In 2018, a small Texas health plan paid $100,000 to settle HIPAA violations after a breach involving fewer than 500 individuals. The organization's leadership told OCR investigators they weren't sure who on staff was actually responsible for HIPAA compliance. That confusion cost them six figures. If you've ever asked who is responsible for implementing and monitoring the HIPAA regulations, the answer is layered — and getting any layer wrong puts your organization at serious financial risk.

This post breaks down every level of responsibility, from the federal agencies that write and enforce the rules all the way down to the individual workforce members who handle PHI every day. By the end, you'll know exactly who owns what — and where most organizations fail.

The Federal Level: HHS and OCR Set the Rules and Enforce Them

At the top of the chain, the U.S. Department of Health and Human Services (HHS) is the federal agency responsible for creating and publishing the HIPAA regulations. HHS wrote the Privacy Rule, the Security Rule, the Breach Notification Rule, and the Enforcement Rule. They set the standards every covered entity and business associate must follow.

But HHS doesn't do the day-to-day enforcement. That job belongs to the Office for Civil Rights (OCR), a division within HHS. OCR investigates complaints, conducts compliance reviews, and issues the penalties that make headlines.

In my experience, most people in healthcare know the name "HIPAA" but couldn't tell you that OCR is the office that actually shows up when things go wrong. That gap in knowledge matters because it shapes how seriously organizations treat compliance internally.

What OCR Actually Does

OCR reviews every breach report involving 500 or more individuals. They investigate complaints filed by patients and employees. They audit covered entities and business associates — sometimes randomly, sometimes triggered by a reported incident.

When OCR finds violations, the consequences range from corrective action plans to multi-million-dollar settlements. Anthem Inc. paid $16 million in 2018 — the largest HIPAA settlement in history — after a breach affecting nearly 79 million people. That penalty came directly from OCR's enforcement authority.

Who Is Responsible for Implementing and Monitoring the HIPAA Regulations Inside Your Organization?

Here's where the question gets personal. Federal law requires every covered entity to designate specific individuals responsible for HIPAA compliance. This isn't optional. It's written into the regulation itself.

The Privacy Rule (45 CFR § 164.530) requires a designated Privacy Officer. The Security Rule (45 CFR § 164.308) requires a designated Security Officer. In small practices, one person often fills both roles. In large health systems, these are separate full-time positions with dedicated teams.

These officers are responsible for developing policies, conducting risk assessments, managing breach notification procedures, and training the workforce. They're the internal engine of HIPAA compliance. When OCR comes knocking, they're the ones who need to produce documentation.

The Privacy Officer's Core Duties

  • Drafting and updating the organization's Notice of Privacy Practices
  • Creating policies for how PHI is used, disclosed, and safeguarded
  • Handling patient complaints related to privacy
  • Ensuring minimum necessary standards are applied to every disclosure
  • Coordinating workforce training on the Privacy Rule

The Security Officer's Core Duties

  • Conducting annual risk assessments of ePHI systems
  • Implementing administrative, physical, and technical safeguards
  • Managing access controls — who can see what, and when
  • Monitoring security incidents and leading breach response
  • Documenting every security measure and every gap

I've audited organizations where the Privacy Officer didn't know they were the Privacy Officer. Their name was on a compliance plan filed three years earlier, but no one told them and no one gave them the authority to act. That's a compliance disaster waiting to happen.

Leadership Bears the Ultimate Responsibility

Designating officers doesn't let executives off the hook. OCR has made it clear through enforcement actions that organizational leadership — CEOs, board members, practice owners — bear ultimate responsibility for creating a culture of compliance.

In 2020, Premera Blue Cross paid $6.85 million to settle potential HIPAA violations tied to a breach that affected over 10 million people. OCR's investigation found systemic noncompliance, including failure to conduct an enterprise-wide risk analysis. That's a leadership failure, not just a security officer failure.

Leadership must fund compliance programs, authorize staffing, and ensure that privacy and security officers have the organizational authority to make changes. Without executive support, even the best compliance officer is just a person with a title and no power.

Every Workforce Member Has a Role

HIPAA defines "workforce" broadly — employees, volunteers, trainees, contractors, and anyone under an organization's direct control. Every one of these individuals is responsible for following HIPAA policies and protecting PHI in their daily work.

This is where workforce training becomes critical. The Privacy Rule requires training for every workforce member. The Security Rule requires security awareness training. Both rules require retraining when policies change or when new threats emerge.

I've seen breaches caused by a front-desk receptionist texting a patient's test results to the wrong phone number. I've seen breaches caused by an IT contractor leaving a server unencrypted during a migration. In both cases, the organization was held responsible — not just the individual.

What Training Actually Needs to Cover

Generic "don't share passwords" training doesn't cut it. Effective HIPAA training must be role-specific. A billing clerk faces different risks than a nurse, and both face different risks than an IT administrator.

Training should cover PHI handling, breach reporting obligations, social engineering threats, and the specific policies your organization has put in place. If your workforce operates in Texas, you also need to address state-specific requirements under Texas HB 300, which adds protections beyond federal HIPAA requirements.

If you're looking for structured training that covers both federal and state-level privacy requirements, our full training catalog is built for exactly this purpose.

Business Associates: The Third-Party Responsibility Layer

Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for HIPAA compliance. That means your EHR vendor, your cloud storage provider, your billing company, and your shredding service all share responsibility for protecting PHI.

Every business associate relationship must be governed by a Business Associate Agreement (BAA). The BAA spells out what the associate can and can't do with PHI, requires them to implement safeguards, and obligates them to report breaches.

OCR doesn't give covered entities a pass just because a business associate caused the breach. In many enforcement actions, both the covered entity and the business associate face penalties. You're responsible for vetting your partners and ensuring those BAAs are current and enforceable.

State Attorneys General Add Another Layer of Enforcement

Here's something many compliance officers overlook: the HITECH Act gave state attorneys general the authority to bring civil actions for HIPAA violations on behalf of state residents. This means your organization can face enforcement from both OCR at the federal level and your state AG simultaneously.

Several states have exercised this power. The Indiana Attorney General, for instance, has pursued HIPAA-related actions against healthcare entities operating within the state. This dual-enforcement model means that monitoring HIPAA regulations isn't just a federal concern — it's a state-level obligation as well.

Quick Answer: Who Is Responsible for HIPAA Compliance?

At the federal level, HHS creates the HIPAA regulations and OCR enforces them through investigations, audits, and penalties. At the organizational level, every covered entity must designate a Privacy Officer and a Security Officer who develop policies, conduct risk assessments, and manage compliance programs. Leadership — executives and board members — must fund and support the compliance program. Every workforce member must follow HIPAA policies and complete required training. Business associates are directly liable under the Omnibus Rule and must comply with BAA terms. State attorneys general can also enforce HIPAA violations independently. In short, responsibility is shared across every level — and no single person or agency carries it alone.

The $1.5 Million Mistake of Assuming Someone Else Owns It

The most dangerous assumption in HIPAA compliance is that "someone else is handling it." I've watched organizations crumble during OCR investigations because departments pointed fingers at each other. The IT team assumed the compliance department handled training. The compliance department assumed IT handled encryption. Nobody handled either.

That's how settlements in the millions happen. Not from sophisticated cyberattacks. From internal confusion about who owns what.

Build a compliance structure with named individuals, documented authority, funded budgets, and regular audits. Train your entire workforce — not once, but continuously. Monitor your business associates. And make sure your leadership team understands that HIPAA responsibility starts at the top and touches every person who handles protected health information.

Because when OCR asks who is responsible for implementing and monitoring the HIPAA regulations at your organization, "I thought someone else was doing it" is the most expensive answer you can give.