HIPAA Privacy Lead

Skills
CFRData ArchitectureData WarehousingHealthcarePrivacy CompliancePrivacy LawRegulatory Requirements
Role

What the job involves

The main requirements, responsibilities and hiring steps.

Requirements

  • 5+ years of hands-on HIPAA Privacy compliance experience in a regulated environment within a Specialty Pharmacy or other Covered Entity
  • Hands-on experience with PHI/PII data flow mapping leading a HIPAA Annual Risk Assessment and designing and delivering HIPAA Incident Management training
  • Working knowledge of the HIPAA Privacy Rule Security Rule interplay BAA requirements and de-identification standards
  • Demonstrated experience drafting or managing BAAs data-sharing agreements or privacy policies and working directly with outside counsel and technical stakeholders
  • Experience using compliance and governance platforms document management systems and Microsoft Office Suite to support HIPAA privacy and compliance programs
  • Strong written communication skills to translate legal and regulatory requirements into plain actionable guidance

Nice to have

  • Healthcare compliance
  • Privacy leadership
  • Cross-functional collaboration
  • Regulatory fluency
  • Detail-oriented
  • Analytical mindset

Day to day

  • Serve as the enterprise HIPAA Privacy subject matter expert for U.S. operations and own day-to-day interpretation and oversight of the HIPAA Privacy Rule
  • Maintain and improve privacy policies procedures and controls across multiple healthcare brands while advising business clinical and IT teams on PHI handling and privacy risk mitigation
  • Conduct privacy risk assessments breach analyses and vendor due diligence while partnering with engineering security legal and compliance stakeholders to embed privacy-by-design