The Campus Covered Components (CCC) Program supports compliance with the Health Insurance Portability and Accountability Act (HIPAA) Security Rule across designated campus covered components, excluding MU Health Care (MUHC) operations.
Launched in Spring 2025, the program helps covered components protect electronic protected health information (ePHI) and maintain the confidentiality, integrity and availability of sensitive health information.
What We Do
The CCC Program works with designated covered components to strengthen and maintain HIPAA Security Rule compliance through:
- Policies and Guidance – Developing institutional policies, resources and guidance to support HIPAA Security Rule requirements.
- Risk and Compliance Assessments – Conducting regular assessments to identify compliance gaps, risks and opportunities for improvement.
- Privacy and Security Awareness – Promoting awareness of responsibilities for protecting ePHI and maintaining appropriate safeguards.
- Compliance Support – Assisting covered components with understanding requirements, addressing identified risks and implementing appropriate compliance activities.
Through these efforts, the CCC Program promotes a consistent approach to HIPAA Security Rule compliance while supporting accountability and protecting sensitive health information across the University of Missouri System.
Designated Covered Components
The University of Missouri System Privacy Officer serves as the official authority for designating covered components and informing the scope of this program. Below is a list of designated covered components listed by Business Unit:
University of Missouri System:
- University of Missouri Medical and Dental Benefits Plans
- University of Missouri Health Flexible Spending Account
- University of Missouri Employee Assistance Program
University of Missouri - Columbia:
- MU Counseling Center
- MU Psychological Service Clinic
- MU Student Health
University of Missouri - Kansas City:
- UMKC School of Dentistry Clinics
University of Missouri - St. Louis:
- UMSL School of Optometry Clinics
- UMSL St. Louis Children’s Advocacy Center
- UMSL Center for Behavioral Health
- UMSL Community Psychological Service
Security Risk Assessments
The CCC Program uses a series of assessments to evaluate HIPAA Security Rule compliance and help covered components identify documentation, safeguards and risk management needs.
HIPAA Organizational Compliance Assessment (HOCA)
Focuses on organizational compliance requirements, including policies, procedures, documentation and other applicable HIPAA Security Rule requirements.
- Baseline: Broad review of primarily critical and high-priority topics to establish an initial understanding of the component’s compliance posture.
- Full Assessment: More in-depth review of applicable organizational requirements, supporting documentation, policies and procedures.
HIPAA Security Rule Assessment for Safeguards (HSRAS)
Focuses on the administrative, physical, and technical safeguards used to protect electronic protected health information (ePHI).
- Baseline: Broad review of primarily critical and high-priority safeguards to establish an initial understanding of the component’s security posture.
- Full Assessment: More in-depth review of safeguard documentation and implementation across administrative, physical and technical requirements.
To learn more about the assessments and the steps involved, visit the Assessment Help page.
Industry-recognized Cybersecurity Resources
The program recognizes the importance of aligning with industry-recognized cybersecurity frameworks to strengthen security practices and support effective risk management.
Our program adopts and recommends guidance from the following frameworks:
- HIPAA Security Rule Standards – Establishes the federal requirements for protecting electronic protected health information (ePHI), including administrative, physical and technical safeguards.
- National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) – Provides a flexible framework for identifying, assessing and managing cybersecurity risks across an organization.
- Health Industry Cybersecurity Practices (HICP) – Provides health care-focused cybersecurity practices and recommendations designed to address common threats and strengthen protection of health information and systems.
Contact Information
Contact Information
Throughout the process, the CCC team works closely with key partners across campus to support coordination, communication and HIPAA Security Rule compliance, including:
- CCC Program Manager: Jennifer Rodriguez, jrodriguez@missouri.edu
- Information Security Officers
- UM System Privacy Officer
Role-based Definitions
Role-based Definitions
Responsible for coordinating the HIPAA Security compliance program for designated Covered Components.
Responsible for complying with applicable HIPAA Security Rule requirements and maintaining appropriate safeguards for ePHI within their operations.
Responsible for overseeing HIPAA Security Rule compliance within the designated Covered Component and serving as the primary point of accountability for security-related matters.
Responsible for providing information security expertise and support related to the Covered Component’s systems, technologies and security practices.
Responsible for following applicable HIPAA Security policies, procedures and safeguards when accessing, using or handling ePHI.
Additional Definitions
Additional Definitions
Administrative actions, policies and procedures to manage the selection, development, implementation and maintenance of security measures to protect electronic protected health information and to manage the conduct of the covered entity's or business associate's workforce in relation to the protection of that information.
Means the property that data or information is accessible and usable upon demand by an authorized person.
Means the property that data or information is not made available or disclosed to unauthorized persons or processes.
Refers to electronic protected health information that is created, received, maintained or transmitted by or on behalf of the health care component of the covered entity.
Means the property that data or information have not been altered or destroyed in an unauthorized manner.
Physical measures, policies and procedures to protect a covered entity's or business associate's electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion.
Means the technology and the policy and procedures for its use that protect electronic protected health information and control access to it.