Both officers appointed with signed designation evidence, a written rationale when one person holds both roles, and a policy that names where complaints actually go.
The rule requires a named security official. Most clinics have one in the sense that someone would raise their hand, which is not the same as a designation anyone can produce.
Your officer designation policy names both your privacy and security officers, how designations are made, what authority the role carries, the qualifications expected, where complaints go, rendered from your own recorded contact, how the workforce is told, interim coverage during a vacancy, the cadence for keeping designations current, how changes are handled, and records. A clinic where one person holds both roles gets a clause addressing exactly that.
Eight requirements:
The dual-role check compares the two appointments and only asks for a rationale when they are the same person. Small clinics frequently combine the roles, which is permitted, but combining them without a stated reason is a gap worth closing before someone asks.
The system tracks appointments, evidence documents, and the dual-role rationale. It does not evaluate whether the named officer actually performs the role, has the time for it, or is qualified beyond what your policy states. A designation on file is a designation, not a working compliance function.
That said, the failure this catches is real: an officer named in a policy years ago who has since left, or a role assigned verbally with nothing signed.
Two named officers with signed designation evidence and dates. A documented rationale where the roles are combined. A policy naming where complaints go. The answer to “who is your security official,” with a document behind it.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.