EMStool LLC — Cadence MIH Scheduling Platform

HIPAA Security & Privacy Officer Designation

Policy #: HIPAA-SEC-001 Effective Date: June 1, 2026 Version: 1.0 Next Review: June 1, 2027

1. Purpose

This document formally designates the HIPAA Security Officer and Privacy Officer for EMStool LLC in accordance with the requirements of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations.

The HIPAA Security Rule (45 CFR §164.308(a)(2)) requires covered entities and business associates to identify the security official responsible for the development and implementation of security policies and procedures. The Privacy Rule (45 CFR §164.530(a)) requires designation of a privacy official responsible for the development and implementation of privacy policies and procedures.

2. Designation

Hereby Designated as
HIPAA Security Officer & Privacy Officer
Jacob Russell
Founder & Chief Technology Officer, EMStool LLC
Effective: June 1, 2026

3. Scope of Authority

The Security and Privacy Officer has organization-wide authority and responsibility for all matters relating to HIPAA compliance, including the authority to:

4. Responsibilities

Responsibility AreaSpecific Duties
Risk Management
  • Conduct annual risk analysis identifying threats to ePHI
  • Implement and document risk management measures
  • Review and update risk analysis when significant changes occur
Policies & Procedures
  • Develop and maintain all HIPAA policies (Security, Privacy, Breach)
  • Review all policies annually and update as needed
  • Ensure policies are accessible to all workforce members
Workforce Training
  • Ensure all workforce members complete required HIPAA training
  • Maintain training records for 6 years
  • Provide role-based training for employees with elevated PHI access
Incident Response
  • Serve as primary contact for all security incidents and privacy complaints
  • Conduct breach risk assessments within 72 hours of discovery
  • Manage all breach notification obligations and HHS reporting
Access Management
  • Maintain records of all workforce members with PHI access
  • Ensure access is revoked immediately upon termination or role change
  • Review access logs and audit trails at minimum quarterly
Business Associates
  • Identify all Business Associates who receive or handle PHI
  • Execute BAAs prior to sharing PHI with any third party
  • Monitor BA compliance and address incidents involving BAs
Technical Safeguards
  • Oversee encryption, access controls, and audit logging for all systems containing ePHI
  • Ensure database encryption keys are managed and backed up securely
  • Review and approve all changes to systems that store or transmit ePHI

5. Succession

In the event the designated Security and Privacy Officer is temporarily unavailable, no other individual is currently designated as a successor. In such cases, all security incidents and privacy complaints must be held and documented until the Security Officer is available. For extended unavailability (greater than 14 days), a written interim designation will be issued.

6. Acknowledgment

By signing below, the designated Security and Privacy Officer acknowledges acceptance of the responsibilities described in this document and commits to fulfilling those responsibilities in accordance with HIPAA requirements and EMStool LLC organizational policies.

Security & Privacy Officer Signature
Jacob Russell
Date of Designation
June 1, 2026