A covered entity must designate a privacy official responsible for developing and implementing its privacy policies and procedures, and a contact person or office responsible for receiving complaints and providing information about the notice, per 164.530(a).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.