SESK: Stuff Everyone Should Know · sesk.info/hipaa-privacy-officer-breach-role
Under the Privacy Rule, which job must every covered entity give to a named person?
A privacy official, who is responsible for its privacy policies.
- A media spokesperson
- An outside HIPAA lawyer
- A privacy official ✔
Why: Every covered entity must designate a privacy official who develops and carries out its privacy policies. It must also name a contact person to receive complaints.
Huh, didn't know that: The Security Rule separately requires a named security official; one person can hold both roles.
Who solves privacy mysteries at the clinic? The privacy official, of course.
Like this card?
References
Answer: A privacy official. Every covered entity must designate a privacy official who develops and carries out its privacy policies. It must also name a contact person to receive complaints.
- 45 CFR 164.530(a) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
A covered entity must designate a privacy official who is responsible for the development and implementation of the policies and procedures
Checked 2026-10-10. - 45 CFR 164.308(a)(2) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Identify the security official who is responsible for the development and implementation of the policies and procedures
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.