Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Governance topic
No spam. Unsubscribe anytime.
Commissioners debate limits on privacy‑officer access as county reaffirms hybrid entity status
Summary
A resolution to reaffirm Hamilton County as a hybrid entity and to define HIPAA privacy and security responsibilities prompted debate over whether the county's privacy officer should have 'reasonable' or 'sufficient' access to records and whether privacy and security roles should be combined to save a position.
Get email alerts on the Governance topic
No spam. Unsubscribe anytime.
The commission reviewed Resolution 326‑9, which reaffirms Hamilton County’s status as a hybrid entity for HIPAA compliance and designates covered components and part two programs.
Several commissioners expressed concern about delegating broad authority to modify, create and implement policies without returning the final approval to the full commission. One commissioner urged removal of the word "approve" from a paragraph that delegates policy creation and suggested changing the language that grants the privacy officer access from "reasonable" to "sufficient," citing inspector‑general guidance that compliance officials should have authorized but not unrestricted access.
Miss Duncan, who is referenced in the discussion as the county privacy/security professional, told commissioners she is certified and that the county already has policies, training and a security‑risk assessment in place: "I would say that I am certified," she said, noting existing policy and training materials and that brief‑investigation and auditing procedures are included in the written materials.
Commissioners also discussed budgetary implications and whether combining the privacy and security officer roles could save a position; staff said they would review prior recommendations from the county's counsel and report back. The item will be taken up again after staff reviews suggested language and organizational options.

