Privacy Official for Entity, v1.0

Specifies that a covered entity must have policies and procedures to designate a privacy official who is responsible for the development and implementation of the policies and procedures of the entity.
A covered entity must document the personnel designations as required by Section 164.530(j).
A covered entity that is a group health plan is not subject to the standards or implementation specifications in this trustmark, but see Section 164.530(k) for specific exclusions.

Assessment Steps (2)

1
Privacy Official (PrivacyOfficial)
Does the covered entity have policies and procedures to designate a privacy official who is responsible for the development and implementation of the policies and procedures of the entity?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.), including the current personnel designations, that support the assessor's response to this assessment step.
2
Contact Person (ContactPerson)
Does the covered entity have policies and procedures to designate a contact person or office who is responsible for receiving complaints under this section and who is able to provide further information about matters covered by the notice of privacy practices (Section 164.520)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.), including the current personnel designations, that support the assessor's response to this assessment step.

Conformance Criteria (2)

Designate Privacy Official
The covered entity must have policies and procedures to designate a privacy official who is responsible for the development and implementation of the policies and procedures of the entity.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(a)(1)(i) and (a)(2)
Designate Contact Person
The covered entity must have policies and procedures to designate a contact person or office who is responsible for receiving complaints under this section and who is able to provide further information about matters covered by the notice of privacy practices (Section 164.520).
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(a)(1)(ii) and (a)(2)