Compliance & HIPAA Staffing

Who Owns HIPAA Compliance in a 2-Provider OB-GYN?

Who is responsible for HIPAA compliance in a small office when two owners assume the other has it? Settling the responsibility question in a 2-provider OB-GYN.

The CallSphere Health Team July 14, 2026 8 min read
HIPAA riskCallSphere AIAudit-readyCOMPLIANCE & HIPAA STAFFING

Two OB-GYNs open a practice together. They split the panel, alternate call, and trust each other completely, which is exactly how a HIPAA gap opens. Ask each partner who owns compliance and you get the same answer twice: "I figured you were handling that." Neither is lying. Both assumed the other had it, and the question of who is responsible for HIPAA compliance in a small office quietly went unanswered for two years while the practice grew to 3,000 active patients and a front desk that fields 80 calls a day.

This is the most common failure mode in a two-owner clinic. It is not negligence and it is not ignorance of the rules. It is diffusion of responsibility between two people who each had reason to believe the other was on it. The fix is not more compliance software or a consultant on retainer. It is a decision about ownership, made once, written down, and then made small enough that a busy OB-GYN can actually sustain it.

Why HIPAA holds the practice liable, not a job title

Start with the part that surprises most partners: HIPAA does not assign liability to a person called the privacy officer. It assigns it to the covered entity. Your practice, as a legal entity, is the party the Office for Civil Rights investigates, fines, and enters into a corrective action plan. The privacy official is a required internal role, but naming one does not move the legal exposure onto that individual's shoulders. The practice, and the owners who stand behind it, remain accountable.

That has a sharp implication for a two-owner OB-GYN with no compliance staff. If neither of you has been designated, the default is not "nobody is responsible." The default is "the entity is responsible, and both owners are the entity." A breach investigation into a shared practice does not stop at the partner who happened to be in the building. It looks at policies, training records, risk analyses, and business associate agreements for the whole organization, and both owners answer for the gaps.

So the goal of designation is not to create a scapegoat. It is to create accountability that is real enough to prevent the breach in the first place. 45 CFR 164.530 requires you to designate a privacy official responsible for developing and implementing your policies. 45 CFR 164.308 requires a security official for your electronic protected health information safeguards. Neither rule says the two roles must be different people, and neither says either must be a full-time hire. In a two-provider practice, the honest reading is that you need two roles filled and documented, and you have exactly two owners plus, often, a practice manager to fill them.

The unclaimed duties that actually cause breaches

Here is what makes the two-owner gap dangerous, and it is not the officer title. It is the stream of small PHI decisions that happen at the front desk every hour, none of which either partner is watching because both are in exam rooms. The officer role is a monthly-and-yearly job. The breach risk is a minute-by-minute job, and that is the part that goes unclaimed.

Think about what your front desk decides without you. Whether it is safe to leave OB lab results on a voicemail. Whether the person calling about a patient's ultrasound is actually that patient or a curious relative. What gets said out loud at the check-in window with three other women in the waiting room. How a records request from a divorce attorney gets handled. Whether a no-show reminder text goes to the number a patient's abusive ex still has access to. Each of these is a HIPAA decision, and in a practice where both owners assumed the other was supervising intake, nobody set the rule.

The cascade below is how a two-owner clinic goes from "we trust each other" to a reportable breach without either partner making a single reckless choice.

flowchart TD
  A[Two owners open practice] --> B[Each assumes partner owns HIPAA]
  B --> C[No privacy official designated]
  C --> D[Front desk sets its own call rules]
  D --> E[Voicemails and window talk leak PHI]
  E --> F[Patient complaint to OCR]
  F --> G[Investigation finds no named owner]
  G --> H[Both partners and entity liable]

Notice where the chain actually breaks. It is not at the officer designation, which is a paperwork fix. It is at the front desk, where undefined duties turn into improvised decisions. You can name a privacy official tomorrow and still have this cascade if the daily intake work stays ungoverned. That is why the responsibility question has two halves: who holds the title, and who, or what, governs the calls.

Settling the title: privacy official, security official, and the practice manager

The cleanest resolution in a two-provider OB-GYN is to stop treating "HIPAA" as one job. Split it the way the rules already split it. One partner takes privacy official: policies, the Notice of Privacy Practices, patient access and complaint handling, disclosure decisions, and training. The other takes security official: risk analysis, access controls, encryption, device and password policy, and vendor security review. Each role is a few hours a month once the practice is running on rails, and the split matches how the two of you already divide administrative load.

If you employ a practice manager, they usually become the operational deputy for both roles, but read the practice manager HIPAA responsibilities carefully before you hand it all over. A manager can maintain training logs, collect signed acknowledgments, run point on records requests, and keep the risk-analysis calendar. What a manager cannot do is absorb the legal accountability. The owner-designated officers still answer for the practice, so the designation memo should name the officer partner and describe the manager's delegated tasks underneath, not swap one for the other.

Put it in writing in a single page. Date it, sign it, and store it where an auditor can find it in ten seconds. The memo should say who is privacy official, who is security official, what the practice manager handles day to day, and how patients reach the contact person for complaints. That one page is the difference between "the entity had no accountability structure" and "here is exactly who owned what." When the two owners each stop assuming and instead see their name next to a role, the diffusion problem is solved on paper. The harder half is the front desk.

Closing the front-desk gap without hiring a compliance coordinator

The daily intake duties are the ones neither partner claimed, and hiring your way out is expensive and fragile. A dedicated compliance coordinator runs $55,000 to $75,000 a year in most markets, and a single front-desk staffer who quits takes their undocumented judgment calls with them, restarting the training and the risk. For a two-owner practice, the more durable answer is to make the call-handling rules live in a system instead of in a person's memory, so the same PHI decision gets made the same defensible way every time.

That is where an AI front desk changes the responsibility math. When every inbound call is answered by a system that verifies caller identity before releasing information, follows a fixed script for what can and cannot go on a voicemail, and logs each interaction under a signed business associate agreement, the ambiguous "who was watching intake" question turns into an audit trail. The AI answers 100 percent of calls 24/7, books appointments directly into your schedule, handles the waitlist and reminders, and does it in English and Spanish without a bilingual hire. More to the point for HIPAA: it does not improvise. The disclosure rules your privacy-official partner sets become the rules the front desk actually follows, on call number one and call number 800. You can see how the intake, scheduling, and messaging pieces fit together on the /features page, and the tiers that match a two-provider volume on the /pricing page.

The workflow below shows how the same practice looks once ownership is assigned and intake is systematized. The title question is settled by a memo; the daily question is settled by a logged system.

flowchart LR
  A[Inbound patient call] --> B[AI front desk answers]
  B --> C[Verify caller identity]
  C --> D[Apply disclosure rules]
  D --> E[Book or route request]
  E --> F[Log interaction under BAA]
  F --> G[Officer reviews audit trail]

This does not remove the officer roles, and it should not. Your privacy-official partner still writes the disclosure rules, still handles complaints, still runs training. What the system removes is the part that was truly unowned: the thousand small front-desk judgment calls that no partner was supervising because both were with patients. Those now run on rules you wrote once, with a record you can hand to an auditor.

Making the answer stick after you have assigned it

Assigning ownership once is easy. Keeping it assigned as the practice changes is where two-owner clinics slip back into "I thought you had it." Build three habits so the answer holds. First, revisit the designation memo every year alongside your risk analysis, so a partner sabbatical, a new associate, or a manager's departure does not quietly reopen the gap. Second, keep the front-desk rules in one place, owned by the privacy-official partner, so when the disclosure policy changes it changes everywhere the calls are handled, not just in one staffer's head. Third, review the intake log monthly, even for fifteen minutes, so ownership is a thing you exercise and not just a thing you declared.

The responsibility question in a two-provider OB-GYN was never really about the officer title. It was about the space between two owners who trusted each other and therefore both looked away from the same set of duties. Name the roles in a one-page memo, split privacy and security between the two of you, and route the front desk through a logged system so the daily PHI decisions stop being improvised. Do that, and the next time someone asks who owns HIPAA here, you have an answer with a signature on it, not a shrug and a "I figured you had it."

Frequently asked questions

Who is responsible for HIPAA compliance in a practice with no compliance staff?

The covered entity is responsible, which in a two-partner OB-GYN means the practice itself and, by extension, both owners. HIPAA requires you to designate a privacy official and a security official, but it does not require those to be dedicated hires. Until you name someone in writing, regulators treat the whole practice as accountable, so the safest move is a one-page designation memo assigning the roles to a specific partner or manager.

Who is liable if neither partner owns HIPAA?

Both partners and the practice entity are liable. The absence of a named officer does not shift blame to a third party or excuse the practice; if anything it looks worse to the Office for Civil Rights because it shows no accountability was ever established. In a shared-ownership structure, a breach investigation will pull in both owners regardless of who was closer to the incident, which is exactly why the responsibility should be assigned before anything goes wrong.

Can two owners share HIPAA officer duties?

Yes. One common split in a two-provider practice is one partner as privacy official and the other as security official, since the roles cover different ground. What matters is that the split is written down, that each partner knows which decisions are theirs, and that day-to-day intake and messaging duties are assigned to a specific person or system rather than left floating. Sharing works only when it is documented, not assumed.

Stop staffing around the problem. Let AI cover it.

CallSphere Health puts an AI team inside every part of your front office — answering every call, filling the schedule, chasing claims and recalling patients — so a short-staffed practice runs like a fully-staffed one.

Keep reading