Senior Privacy Analyst
JOB SUMMARY
This role will support the Company’s privacy and data protection program by working with members of the Compliance department and other cross-functional teams to implement, maintain and oversee privacy-related compliance efforts. The person in this role supports the Sr. Manager, Data Privacy and is responsible for actively supporting and coordinating privacy operations and initiatives, including conducting privacy incident investigations, analyzing reports, performing database management, including disseminating information from various sources and systems. This position supports and coordinates operational activities and initiatives, resolving issues by working with staff across departments. This role may evolve as organizational needs change.
KEY RESPONSIBILITIES
-
Performs advanced (senior level) privacy analysis work. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment.
-
Conducts privacy impact assessments (PIAs), data protection impact assessments (DPIAs), and related risk assessments to evaluate the collection, use, storage, and sharing of personally identifiable data.
-
Affixes with responding to Data Subject Requests and other related privacy requests.
-
Identifies and analyzes privacy risks associated with new and existing products, technologies, and business processes, and recommends mitigation strategies.
-
Investigates, documents and tracks routine privacy incidents in a thorough and timely manner, tracking and reporting trends.
-
Responds timely to, track, and document privacy inquiries, seeking guidance as necessary from the Sr. Manager, Data Privacy.
-
Assists with the development and implementation of the privacy program and privacy policies as necessary to build and maintain an effective privacy program.
-
Collaborates with cross-functional teams to support privacy-by-design principles and ensure privacy requirements are integrated into projects early.
-
Conducts routine and targeted audits of electronic medical records and other electronic systems, to identify and report inappropriate uses and disclosures of sensitive data.
-
Affixes in preparing comprehensive responses to privacy and security surveys and questionnaires required by other program areas.
-
Performs other duties as assigned to support team and organizational objectives.
QUALIFICATIONS
-
Bachelor’s degree in Healthcare Administration, Business Administration, Public Health, Computer Science, or a related field.
-
2-4 years of experience in healthcare privacy compliance.
-
Demonstrated knowledge and understanding of all federal, state and international laws affecting the management of protected health information (PHI) and personally identifiable information (PII).
PREFERRED
-
Certified in Healthcare Privacy Compliance (CHPC) or Certified Information Privacy Professional (CIPP/US).
-
Experience navigating incident management workflows and EMR auditing tools.
-
Experience assessing or reviewing applicable AI laws and regulations, including state-level AI disclosure requirements.
COMPETENCIES
-
Excellent written communication skills, with the ability to draft clear, well-structured assessments, reports, and policies.
-
Strong verbal communication skills, capable of explaining privacy risks and requirements to technical and non-technical audiences.
-
Analytical mindset with attention to detail and sound judgment in risk evaluation.
-
Ability to work independently while collaborating effectively across teams.