HIPAA privacy officer and security officer: the two roles a small NEMT company must name
Overview
A HIPAA covered entity must name a privacy official to write and run its privacy policies, plus a contact for complaints (45 CFR 164.530(a)). Covered entities and business associates must also name a security official (164.308(a)(2)). One person may hold every role, and no credential is required. Put the designation in writing and keep it for six years after it was last in effect.
On this page
The designations HIPAA requires
HIPAA makes a company assign three jobs to specific people, or for complaints, to an office:
- Privacy official. A covered entity must designate the person responsible for developing and carrying out its privacy policies and procedures (45 CFR 164.530(a)(1)(i)).
- Complaint contact. A covered entity must also name a person or office that receives privacy complaints and can answer questions about its notice of privacy practices (164.530(a)(1)(ii)). The notice itself has to list that contact by name or title, with a phone number (164.520(b)(1)(vii)).
- Security official. Covered entities and business associates alike must identify the official responsible for their Security Rule policies (164.308(a)(2)).
Which of these apply depends on your HIPAA role. Our guide to HIPAA for NEMT providers explains how to decide, one line of business at a time, whether you hold covered entity or business associate status.
Business associates name a security official, not a privacy official
A company that runs trips only as a broker’s subcontractor counts as a business associate under HIPAA, and the privacy official requirement does not reach it by law. HHS said so directly in the 2013 Omnibus rule: business associates do not have to designate a privacy official unless a covered entity hands them that duty by contract (78 FR 5566). The security official requirement does apply, because the Security Rule covers business associates.
Broker contracts fill the gap in practice. They make you report privacy and security problems on a short clock, so someone has to own that call.
One person can hold every role
The owner or office manager can be privacy official, complaint contact, and security official at once. HHS said in 2003 that the same person could fill the security and privacy roles. In 2000 it said the privacy job could be an added duty for an existing employee, using an office manager in a small entity as its example, and that duties may be shared as long as one person stays accountable.
HHS also declined to set qualifications for the role, because the job varies so much with the size of the organization.
What the job covers in a small fleet
In a NEMT company the privacy and security officer usually handles:
- Policies. Keep the written rules for manifests, phones, texting, records requests, and disposal, and update them when something changes.
- Training records. Make sure drivers and office staff are trained and that the training is documented, as the HIPAA guide describes.
- Complaints and sanctions. Log every privacy complaint and what was done about it (164.530(d)), and apply the sanction policy when someone breaks the rules.
- The risk analysis. Lead the Security Rule risk analysis; the risk assessment template is a starting point.
- Incident reports. Take the first report of a lost phone or misdirected manifest and meet the broker’s deadline. WellTrans’s subcontractor agreement (October 2025) allows one business day for improper disclosures and security incidents.
- Agency questions. Answer an OCR inquiry. Riders can complain to HHS within 180 days of learning of a problem (45 CFR 160.306), and the guide to an OCR investigation covers what happens next.
Put the designation in writing
The designation has to be documented. Privacy Rule records stay on file for six years, counted from creation or from the last day they applied if that is later (164.530(j)), and the Security Rule sets the same six-year period for its own documentation (164.316(b)(2)). A one-page memo with the person’s name, title, start date, and duties, signed by the owner, does the job. When the person leaves, write a new designation and keep the old one.
HealthRide is HIPAA compliant. In the provider portal, each person sees only what their role allows, and a record of every change gives your privacy officer something concrete to check when a question comes in.
Frequently asked questions
- Does a NEMT company with one or two vans need a privacy officer?
- If it is a covered entity, yes. The rule has no size exemption. HHS expected small offices to hand the job to someone already on staff, naming an office manager as the example, so the owner or the office lead usually takes it. A company that works only as a broker subcontractor still has to name a security official, and its broker agreement may ask for more.
- Does the privacy officer need a HIPAA certification?
- No. When HHS wrote the rule in 2000, commenters asked it to require a credentialed professional, and HHS declined because the job differs so much by size. Training helps, and some brokers send their own HIPAA course each year, but no certificate is a legal condition for holding the role.
- Is the complaint contact the same person as the privacy officer?
- It can be. HHS said the contact person could be, but did not have to be, the privacy official. In a small company one name usually covers both. If you are a covered entity, your notice of privacy practices must list that contact by name or title with a phone number.
- Who should a driver tell about a lost manifest or phone?
- The person you named, right away. Broker deadlines are short. The WellTrans subcontractor agreement (October 2025) requires a report of any improper use or disclosure, and of any security incident, within one business day, and it counts a breach as known to the company from the moment any employee besides the one responsible learns of it.