Security Rule

Assigned Security Responsibility: The HIPAA Standard That Names a Person

The HIPAA Security Rule requires every covered entity and business associate to identify a security official who is responsible for developing and implementing its security policies and procedures. The requirement is one sentence long, it applies to a solo practice and a health system equally, and it is one of the few places in the rule where the regulation asks for a person rather than a control. That distinction is the whole point of the standard, and it is the part most often missed: you cannot satisfy it by buying something.

What the standard actually says

The provision is 45 CFR 164.308(a)(2), and here it is in full:

§ 164.308(a)(2) Standard: Assigned security responsibility. “Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate.”

That is the entire text. There are no implementation specifications underneath it, no sub-paragraphs, and no conditions. It is worth reading the sentence closely, because each part of it is doing work.

  • “Identify” — the role has to be filled and known, not merely contemplated.
  • “the security official” — definite article, singular. The rule contemplates one accountable person, not a committee with distributed ownership.
  • “responsible for the development and implementation” — both halves. Writing the policy and making it real are the same person's remit.
  • “the policies and procedures required by this subpart” — the whole Security Rule, not a subset. Administrative, physical, and technical.
  • “or business associate” — business associates carry this obligation directly, not through their customer.

It is a standard, which matters

The Security Rule has two kinds of provisions, and the difference decides how much latitude you have.

Implementation specifications carry a parenthetical label — (Required) or (Addressable). An addressable specification gives you a documented decision procedure: implement it, or determine it is not reasonable and appropriate, document why, and implement an equivalent alternative measure where one is reasonable and appropriate. That is the flexibility mechanism at 45 CFR 164.306(d).

Standards have no such label and no such mechanism. Assigned security responsibility is a standard. There is no “addressable” escape hatch, no documented-alternative path, and no size threshold below which it stops applying. If you are a covered entity or a business associate, you identify a security official. That is it.

This is a useful thing to know when someone tells you the requirement is scalable. The scope of the work scales — 164.306(b) tells you to take into account your size, complexity, and capabilities, your technical infrastructure, the cost of security measures, and the probability and criticality of potential risks. The existence of the role does not scale. It is binary.

What the security official is responsible for

The rule assigns the official the policies and procedures required by the subpart. Walking the subpart, that is a substantial list. It includes, among others:

ProvisionWhat it requires
164.308(a)(1)(ii)(A)Risk analysis (Required) — an accurate and thorough assessment of risks and vulnerabilities to ePHI
164.308(a)(1)(ii)(B)Risk management (Required) — security measures sufficient to reduce risk to a reasonable and appropriate level
164.308(a)(1)(ii)(C)Sanction policy (Required) — appropriate sanctions against workforce members who fail to comply
164.308(a)(1)(ii)(D)Information system activity review (Required) — regular review of audit logs, access reports, and incident tracking
164.308(a)(6)(ii)Response and reporting (Required) — identify and respond to security incidents, mitigate, and document
164.308(a)(7)Contingency plan — including data backup, disaster recovery, and emergency mode operation, all Required
164.308(a)(8)Evaluation — periodic technical and nontechnical evaluation
164.310Physical safeguards — facility access, workstation use and security, device and media controls
164.312Technical safeguards — access control, audit controls, integrity, authentication, transmission security
164.316Documentation — written policies, six-year retention, availability, periodic update

Note what is on that list that no software product experiences: sanctioning an employee, walking a facility, deciding what is reasonable and appropriate for this organization, and being the person who answers when a regulator calls. The security official owns the parts of the rule that are judgment and the parts that are physical, not only the parts that are configuration.

The security official and the privacy official are different requirements

These get conflated constantly, and they live in different rules.

  • Security official — 45 CFR 164.308(a)(2), Security Rule. Responsible for the policies and procedures required by the Security Rule. Applies to covered entities and business associates.
  • Privacy official — 45 CFR 164.530(a)(1)(i), Privacy Rule. “A covered entity must designate a privacy official who is responsible for the development and implementation of the policies and procedures of the entity.”
  • Complaint contact — 45 CFR 164.530(a)(1)(ii). A covered entity must also designate a contact person or office responsible for receiving complaints and able to provide further information about the matters in its notice of privacy practices.

That is three designations, two of them in the same paragraph of the Privacy Rule. Nothing prohibits one person from holding all three, and in a small organization one person usually does. But each designation has to actually be made. “We assume the office manager handles it” is not a designation.

Can the role sit outside the organization?

This question comes up constantly and the honest answer is that the regulation does not address it directly. 164.308(a)(2) says to identify the security official responsible for the development and implementation of the policies and procedures required by the subpart. It does not say the person must be on your payroll.

What the regulation is unambiguous about is where the obligation sits. The duty to comply belongs to the covered entity or business associate. You can buy expertise, and many organizations do — a fractional officer, a consultant, an advisor on retainer. What you cannot do is transfer the obligation along with the invoice. If the arrangement ends, the requirement does not.

So the practical test is not employee or vendor. It is: is there a specific, named human being who knows they hold this role, whose responsibility covers the whole subpart, who is reachable in the month nothing is scheduled, and whose designation is written down? An organization that can answer that has met the standard. An organization whose answer is a product name has not, because the rule asked for an official and received a login.

The job does not end when the assessment does

The most common structural misunderstanding of this role is treating it as an annual event with a person attached.

Two provisions say otherwise. 164.308(a)(8) requires a periodic technical and nontechnical evaluation, performed initially against the standards and subsequently in response to environmental or operational changes affecting the security of ePHI. And 164.316(b)(2)(iii) requires documentation to be reviewed periodically and updated as needed, in response to the same kinds of changes.

HHS is direct about the cadence in its risk analysis guidance: the process “should be ongoing,” and an entity “should conduct continuous risk analysis to identify when updates are needed.” It names the triggers plainly — if the entity “has experienced a security incident, has had change in ownership, turnover in key staff or management, is planning to incorporate new technology to make operations more efficient, the potential risk should be analyzed.”

Look at that list. A security incident. A change in ownership. Staff turnover. New technology. None of those wait for your renewal date. That is the argument for the role being continuous rather than seasonal, and it is HHS's argument, not a vendor's.

Worth noting for planning purposes: HHS also states that the Security Rule “does not specify how frequently to perform risk analysis,” and that some entities perform it annually or as needed. There is no federal annual deadline for a risk analysis. Anyone who tells you there is has invented it.

What this looks like in a small organization

The standard applies at every size, but it does not demand a full-time hire. HHS notes in its guidance that small organizations tend to have more control within their environment and fewer variables to consider, and that appropriate security measures in a small organization may differ from those appropriate in a large one.

In a five-person practice, the security official is typically the practice manager or an owner-physician, spending a small fraction of their time on it. That is a legitimate answer. What makes it work is that the person knows they hold the role, has the authority to change how things are done, and has somewhere to go for the parts they are not equipped to judge alone. What makes it fail is when the role exists on paper and the named person learns about it during an investigation.

Documenting the designation

Under 164.316(b)(1), if an action, activity, or assessment is required by the subpart to be documented, you maintain a written or electronic record of it. Policies and procedures implemented to comply with the subpart are kept in written form.

The retention period is specific and longer than most people assume: 164.316(b)(2)(i) requires documentation to be retained for six years from the date of its creation or the date when it last was in effect, whichever is later. If a person held the security official role for three years and left in 2021, the record of that designation runs six years from when it ceased to be in effect.

The Privacy Rule carries a parallel six-year retention requirement for its own documentation at 164.530(j)(2), and 164.530(a)(2) requires the personnel designations to be documented.

Two more requirements sit next to retention and are easy to skip: 164.316(b)(2)(ii) requires documentation to be made available to those persons responsible for implementing the procedures to which it pertains. A policy nobody can find has not met that. And 164.316(b)(2)(iii) requires periodic review and update.

Four common mistakes

  1. Naming a role instead of a person. “The IT department” is not a security official. The rule says the security official, singular and definite.
  2. Naming someone who does not know. Discovered regularly, and always at the worst moment. The designation is only real if the designee knows about it.
  3. Assuming the vendor is the official. A vendor can do the work. The obligation stays with you, and if the relationship ends, the requirement is still yours.
  4. Letting the designation go stale. Staff turnover is on HHS's own list of triggers for re-analysis. When the named official leaves, two things need to happen: name a successor, and revisit what changed.

Common questions

Does HIPAA require a security officer?

Yes. 45 CFR 164.308(a)(2), the Assigned security responsibility standard, requires a covered entity or business associate to identify the security official who is responsible for the development and implementation of the policies and procedures required by the Security Rule. It is a standard, not an addressable implementation specification, so there is no documented-alternative path. Every covered entity and business associate must identify one, regardless of size.

Can the security official and the privacy official be the same person?

Nothing in the rules prohibits it, and in smaller organizations it is common. They are two separate requirements in two separate rules: the security official at 45 CFR 164.308(a)(2) under the Security Rule, and the privacy official at 45 CFR 164.530(a)(1)(i) under the Privacy Rule. The Privacy Rule separately requires a covered entity to designate a contact person or office responsible for receiving complaints. One person may hold more than one of these roles, but each designation has to actually be made and documented.

Can you outsource the security official role to a vendor?

The regulation says to identify the security official responsible for the development and implementation of the policies and procedures required by the subpart. It does not state whether that person must be an employee. What does not change is that the obligation to comply stays with the covered entity or business associate. Outside help can perform the work; the regulated entity remains the regulated entity. If you use outside support, the practical questions are who is named, what they are responsible for, whether they are reachable when something happens, and whether the arrangement is documented.

How often does the security official's work need to be reviewed?

The Security Rule does not set a calendar. 45 CFR 164.308(a)(8) requires a periodic technical and nontechnical evaluation in response to environmental or operational changes affecting the security of ePHI. HHS guidance states that the risk analysis process should be ongoing and gives examples of triggers: a security incident, a change in ownership, turnover in key staff or management, or planned new technology. 45 CFR 164.316(b)(2)(iii) separately requires documentation to be reviewed periodically and updated as needed in response to environmental or operational changes.