Skip to main content
Category: Governance and Workforce

Privacy Official

Also known as: Privacy Officer, HIPAA Privacy Official
Simply put

A Privacy Official is the person a healthcare organization must designate to develop and implement its privacy policies and procedures under the HIPAA Privacy Rule. This role helps ensure the organization protects individuals' medical records and other identifiable health information. Designating this person is a required administrative step for organizations subject to the Privacy Rule.

Formal definition

Under the HIPAA Privacy Rule, a covered entity must designate a privacy official who is responsible for developing and implementing the entity's privacy policies and procedures governing protected health information (PHI) in all forms, including oral, paper, and electronic. This is a required workforce/personnel designation distinct from the Security Rule's requirement to identify a security official responsible for ePHI safeguards, though a single individual may hold both roles. The Privacy Rule generally does not prescribe specific credentials or a fixed title for this position, and requirements may be affected by state law or other frameworks beyond HIPAA; readers should confirm details against the current regulatory text.

Why it matters

The Privacy Official designation is one of the foundational administrative requirements of the HIPAA Privacy Rule. By requiring a covered entity to name a specific person responsible for developing and implementing its privacy policies and procedures, the rule creates a clear point of accountability for how protected health information (PHI) is handled across the organization. Without a designated individual owning this responsibility, privacy obligations can become diffuse, inconsistently applied, or overlooked entirely.

Because the Privacy Rule covers PHI in all forms, oral, paper, and electronic, the Privacy Official's remit is broader than that of the Security Official, whose responsibilities under the Security Rule are limited to electronic PHI (ePHI). This distinction matters in practice: policies governing conversations at a reception desk, faxed records, and paper charts all fall within the Privacy Official's scope, not just digital systems. Organizations that treat privacy as solely an IT concern risk gaps in exactly these non-electronic areas.

Designating a Privacy Official is a required step, but the designation alone does not establish compliance; the individual must actually develop and implement working policies and procedures. Readers should also note that the Privacy Rule generally does not prescribe specific credentials or a title for the role, and that state law or other frameworks beyond HIPAA may impose additional requirements. Specific obligations should be confirmed against the current regulatory text.

Who it's relevant to

Covered entities
Health plans, healthcare clearinghouses, and healthcare providers who conduct covered transactions are subject to the Privacy Rule and must designate a privacy official responsible for developing and implementing privacy policies and procedures. This is a required administrative step, not an optional best practice.
Privacy and compliance officers
Individuals appointed to or overseeing this role need to understand that their responsibility spans PHI in all forms, oral, paper, and electronic, rather than being limited to electronic records. They are accountable for the substance of the organization's privacy policies, not merely holding the title.
Security officials
Because a single individual may hold both the privacy and security roles, security officials should be aware of the distinction: the Security Rule role addresses safeguards for ePHI, while the Privacy Official role covers PHI in all forms. Organizations combining the roles should ensure both scopes are fully addressed.
Healthcare leadership and HR
Executives and human resources teams involved in structuring compliance functions should recognize that the Privacy Rule generally does not prescribe specific credentials or a fixed title for the position, giving organizations some flexibility in how they staff it, while noting that state law or other frameworks may add requirements to confirm against current guidance.

Inside Privacy Official

Privacy Official Designation Requirement
The HIPAA Privacy Rule generally requires each covered entity to designate a privacy official who is responsible for developing and implementing the entity's privacy policies and procedures. This designation is a required administrative safeguard obligation under the Privacy Rule, not the Security Rule.
Scope of Responsibility (All Forms of PHI)
Because the privacy official operates under the Privacy Rule, their responsibilities generally extend to protected health information in all forms, including oral, paper, and electronic PHI. This distinguishes the role from the security official, whose focus under the Security Rule is limited to electronic PHI (ePHI).
Contact Person or Office for Complaints
The Privacy Rule also generally requires a covered entity to designate a contact person or office responsible for receiving complaints and providing information about the entity's notice of privacy practices. In many organizations this function is assigned to the privacy official, though the roles can be separately designated.
Relationship to the Security Official Role
The privacy official is a distinct role from the security official required under the Security Rule. The same individual may serve in both capacities in some organizations, but the two designations arise from different rules with different scopes and should not be conflated.
Applicability to Covered Entities and Business Associates
The privacy official designation is primarily a Privacy Rule obligation for covered entities. Business associates carry certain obligations through business associate agreements and applicable regulation, but their required workforce role designations differ; practitioners should verify the specific obligations that flow through their agreements and the current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Privacy Official.

Does the Privacy Official have to be a different person from the Security Official?
No. The HIPAA Privacy Rule requires a covered entity to designate a Privacy Official, and the Security Rule separately requires designation of a Security Official, but these are distinct roles that may be filled by the same individual. Many smaller organizations assign both responsibilities to one person, while larger organizations often separate them. Note that the two roles address different scopes: the Privacy Official covers PHI in all forms, while the Security Official focuses on ePHI safeguards. Readers should confirm designation requirements against the current regulatory text.
Is designating a Privacy Official only necessary for large healthcare organizations?
No. The requirement to designate a Privacy Official generally applies to covered entities regardless of size. There is no exemption based solely on being a small practice or organization. What may scale with organizational size is how the role is staffed and resourced, smaller entities may combine the function with other duties, while larger ones may create a dedicated position, but the underlying designation obligation still applies. Verify specifics against current guidance from HHS OCR.
What are the core responsibilities typically assigned to a Privacy Official?
The Privacy Official is generally responsible for the development and implementation of the covered entity's privacy policies and procedures under the HIPAA Privacy Rule. In most cases this includes overseeing how PHI is used and disclosed, supporting workforce privacy training efforts, and handling privacy-related matters within the organization. The specific scope should be tailored to the entity's operations and confirmed against the applicable regulatory text, since state law or the HITECH Act may add further considerations.
How does the Privacy Official role relate to receiving complaints about privacy practices?
The Privacy Rule generally requires a covered entity to designate a contact person or office responsible for receiving complaints and providing information about the entity's privacy practices. This function is commonly assigned to the Privacy Official, though the regulation frames it as a contact designation that can be handled by a person or office. Organizations should document who fills this role and how individuals can reach them, and verify the current requirements against the regulatory text.
Can a business associate be required to designate a Privacy Official?
The Privacy Rule's designation requirement is directed at covered entities. Business associates are bound by obligations that flow through business associate agreements and by directly applicable provisions extended under the HITECH Act, but the specific privacy official designation obligation is framed for covered entities. Whether a business associate assigns a comparable role internally is often a matter of contractual terms and organizational practice. Confirm the precise obligations against current guidance and the terms of the applicable agreement.
How should the Privacy Official designation be documented?
As a general practice, the designation should be recorded in the covered entity's written privacy policies and procedures, which the Privacy Rule requires entities to maintain. Documenting who holds the role, the scope of their responsibilities, and how they can be contacted supports demonstrating that the designation requirement has been met. Specific documentation and retention expectations should be confirmed against the current regulatory text, and note that state law may impose additional requirements.

Common misconceptions

The privacy official and the security official must be the same person, or must always be different people.
These are two distinct designations arising from the Privacy Rule and the Security Rule respectively. A single individual may serve in both roles in some organizations, or the roles may be held by different people. The rules generally do not mandate a specific staffing arrangement, so the choice depends on the entity's size, structure, and resources.
The privacy official is only concerned with electronic health records and IT systems.
The privacy official operates under the Privacy Rule, which covers PHI in all forms including oral and paper. Protection of electronic PHI specifically is the focus of the Security Rule and the security official. Limiting the privacy official's attention to electronic systems overlooks a significant portion of their responsibilities.
Designating a privacy official by itself makes an organization HIPAA compliant.
Designation is one required element among many. The privacy official is responsible for developing and implementing privacy policies and procedures, but compliance depends on the entity's overall program. No single measure guarantees compliance, and state law or the HITECH Act may impose additional requirements beyond the baseline HIPAA obligations.

Best practices

Formally document the privacy official designation in writing and keep the designation current as personnel change, so the responsible role is clearly identifiable.
Clarify in policy whether the privacy official and security official roles are held by the same person or separate individuals, and define how the two coordinate given their different scopes under the Privacy Rule and Security Rule.
Ensure the privacy official's scope explicitly addresses PHI in all forms, including oral and paper, rather than limiting attention to electronic systems.
Designate and publicize a contact person or office for receiving privacy complaints and questions about the notice of privacy practices, and confirm whether this function sits with the privacy official.
Grant the privacy official appropriate authority, resources, and access to develop, implement, and maintain privacy policies and procedures across the organization.
Verify the specific designation and workforce obligations against the current regulatory text and any applicable state law or HITECH Act requirements, since these may impose additional duties beyond baseline HIPAA.