The regulation that creates your job is one sentence long. 45 CFR 164.308(a)(2) says a covered entity must identify the security official responsible for developing and implementing the policies and procedures required by the Security Rule. That is the entire text. Everything else people call HIPAA Security Officer responsibilities is inherited from the other 40-odd implementation specifications in the rule, which land on whoever's name appears in that one line.

If you were just handed the title, or you are the practice owner who has quietly held it for four years without documenting anything, this is the working breakdown: what you own, on what schedule, and what the paper trail has to look like when OCR asks.

The Sentence That Creates the Job — and What It Actually Assigns

"Assigned security responsibility" is a required implementation specification, not an addressable one. There is no risk-based analysis that lets you skip it. One named human being, documented, with the authority to act.

That last part is where small practices get into trouble. Naming the office manager as Security Officer while giving her no budget authority, no ability to remove a user's access, and no standing with the physician owners produces a role that exists on paper and nowhere else. Enforcement records make clear that OCR reads the risk analysis and the risk management plan as the test of whether the role was real.

The Privacy Officer is a separate requirement under 45 CFR 164.530(a)(1). One person can hold both roles. Many practices under 20 staff do exactly that. Document it as two designations, not one hybrid title, because the duties diverge and so do the audit questions.

HIPAA Security Officer Responsibilities in Ten Lines

If your practice needs a one-page answer for a policy manual or a board memo, this is it. The Security Officer:

  • Conducts and updates the enterprise-wide security risk analysis (164.308(a)(1)(ii)(A))
  • Runs the risk management plan that remediates what the analysis found (164.308(a)(1)(ii)(B))
  • Writes, approves, and maintains the Security Rule policies and procedures (164.316(a))
  • Owns workforce security: access authorization, modification, and termination (164.308(a)(3) and (a)(4))
  • Delivers and documents security awareness training, including periodic reminders (164.308(a)(5))
  • Operates security incident response and reporting procedures (164.308(a)(6))
  • Maintains the contingency plan: data backup, disaster recovery, emergency mode operations, and testing (164.308(a)(7))
  • Performs periodic technical and non-technical evaluation when the environment changes (164.308(a)(8))
  • Verifies that business associate agreements exist and that assurances are obtained before ePHI is disclosed (164.308(b) and 164.314(a))
  • Retains all required documentation for six years from creation or last effective date (164.316(b)(2)(i))

Ten lines, and the first two consume most of the time.

The Risk Analysis Is the Center of Gravity

Every other duty depends on the risk analysis being current and honest. It is the single most commonly cited failure in OCR resolution agreements, and it is the first document requested when a complaint or breach investigation opens.

What a defensible risk analysis contains

Start with a complete inventory of where ePHI lives, moves, and rests. That means the EHR, but also the billing clearinghouse portal, the scanner that emails PDFs, the front-desk workstation with a saved spreadsheet of no-shows, the two laptops a physician takes home, the text-message app your intake coordinator uses, and the cloud backup you set up in 2019 and never touched again.

For each asset, document the threats, the existing controls, the likelihood, the impact, and the resulting risk level. HHS and NIST published NIST SP 800-66 Revision 2 as an implementation guide specifically for HIPAA Security Rule work; it maps the rule's specifications to concrete practices and is the closest thing to an official methodology you will find. The free Security Risk Assessment Tool from ONC and OCR is a reasonable starting structure for practices under about 50 users.

A vendor scan report is not a risk analysis. A checklist attestation is not a risk analysis. If your document does not name specific systems in your specific practice, it will not survive review.

The risk management plan that follows

The analysis identifies risk. The management plan reduces it. Each finding needs an owner, a remediation action, a target date, and a closure note with a date.

Not every finding gets fixed immediately. That is acceptable if you document the decision, the compensating control, and the review date. What is not acceptable is a risk analysis with 30 findings and no evidence anyone did anything about them. That gap is what turns a small incident into a large settlement.

Update the analysis when something material changes — new EHR, new location, new remote-work arrangement, a merger, or a significant incident — and review it at least annually regardless. Practices that need to move faster often automate the risk analysis report and the supporting policy set rather than rebuilding the whole document by hand each year.

The Safeguards You Personally Sign Off On

The technical safeguards at 164.312 are where the Security Officer's name goes on decisions the IT vendor executes. Unique user IDs for every person who touches ePHI — no shared "frontdesk" login. Automatic logoff on workstations in patient-accessible areas. Audit controls that actually record access and that someone actually reviews. Encryption of ePHI at rest and in transit, or a documented, defensible explanation of the equivalent alternative you chose.

Encryption is technically "addressable," which does not mean optional. It means you either implement it or you document why it is not reasonable and appropriate and what you did instead. In 2025, there is almost no defensible reason a practice laptop is unencrypted. Breach notification also carries a safe harbor for properly encrypted data, which makes this the highest-return control on the list.

Physical safeguards at 164.310 are yours too: facility access controls, workstation placement, device and media disposal, and a record of media reuse. When the copier lease ends, the Security Officer confirms the hard drive was wiped or destroyed and files the certificate.

Vendors: The List, the Agreements, and the Renewal Calendar

Build and maintain a business associate inventory. For each vendor: what ePHI they touch, how they touch it, the agreement's effective date, the signer, and the renewal or review date. Most practices discover 15 to 30 business associates when they do this honestly — transcription, billing, answering service, IT support, shredding, secure messaging, cloud storage, appointment reminders, credentialing, collections.

The Security Officer's specific duty under 164.308(b)(1) is obtaining satisfactory assurances before ePHI is disclosed. Signing the BAA after the vendor has been receiving data for six months does not cure the gap; it just documents it.

When you find an unpapered vendor — and you will — you need an agreement on the table quickly, not a two-week wait for outside counsel to redline a template. A six-step wizard that produces a signature-ready Business Associate Agreement in PDF and DOCX closes that gap the same afternoon, as a one-time purchase rather than another subscription line item. Attach the executed copy to your inventory row and set the review date.

Subcontractors matter as well. Your billing company's offshore coding partner is a subcontractor business associate, and your BAA should require downstream agreements. Ask for confirmation in writing; file the answer.

Training, Sanctions, and the Evidence You Did It

Security awareness and training under 164.308(a)(5) covers four addressable areas: security reminders, malicious software protection, log-in monitoring, and password management. The rule does not set a frequency. Annual training plus quarterly reminders is the defensible floor most practices land on.

The evidence is what matters. Keep the curriculum or deck, the date, the attendance roster with signatures or system-logged completions, and the quiz results if you use one. "We talk about it at staff meetings" is not evidence.

Pair training with an applied sanction policy under 164.308(a)(1)(ii)(C). When someone opens a coworker's chart out of curiosity, the file should show the audit-log detection, the investigation notes, the sanction applied, and the date. A sanction policy that has never been used against a real incident reads as decorative.

The 60-Day Breach Clock and Who Starts It

A laptop goes missing Friday afternoon. Your incident response procedure, which you wrote, tells staff to report it to you immediately — that is the security incident procedure requirement at 164.308(a)(6) doing its job.

From there the Security Officer runs the four-factor risk assessment under the Breach Notification Rule: the nature and extent of the PHI, the unauthorized person who used or received it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated. If you conclude there is a low probability of compromise, the documentation of that analysis is what you file.

If it is a reportable breach, individual notice goes out without unreasonable delay and no later than 60 calendar days from discovery. Breaches affecting 500 or more individuals go to HHS within that same 60 days, plus media notice in the affected state or jurisdiction. Breaches under 500 are logged and submitted to HHS within 60 days after the end of the calendar year — meaning anything discovered in 2025 is due by March 1, 2026. The current forms and instructions are on the HHS breach notification page.

Note the date rule: the clock starts on discovery, which includes when any workforce member other than the person who caused the breach should reasonably have known. Not when you finished investigating.

The Retention Rule That Gets Tested First

Six years, from the date of creation or the date it was last in effect, whichever is later (164.316(b)(2)(i)). That covers policies, risk analyses, training records, incident files, sanction records, BAAs, and any required documented decision.

This means your superseded 2021 encryption policy stays on file even though you replaced it in 2023. Version everything. Date everything. Keep an index so you can produce a specific document within a business day, because OCR data requests carry short deadlines and "we're still looking for it" is a poor opening.

What Changes If the Proposed Security Rule Update Is Finalized

In January 2025, HHS published a notice of proposed rulemaking that would substantially rewrite the Security Rule — removing much of the addressable/required distinction, mandating asset inventories and network maps, requiring encryption and multifactor authentication more broadly, and tightening verification of business associate safeguards. The comment period closed in March 2025.

As of today it remains a proposal, not law. Do not rewrite your program around it. Do note that an asset inventory, a network map, encryption, MFA, and a current vendor register are all things a competent Security Officer should already have. Building them now is not speculative work.

Your First 90 Days in the Role

Days 1–15. Get your designation in writing, signed by an owner or the board, with stated authority over access provisioning and security spend. Pull whatever risk analysis exists and check its date. Build the ePHI asset inventory.

Days 16–45. Complete or refresh the risk analysis against the inventory. Build the business associate list and identify every missing or expired agreement. Review the user access list against the current staff roster and terminate orphaned accounts — departed employees with live logins is a finding that writes itself.

Days 46–75. Write the risk management plan with owners and dates. Execute the missing BAAs. Confirm backups restore by actually testing one. Verify encryption status on every laptop and mobile device.

Days 76–90. Deliver training and file the roster. Publish the incident reporting procedure to all staff with your name and after-hours contact on it. Set annual recurring calendar entries for risk analysis review, training, contingency plan testing, and BAA review. Then check the OCR breach portal for practices your size and see how the reported incidents map to your own gap list.

The role is not glamorous and it is never finished. But a practice where the Security Officer's duties are documented, dated, and demonstrably performed is a fundamentally different conversation with a regulator than one where the title sits unfilled in a binder.

Close the Vendor Gap First

Of everything on this list, missing business associate agreements are the fastest to find and the fastest to fix. Build your vendor inventory this week, then generate the agreements you're missing and file each executed copy against its inventory row. It is a concrete, dated piece of evidence that the Security Officer role in your practice is doing real work.