHI on your behalf needs a business associate agreement executed before they touch data. That includes the answering service, the shredding company, the transcription contractor, the IT firm with remote access, the billing company, and the marketing agency running your patient recall texts.

Two failure patterns dominate. First, the agreement was never signed — someone onboarded a vendor on a Friday and the paperwork never happened. Second, the agreement was signed in 2016, references the wrong entity name after a practice merger, and has no breach-notification timeline that lets you meet your own 60-day clock.

Fix both with a quarterly reconciliation: pull the accounts-payable vendor list, mark every vendor that touches PHI, and match each one to an executed agreement. Anything unmatched gets a signed agreement or gets cut off from data. If you are papering gaps, a signature-ready business associate agreement generator walks you through a six-step wizard and exports PDF and DOCX for one flat purchase — faster than reworking a template you inherited from a predecessor who is no longer available to explain it.

Complaints, Sanctions, and Mitigation: The Three-Part Response

When a patient complains that a staff member discussed their results within earshot of the waiting room, the privacy official runs three parallel tracks.

Complaint handling (164.530(d)). Log the complaint, investigate, respond to the patient, and document the disposition. You must have a process, and you must document what came of each complaint.

Sanctions (164.530(e)). Apply the sanction your policy specifies for that severity level and document it. If your policy lists verbal warning, written warning, suspension, and termination, the file should show which one and why. Inconsistent sanctioning across similar violations is a finding waiting to happen.

Mitigation (164.530(f)). Take practical steps to reduce harm — retrain the staff member, move the check-in station, install a privacy screen. Write down what you changed and when.

Same incident, three documents. That is what a mature file looks like.

Notice of Privacy Practices: Two Live Deadlines Right Now

The 2024 final rule aligning 42 CFR Part 2 with HIPAA carries a compliance date of February 16, 2026. If your practice is subject to Part 2, or you receive Part 2 records, your notice content and consent handling need to be updated before then. That is under two months from today.

The 2024 reproductive health privacy rule is a different story — a federal district court vacated most of it in 2025, so verify current requirements with counsel before rewriting notice language based on that rule. The Part 2-related notice obligations were not part of what was struck down.

Separately, OCR published a proposed Security Rule overhaul in January 2025 that would tighten technical safeguard requirements considerably. It remains proposed as of today. Your privacy official should be tracking it, not implementing it.

The Evidence Binder: What an Investigator Actually Requests

When a complaint triggers an OCR data request, the list is predictable. Assemble it now, not then.

  1. Signed privacy official, security official, and contact person designations, with dates
  2. Current policies and procedures, version-controlled, with adoption dates
  3. The most recent security risk analysis and the risk management plan derived from it
  4. Training rosters for the past six years
  5. Complaint log with dispositions
  6. Records request log showing response dates
  7. Executed business associate agreements for every vendor on the current list
  8. Breach risk assessments for every incident, including ones you determined were not breaches
  9. Sanction records
  10. Current Notice of Privacy Practices and evidence of distribution

That fourth-from-last item catches people. If you evaluated an incident and concluded no breach occurred, the four-factor assessment supporting that conclusion is the document that protects you. No document, no defense.

For the risk analysis, NIST SP 800-66 Revision 2 is the standard reference, and the HHS/ONC Security Risk Assessment Tool is free and built for practices under 50 people. If you would rather generate the analysis and the accompanying policy set in one pass, automated HIPAA risk analysis and document generation covers the full set. No product, ours included, is government-certified — HHS does not certify or endorse compliance tools.

Staffing the HIPAA Privacy Officer Role in a Practice Under 25 People

You will not hire for this. You will assign it, and the assignment needs three things to survive contact with a busy Tuesday.

Protected time. Four hours a month, calendared, not "as needed." Two hours for the vendor and log reconciliation, two for incident review and policy upkeep.

A named backup. Deadlines do not pause for vacation. The 60-day breach clock started while your privacy official was in Cancun and nobody knew it.

A monthly written report to the owner. Five lines: requests received and closed, complaints, incidents, BAAs pending, training due. That report is both a management tool and six years of evidence that the program was operating.

Five Failure Modes Worth Checking This Week

  • The designation memo names someone who no longer works there
  • The vendor list in accounts payable has entries with no matching business associate agreement
  • Records requests are tracked in someone's inbox instead of a log
  • Incidents deemed "not a breach" have no written four-factor assessment
  • Training rosters exist for 2024 and 2025 but not the four years before that

Each of these takes under an hour to fix today and costs considerably more to explain later.

Start With the Gap You Can Close by Friday

Pull the vendor list. Mark everyone who touches PHI. Count the ones without a current signed agreement. If that number is above zero — and in most practices it is — generate the missing business associate agreements and get them out for signature before the year closes. It is the single fastest reduction in exposure available to the HIPAA privacy officer role, and unlike a policy rewrite, you can finish it this week.