Health System Privacy Officer
About The Job
The System Privacy Officer serves as the leader of the healthcare privacy program, overseeing HIPAA compliance, privacy investigations, audits, training, and risk mitigation efforts across a complex academic healthcare environment. This role provides strategic guidance on privacy regulations and serves as a trusted advisor to operational and executive leaders, ensuring patient information is protected while supporting organizational goals.
Reporting to the Chief Compliance Officer, the ideal candidate brings extensive healthcare privacy and HIPAA experience, preferably within a healthcare system, along with strong leadership, analytical, and relationship-building skills. Success in this role requires the ability to foster collaboration, influence stakeholders, and balance regulatory compliance with operational needs.
Shift
Exempt Employee – Standard Day Shift
Department
Compliance
Compensation
Base Pay Range: $145,808 - $237,848 per year, based on experience
Moving Allowance
Negotiable
Job Description
Oversees implementation and management of the HIPAA Privacy Program to ensure compliance with applicable federal and state regulations. Monitors compliance with HIPAA privacy and related state laws across covered components. Leads investigations of potential privacy breaches, documents findings, ensures mitigation and reports as required. Coordinates privacy audits, risk assessments, and monitoring activities to identify gaps and support mitigation strategies. Provides subject-matter expertise on privacy implications for clinical research, information exchanges, and health data utilities. Collaborates with compliance, legal, information security, and clinical teams to support privacy-by-design in operations and technology initiatives. Participates in system-level data governance and other committees, ensuring privacy considerations are fully integrated. Develops, implements, and updates policies and procedures governing access, use, and disclosure of protected health information (PHI). Coordinates privacy-related education, awareness, and training initiatives to promote HIPAA compliance across all levels of staff and faculty. Monitors privacy program metrics, trends, and incident patterns to identify areas of risk and drive system-wide improvements. Advises and collaborates with MU Health Care leadership, academic partners, and the Tiger Institute on privacy-related initiatives and projects. Prepares regular reports for the Chief Compliance Officer and other leadership on privacy compliance status, investigations, and policy developments. Serves as a key liaison for responding to regulatory inquiries, audits, and investigations related to privacy compliance. Leads, mentors, and supports privacy department staff in best practices, standards, and continuous improvement. Ensures appropriate documentation and tracking of compliance program activities. Leads a culture of safety through proactive risk mitigation and continuous quality improvement, taking measures to routinely evaluate regulatory readiness. Monitors and analyzes safety and performance metrics to identify trends and implement corrective actions for staff and/or patients as appropriate. Manage the development, coordination, and maintenance of daily staffing schedules to ensure the appropriate level of coverage and continuity of care. Monitor and oversee time and attendance in alignment with MU Health Care policies and practices, ensuring accuracy of records and timely approval for payroll purposes. May complete unit/department-specific duties as outlined in department documents.
Knowledge, Skills, And Abilities
Demonstrates advanced knowledge in health care compliance, with specific expertise in privacy and data protection regulations. In-depth understanding of the HIPAA Privacy Rule, HIPAA Security Rule, and the Health Information Technology for Economic and Clinical Health Act (HITECH), as well as applicable state health privacy regulations. Proven ability to interpret and apply privacy laws to complex academic medical center and data exchange settings. Applies critical thinking and problem-solving skills to investigate and analyze privacy incidents, evaluate risk, and guide appropriate responses. Ability to review contracts and data-sharing agreements to determine Business Associate Agreement (BAA) applicability and to oversee negotiation, execution, and management of BAAs in alignment with HIPAA standards. Utilizes technical tools and methodologies to support operational goals, maintain compliance, and optimize privacy performance across digital and clinical systems. Builds consensus and leads initiatives across diverse stakeholders with strong leadership and project management skills. Communicates technical and regulatory information clearly to clinical, administrative, and academic teams, both in writing and verbally. Proficiency in developing and delivering educational content to clinical, administrative, and academic teams on privacy compliance topics. Collaborates effectively with interdisciplinary teams to support innovation, regulatory readiness, and service delivery. Possesses knowledge of clinical operations, academic medical environments, research practices, and digital health tools, including health information exchanges, health data utilities, and multi-entity systems.
Required Qualifications
Bachelor's degree in Healthcare, Business, Legal Studies, Accounting, Finance, or a related area. Master's degree in a related area or an equivalent combination of education and experience from which comparable knowledge, skills, and abilities can be acquired. Seven (7) years of related experience.
Preferred Qualifications
Juris Doctor (JD) or Master's degree in Business Administration, Health Administration, or Finance. Certified in healthcare privacy compliance (CHPC) by the Health Care Compliance Association. Experience working in an academic medical center or integrated health system. Advanced knowledge of healthcare privacy practices, electronic health records, and breach mitigation strategies.