This exciting, very visible role supports a health system's Privacy Program by leading HIPAA privacy training, audits, monitoring, and investigations to protect patient information and ensure ongoing compliance with applicable laws, regulations, and internal policies.
Responsibilities
- Conduct HIPAA privacy training, audits/rounding, and electronic medical record activity monitoring; review FairWarning reports and investigate questionable access.
- Serve as a HIPAA privacy resource for the workforce by providing guidance on privacy policies/procedures and supporting compliance across departments and clinics.
- Lead privacy investigations (including in-person interviews) and manage corrective action plans; maintain investigation documentation and databases in accordance with policy and regulatory requirements.
- Monitor and interpret changes in HIPAA and related privacy regulations; research guidance and develop reports, correspondence, policies, procedures, and intranet content to support the Privacy Program.
- Partner with key stakeholders (Privacy Officer, Compliance, HR, Legal/CISO, Risk Management, and committees) on risk assessments, breach mitigation and notifications, governance reporting, and program improvements.
Requirements
- 3–5+ years of privacy-related experience in a healthcare or regulatory setting (and at least 3 years in a healthcare environment); ability to manage and prioritize high-volume work independently.
- Strong analytical, critical thinking, and problem-solving skills, including the ability to analyze data/trends, identify deficiencies, and implement corrective actions.
- Working knowledge of HIPAA and patient confidentiality (state/federal privacy laws preferred) and electronic medical records systems (EPIC preferred); proficient with Outlook, Teams, PowerPoint, Word, and Excel.
- Bachelor’s degree required (Master’s preferred) and excellent written, verbal, presentation, and interpersonal communication skills; high integrity and discretion with sensitive information.
- Relevant privacy/compliance certifications preferred (CHPC, CIPP, or CIPM).