HIPAA Privacy Lead
Skills
CFRData ArchitectureData WarehousingHealthcarePrivacy CompliancePrivacy LawRegulatory Requirements
What the job involves
The main requirements, responsibilities and hiring steps.
Requirements
- 5+ years of hands-on HIPAA Privacy compliance experience in a regulated environment within a Specialty Pharmacy or other Covered Entity
- Hands-on experience with PHI/PII data flow mapping leading a HIPAA Annual Risk Assessment and designing and delivering HIPAA Incident Management training
- Working knowledge of the HIPAA Privacy Rule Security Rule interplay BAA requirements and de-identification standards
- Demonstrated experience drafting or managing BAAs data-sharing agreements or privacy policies and working directly with outside counsel and technical stakeholders
- Experience using compliance and governance platforms document management systems and Microsoft Office Suite to support HIPAA privacy and compliance programs
- Strong written communication skills to translate legal and regulatory requirements into plain actionable guidance
Nice to have
- Healthcare compliance
- Privacy leadership
- Cross-functional collaboration
- Regulatory fluency
- Detail-oriented
- Analytical mindset
Day to day
- Serve as the enterprise HIPAA Privacy subject matter expert for U.S. operations and own day-to-day interpretation and oversight of the HIPAA Privacy Rule
- Maintain and improve privacy policies procedures and controls across multiple healthcare brands while advising business clinical and IT teams on PHI handling and privacy risk mitigation
- Conduct privacy risk assessments breach analyses and vendor due diligence while partnering with engineering security legal and compliance stakeholders to embed privacy-by-design
