HIPAA Privacy Officer
About the Role
The HIPAA Privacy Officer will oversee the company’s privacy program, developing, managing, and implementing processes to ensure compliance with applicable federal and state HIPAA regulations and guidelines, particularly regarding access to and use of protected health information (PHI).
Responsibilities
- Policy Development & Risk Assessment
- Evaluates existing policies and procedures for HIPAA compliance by performing risk assessments.
- Collaborates with plan management, administration, and legal counsel to identify and improve privacy policies and procedures.
- Develops and implements new and updated policies and procedures.
- Maintains policies and procedures related to PHI access and use; ensures strict adherence by all staff with access to PHI.
- Compliance, Auditing & Breach Management
- Assesses methods and procedures used to store and transmit PHI; identifies security or compliance risks and recommends improvements.
- Maintains required records and supporting documentation, including authorization forms, notices, and plan documents.
- Completes and maintains a breach investigation process and log to ensure compliance with Office for Civil Rights breach reporting requirements.
- Reviews and edits all Business Associate Agreements for the company.
- Training, Leadership & Communication
- Develops and leads the organization’s health information privacy committee, task force, or similar group.
- Provides training on health information privacy requirements and procedures.
- Communicates with individuals regarding their right to inspect, amend, and restrict access to their PHI.
- Drafts and implements procedures for addressing and resolving complaints about privacy policies.
- Advisory & Governance
- Serves as the internal subject matter expert on HIPAA, maintaining current knowledge of laws and regulations.
- Reports on changes in applicable laws and provides training as needed.
- Facilitates disciplinary steps and sanctions for workforce members who fail to comply with privacy policies.
- Performs other related duties as assigned.
Requirements
- Bachelor’s degree in Human Resources or a related field.
- Minimum of three (3) years of related experience.
- Experience with HIPAA required.
- Thorough understanding of related information privacy laws and regulations, including those governing access, release of information, and security technologies.
Skills
- Excellent verbal and written communication skills, with the ability to explain complex information clearly.
- Strong organizational skills, attention to detail, and proficiency with Microsoft Office Suite or related software.
Preferred Qualifications
- Certifications in privacy compliance (CHC or CHPC).
- SHRM-CP or SHRM-SCP.
Schedule
This is a full-time position, Monday through Friday. Occasional evening and weekend work may be required as job duties demand.
Work Environment
This job operates in a professional office environment. The role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets, and fax machines.
Physical Demands
The physical demands described are representative of those required to successfully perform the essential functions of this job. This is largely a sedentary role; however, some filing may be required, which would involve lifting files, opening filing cabinets, and bending or standing on a stool as necessary.