Can you outsource the HIPAA security officer role along with the rest of your technology? It is the question that produces the longest pause when a surveyor asks a home health administrator to name the agency’s Security Official. Agencies that handed their IT to a provider often assume the designation went with it. Below are the questions San Francisco Bay Area home health agencies ask most often about where that designation actually sits, and what an IT provider can and cannot do underneath it.
1. What Is the HIPAA Security Official, and What Does 45 CFR 164.308(a)(2) Require?
The HIPAA Security Official is the person an agency identifies as responsible for developing and implementing its Security Rule policies and procedures. That is the entire text of 45 CFR 164.308(a)(2). The standard carries no implementation specification, sets no qualifications, requires no credential, and names no job title.
It also does not expressly address whether a contractor may hold the designation, which is where most of the confusion starts. One detail worth noting: the standard applies to covered entities and business associates alike. Your IT provider is required to name a Security Official for its own organization, which is a separate designation from yours and does nothing for your agency.
2. Can You Outsource the HIPAA Security Officer Role to an IT Vendor?
The designation is the agency’s to make, and in practice it stays inside the agency. OCR has issued no guidance expressly permitting or prohibiting a contractor in the role, so the honest answer is that the question is unsettled rather than decided. The prevailing practice is that the designation stays internal and vendor support sits underneath it.
The person named has to be identifiable to a surveyor and answerable for the agency’s decisions, which is a high bar for anyone outside the organization to clear. For the wider picture of what does move to a provider, see our article on outsourcing HIPAA compliance for home health agencies.
3. What Duties Does the Security Official Actually Own?
The Security Official owns the administrative safeguards, which make up most of the Security Rule rather than its technical corner. The duties that sit under the designation include:
- Risk analysis and risk management
- Workforce security and the sanction policy
- Security awareness training
- Contingency planning
- Periodic evaluation of the security program
- Business associate oversight
- Facility access controls
- Incident response
Technical safeguards are one of three safeguard categories in the rule, and the administrative category is the largest of the three by a wide margin.
Enforcement tends to land in the same place. In an April 17, 2025 settlement, OCR resolved an investigation for $25,000 and a three-year corrective action plan, citing the failure to conduct an accurate and thorough risk analysis. A second complaint in the same case involved two former employees reaching systems after their employment had ended. The entity was a public hospital rather than a home health agency, but both findings fall to a designated official at any size of organization.
4. Why Do Home Health Agencies End Up Naming Their IT Manager or MSP Contact?
Agencies default to the IT manager or the MSP account contact because ePHI, meaning electronic protected health information, reads as a technology problem. The letter e does a great deal of work in that assumption, and the duties underneath the designation are mostly not technical.
The mismatch appears the moment something is asked of the role. The person who can be sanctioned by your agency, sit through a survey, and answer to the owner is not the same person who patches the servers.
The version we encounter most often is a designation naming the MSP’s account manager, written into a policy the agency has never opened. Nobody chose that arrangement. Somebody accepted a template.
5. What Can an IT Provider Do for the Role, and What Can It Not Do?
A provider can perform, advise, document, and report. What it cannot do is be sanctioned by your agency or answer for your agency’s decisions, and that boundary is structural rather than contractual.
HHS guidance on cloud services describes a vendor handling ePHI as a business associate with its own direct obligations under the HIPAA Rules, while the covered entity keeps its own. Both positions exist at the same time and neither absorbs the other.
In practice that means IT Total Care cannot hold your Security Official designation, approve your risk analysis, or make your breach determinations, and a provider offering to do any of those is offering something the rule does not permit. Expect an IT partner to help support HIPAA compliance, not to hold it.
6. Can You Outsource the HIPAA Security Officer Role at a Small Home Health Agency?
No, and the arrangement that works at a small agency is simpler than it sounds. An administrator or a DON holds the designation, and an IT partner supplies the technical execution and the evidence underneath it. Size does not change who the designation belongs to, only how much help the person holding it needs.
One warning, because it happens more than it should. Naming someone who does not know they hold the role is worse than the problem it was meant to solve. It produces a policy that looks complete, an official who has never been briefed, and an agency that believes the question is settled.
7. Where Should the Security Official Designation Be Documented?
In a job description, not only in a policy header. A name buried in a policy nobody opens is not a designation anyone can act on, and the person named should be identifiable to a surveyor without a search through the document library.
If your agency keeps a written record of which compliance functions belong to which party, the designation appears there as an agency-only line with no vendor column at all. Our guide to building a HIPAA shared responsibility matrix with your IT provider shows where it sits among the rest.
8. Should Your Agency Name a Backup Security Official?
Yes. The role does not pause when the designated person takes leave, changes jobs, or spends three weeks covering clinical shifts. A named backup keeps the designation continuous, which matters most during exactly the stretch when an agency is least able to absorb a gap.
Ask your IT provider for the same arrangement on its side. A standing backup contact means the technical support underneath the role does not pause either, and escalation does not depend on who happens to answer the phone.
9. What Support Should the Designated Official Expect From an IT Provider?
Expect the reporting the role requires to arrive without the designated official having to generate it. In practice that looks like:
- Risk analysis inputs and remediation status, so the official approves a document rather than assembles one. Our guide to the HIPAA risk assessment for home health agencies covers what that approval actually involves.
- Access records from the systems staff actually use, including the EMR and scheduling platform, whether that is Axxess, WellSky, or Homecare Homebase.
- Training delivered by the provider where useful, with the completion records held by the agency, since the records are what an auditor asks to see.
- Survey and audit support, meaning the provider produces the technical evidence while your official answers for the agency’s decisions.
All of it should arrive in language a DON or an administrator can act on, rather than as raw output from a tool nobody at the agency has logged into.
10. What Should You Ask an IT Provider Before Signing?
Five questions, and the answers show quickly whether a provider understands where the designation sits:
- Will you build a written record of who owns which compliance function with us, or only a service agreement?
- Which functions will you decline to perform, and will you say so in writing?
- Do you claim to be HIPAA certified, and if so, certified by whom?
- Will you hold our Security Official designation, and if you say yes, what happens at survey?
- How much of your client base is home health, rather than clinics and outpatient practices?
If a provider answers yes to the fourth question, follow it with the one that settles the matter: who attends the survey? An agency that has read the administrative safeguards end to end and still wants to name its MSP contact usually changes its mind on that question alone. Our article on HIPAA business associate agreements for home health agencies covers what the contract behind those answers should commit a provider to.
“MSPs who aren’t familiar with HIPAA will often say that they can hold your security official designation because they think it’s what you want to hear. In reality, if you hear that you should immediately disqualify that provider because they are just telling you what you want to hear, not what is actually allowed.”
Brendan Duebner, President, IT Total Care
Need Help Deciding Who Holds the Designation?
IT Total Care works with home health agencies across the Peninsula and the South Bay on the technical work that sits underneath the Security Official role: managed field devices, access provisioning, monitoring, and the evidence your designated official needs rather than has to build. Our home-based care IT support covers that work end to end, and you can read more about our approach to healthcare IT.
Contact Us to talk through who should hold the designation at your agency, and what support that person should expect.




