Associate HIPAA Privacy & Data Security Director
Full-time Mid-Senior LevelJob Overview
Under the direction of the Chief Privacy Officer and in close collaboration with the Chief Information Security Officer, the Associate Privacy & Data Security Director will assist with maintaining an effective privacy and data security program, including, but not limited to providing consultative services on privacy and patient confidentiality issues, developing and reviewing policies and procedures, and oversee the privacy and data security program.
Primary Job Duties:
- Initiates, facilitates, and promotes activities to foster a culture of privacy and data security compliance within Privia
- Provides guidance and direction on HIPAA Privacy and Security rules and other applicable federal and state health care privacy laws
- Assists in the development, implementation, and maintenance of administrative, physical, and technical safeguards for personally identifiable data, including, but not limited to managing user access, enforcing least-privilege principles, and maintaining system audit logs
- Periodically reviews and proposes revisions to Privia’s Privacy and Security Policies and Procedures and guidance materials to facilitate compliance with new privacy or cybersecurity-related laws/regulations or changes to existing federal, state, and local privacy or cybersecurity rules and regulations
- Collaborates with the CPO and CISO on the development of privacy and security training modules
- Assists ongoing privacy and security compliance monitoring and auditing activities, including staff awareness programs on phishing, ransomware, and insider threats
- In collaboration with the CPO and CISO, supports investigations of privacy and security incidents, breach risk assessments, and reporting to affected individuals and, when needed, HHS-OCR or other applicable agencies
- Maintains rapport with all business units to facilitate spirit of collaboration
- Collaborates with Information Security including conducting and reviewing security risk assessments to facilitate the implementation of effective mitigation of identified risks
- Assists with the implementation and management of PCI-DSS standards and SOX controls
- Other duties as assigned
Make Your Resume Now