1. Purpose
This document formally designates the HIPAA Security Officer and Privacy Officer for EMStool LLC in accordance with the requirements of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations.
The HIPAA Security Rule (45 CFR §164.308(a)(2)) requires covered entities and business associates to identify the security official responsible for the development and implementation of security policies and procedures. The Privacy Rule (45 CFR §164.530(a)) requires designation of a privacy official responsible for the development and implementation of privacy policies and procedures.
2. Designation
Hereby Designated as
HIPAA Security Officer & Privacy Officer
Jacob Russell
Founder & Chief Technology Officer, EMStool LLC
Effective: June 1, 2026
3. Scope of Authority
The Security and Privacy Officer has organization-wide authority and responsibility for all matters relating to HIPAA compliance, including the authority to:
- Develop, implement, and enforce HIPAA Security and Privacy policies and procedures
- Conduct or commission risk assessments and risk management activities
- Investigate security incidents, breaches, and privacy complaints
- Apply sanctions to workforce members who violate HIPAA policies
- Execute or terminate Business Associate Agreements on behalf of the Organization
- Make breach notification determinations and submit notifications to HHS
- Manage access controls and workforce authorization for all systems containing PHI
- Represent the Organization in any HHS investigation or audit
4. Responsibilities
| Responsibility Area | Specific Duties |
| Risk Management |
- Conduct annual risk analysis identifying threats to ePHI
- Implement and document risk management measures
- Review and update risk analysis when significant changes occur
|
| Policies & Procedures |
- Develop and maintain all HIPAA policies (Security, Privacy, Breach)
- Review all policies annually and update as needed
- Ensure policies are accessible to all workforce members
|
| Workforce Training |
- Ensure all workforce members complete required HIPAA training
- Maintain training records for 6 years
- Provide role-based training for employees with elevated PHI access
|
| Incident Response |
- Serve as primary contact for all security incidents and privacy complaints
- Conduct breach risk assessments within 72 hours of discovery
- Manage all breach notification obligations and HHS reporting
|
| Access Management |
- Maintain records of all workforce members with PHI access
- Ensure access is revoked immediately upon termination or role change
- Review access logs and audit trails at minimum quarterly
|
| Business Associates |
- Identify all Business Associates who receive or handle PHI
- Execute BAAs prior to sharing PHI with any third party
- Monitor BA compliance and address incidents involving BAs
|
| Technical Safeguards |
- Oversee encryption, access controls, and audit logging for all systems containing ePHI
- Ensure database encryption keys are managed and backed up securely
- Review and approve all changes to systems that store or transmit ePHI
|
5. Succession
In the event the designated Security and Privacy Officer is temporarily unavailable, no other individual is currently designated as a successor. In such cases, all security incidents and privacy complaints must be held and documented until the Security Officer is available. For extended unavailability (greater than 14 days), a written interim designation will be issued.
6. Acknowledgment
By signing below, the designated Security and Privacy Officer acknowledges acceptance of the responsibilities described in this document and commits to fulfilling those responsibilities in accordance with HIPAA requirements and EMStool LLC organizational policies.
Security & Privacy Officer Signature
Jacob Russell
Date of Designation
June 1, 2026