Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Privacy And Compliance topic
No spam. Unsubscribe anytime.
Hamilton County moves risk management under COO amid HIPAA breach response; hires outside counsel for compliance review
Summary
The Hamilton County Commission voted to move the countyrisk-management function from the County AttorneyOffice to the chief operating officer and approved up to $40,000 to hire outside counsel to assess HIPAA and related compliance following a data breach.
Get email alerts on the Privacy And Compliance topic
No spam. Unsubscribe anytime.
Hamilton County commissioners on April 9 approved an amended resolution moving the countyrisk-management department from the County AttorneyOffice to the chief operating officer(COO) and separately authorized a contract of up to $40,000 with outside counsel to assess HIPAA and other compliance matters.
The action came after an extended public exchange over the countyresponse to a reported HIPAA breach and whether responsibility for risk management should remain with the County AttorneyOffice, be returned to Human Resources or be assigned to the COO. Commissioners voted to amend the transfer so risk management reports to the COO; the amended resolution was approved by the commission.
The amendment followed a series of motions and a failed attempt to defer action while the commission awaited an outside assessment. County Attorney Tyler Taylor told commissioners the office learned the magnitude of the breach in March and that the office has been working since then on required steps, including notification language. "The key number, as you all have been told, is 500," Taylor said, referring to the number of records involved. Mayor Wong said the county had 60 days from notification to complete required communications and that about 15 days remained. "We have 15 days from today to notify everybody affected by the HIPAA breach," the mayor said during the discussion.
Commissioner Helton moved the amendment that placed risk management under the COO; Commissioner Smith seconded that amendment. Commissioner Sharp led an effort to defer the item while the commission awaited an independent assessment from outside counsel (Baker Donelson); that deferral motion failed. Sharp said he opposed the transfer because he believes the move could create liability and could place compliance staff in a difficult position, saying, "Intimidating privacy officers is a HIPAA violation." Sharp said he would not support placing risk management under the COO because of concerns raised in briefing and legal meetings about staff safety and the scope of authority.
After debate and several procedural motions, the commission approved the amendment and then approved the main motion as amended. The commission also approved a separate resolution authorizing the mayor to enter an agreement with law firm Baker Donelson for an assessment of HIPAA and related federal compliance, not to exceed $40,000. Connor (Baker Donelson) told commissioners the work "is not a compliance audit, but it is to give you a fair assessment" and that the firm planned interviews with county staff and a written report with recommendations, if needed.
County staff and elected officials said the immediate priorities are to finalize breach-notification language and to meet statutory notification deadlines. Commissioners and the mayor repeatedly said they want the notification to go out promptly and that the Baker Donelson assessment is intended to provide a baseline assessment and structural recommendations if required.
Votes at a glance
- Resolution 4 25-5 (transfer risk management): Approved as amended to transfer risk management to the chief operating officer. Amendment moved by Commissioner Helton; amendment seconded by Commissioner Smith. Outcome: approved by the commission as amended (final roll-call recorded in the official minutes).
- Resolution 4 25-13 (contract with Baker Donelson for compliance assessment, up to $40,000): Approved. Sponsor: Commissioner Baker. Second: Commissioner Highlander. Outcome: approved by the commission (final roll-call recorded in the official minutes).
Other items decided the same day (summary)
The commission also approved several routine resolutions and appropriations on the April agenda, including: certification of notaries and deputy oaths (4 25-1); acceptance of the Hamilton County Assessorreappraisal plan under Tennessee Code Annotated section 67-5-1601 (4 25-2); small appropriations to veteran and school booster funds (4 25-3 and 4 25-4); lease agreements with nonprofit and university partners (4 25-6 and 4 25-7); acceptance of a TDOT bridge project (4 25-8); adoption of certain public-works fees (4 25-9); transfer of a surplus vehicle to Marion County fire rehab services (4 25-10); and grant- and debris-related budget amendments for emergency management (4 25-11 and 4 25-12). The clerkrecord and official minutes contain the full roll-call records for each resolution.
Why it matters
The transfer shifts administrative oversight of the countyrisk-management and HIPAA compliance function to the COO amid a time-sensitive breach-notification window. Commissioners said the Baker Donelson assessment is meant to provide an independent, short-term review of the countycompliance posture and structural recommendations on reporting lines and procedures that could be implemented later.
Whathappens next
The county attorneyoffice and administration said they are finalizing notification language and signatures so notifications can be distributed as required. Baker Donelson said it aims to complete its assessment and deliver recommendations within about 30 days, subject to the scope of the engagement and access to staff and records. The commission can revisit the organizational placement of risk management if the outside assessment recommends a different structure.
Quotes
"We have 15 days from today to notify everybody affected by the HIPAA breach," Mayor Wong said during the discussion.
"The key number, as you all have been told, is 500," County Attorney Tyler Taylor said about the size of the breach.
"Intimidating privacy officers is a HIPAA violation," Commissioner Sharp said, urging caution about reporting structure and worker safety.
"It's not a compliance audit, but it is to give you a fair assessment," said Connor of Baker Donelson, describing the scope of the contracted review.
Ending
Commissioners said they expect both breach notifications and the Baker Donelson assessment to be available in short order; the commission can consider structural changes again after it reviews the outside counselreport and any legal recommendations.

