Privacy Specialist
Texas Health and Human Services · Austin, TX · Yesterday
Legal$5k–$6k/moFull-time
About the role
This Privacy Specialist (Program Specialist VI) position reports to the HHSC Privacy Director and performs moderately advanced consultative services and technical assistance work for internal and external agency partners during the course of privacy investigations.
Responsibilities
- Leads or participates in privacy incident response activities, including triage and investigation, regulatory research, third party contractual obligations, risk assessment, breach determination, remediation, notification, prevention, and analysis.
- Coordinates with internal and external agency partners to investigate incidents, document investigation findings, and share recommendations.
- Maintains privacy-related compliance records for federal audits and compiles relevant information for required reporting to federal officials.
- Validates data and prepares briefing materials for leadership.
- Provides technical assistance to other program areas to facilitate the implementation of policy or program changes that may be impacted by privacy issues.
- Plans and conducts detailed, complex research and analyses of privacy complaints, including analysis of compliance with rules, policies, laws, regulations, operational procedures, and policies.
- Collects, validates, and documents findings, reports, and other information to identify operational trends and potentially emerging operational issues related to privacy and privacy-related issues.
- Reports relevant changes and their implications to division leadership.
- Reports privacy breaches to the federal government, as required.
- Utilizes Archer eGRC and data visualization software to develop reports for leadership.
- Assists with the development, maintenance, and review of privacy-related manuals, policies, and procedures.
- Serves as Archer eGRC backup for application development, testing, and production.
- Researches and monitors current and emerging regulatory requirements related to privacy, including potential implications of statutory or policy changes.
- Researches and monitors industry best practices in order to make recommendations for the development and improvement of privacy-related processes and activities.
Knowledge, Skills and Abilities
- HHSC divisions, business, and program areas.
- Medicaid, CHIP, SNAP, and TANF.
- Federal and state privacy laws, regulations, and rules (e.g., HIPAA; Texas Identity Theft Enforcement and Protection Act), including applicable reporting and breach notification requirements and timelines.
- Personally Identifiable Information (PII), Protected Health Information (PHI), Sensitive Personal Information (SPI), and other confidential or sensitive information types.
- Privacy incident and breach investigation principles, including incident identification, assessment, documentation, mitigation, and resolution.
- Root cause analysis and corrective action principles.
Skills
- Investigating privacy incidents and gathering, reviewing, and evaluating relevant facts and evidence.
- Analyzing complex or incomplete information and identifying privacy risks, compliance concerns, and additional information needed to complete an investigation.
- Preparing professional written communications, investigative summaries, reports, and recommendations.
- Managing multiple investigations and assignments simultaneously while meeting regulatory and organizational deadlines.
- Reviewing and organizing supporting documentation such as emails, policies, procedures, system records, and contractual requirements.
- Maintaining effective working relationships.
Ability
- Independently plan, conduct, and document incident investigations from initial report through resolution.
- Exercise sound judgment when facts are incomplete, conflicting, or evolving.
- Identify gaps or inconsistencies in available information and pursue appropriate follow-up.
- Handle confidential and sensitive information with discretion and care.
- Organize complex facts and develop clear, logical, and well-supported conclusions.
- Recognize matters that require escalation to management or other agency partners.
- Prioritize assignments based on risk, regulatory requirements, and established deadlines.
- Adapt to changing facts, priorities, regulatory requirements, and organizational needs.
Qualifications
- Certified Information Privacy Professional (CIPP/US), Certified Information Privacy Manager (CIPM), or equivalent certification is preferred.
- Bachelor’s degree in a relevant field is preferred.
- Experience performing professional work involving investigation, analysis, compliance, auditing, risk assessment, case review, regulatory review, quality assurance, program policy, legal or policy research, or other work requiring the evaluation of facts, application of standards or requirements, professional judgment, and written documentation of findings, conclusions, or recommendations is required.
Pay
$5,250.00 – $6,250.00 per month.
Schedule
Full-time, day shift. Eligible for telework (up to 5% travel).
Benefits
- 100% paid employee health insurance for full-time eligible employees.
- Defined benefit pension plan.
- Generous time off benefits.
- Numerous opportunities for career advancement.