Privacy Officer – Legal
Job Description
Job Purpose or Objective(s): Provides strategic leadership and oversight of the organization’s privacy and security program to ensure compliance, manage risk, protect information assets, and promote a culture of privacy, security, and accountability. The position provides strategic guidance to executive leadership and oversees the continuous improvement of privacy and security controls, processes, and services to support organizational objectives and regulatory requirements. You will report directly to the Executive Director of Legal.
Monday-Friday, 8:00am-4:30pm
Primary Tasks
- You will build a strategic and comprehensive privacy program that defines policies that allow privacy practices which minimize risk and ensure the confidentiality of protected health information (PHI), paper and electronic, across all media types. Ensure privacy forms and procedures are up-to-date.
- Collaborate with the information security officer to ensure understanding between security and privacy compliance programs including policies, investigations, and acts as a liaison to the information systems department.
- Establish with the information security officer, an ongoing process to track inappropriate access and disclosure of protected health information. Monitor patterns of inappropriate access and disclosure of protected health information.
- Work cooperatively with the Health Information Management (HIM) Director and other applicable organization units in overseeing patient rights to inspect access to protected health information.
- You will take a lead role, to ensure we have and maintain appropriate privacy and confidentiality consents, authorization forms and information notices and materials reflecting current organization and legal practices and requirements.
- Be information privacy resource to our organization regarding release of information and to all departments for all privacy related issues.
- Perform other tasks as assigned.
Job Requirements
- Bachelor's degree with Business Administration or related field or 4 years related experience.
- Knowledge of HIPAA and related Federal and State privacy laws and regulations.
- 3+ years of experience in information access, release of information, and release control technologies.
- Skill in examining and re-engineering operations and procedures, formulating policy, and developing new strategies and procedures.
- 4+ years of related experience.