Under the Privacy Rule, which job must every covered entity give to a named person?

A privacy official, who is responsible for its privacy policies.

Start playing free

  1. A media spokesperson
  2. An outside HIPAA lawyer
  3. A privacy official ✔

Why: Every covered entity must designate a privacy official who develops and carries out its privacy policies. It must also name a contact person to receive complaints.

Huh, didn't know that: The Security Rule separately requires a named security official; one person can hold both roles.

The dad joke
Who solves privacy mysteries at the clinic? The privacy official, of course.
Like this card?
Play the game

References

Answer: A privacy official. Every covered entity must designate a privacy official who develops and carries out its privacy policies. It must also name a contact person to receive complaints.

  1. 45 CFR 164.530(a) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
    A covered entity must designate a privacy official who is responsible for the development and implementation of the policies and procedures
    Checked 2026-10-10.
  2. 45 CFR 164.308(a)(2) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
    Identify the security official who is responsible for the development and implementation of the policies and procedures
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game