
HIPAA Privacy Lead β Policy, Risk & Compliance
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in Texas.
β’ Oversee and enhance HIPAA Privacy policies and procedures across all covered entities and business associates.
β’ Provide guidance to business, clinical, and IT teams regarding PHI management and strategies for mitigating privacy risks.
β’ Establish, execute, and monitor HIPAA controls alongside GRC, ensuring privacy requirements are in harmony with broader regulatory frameworks, including SOC 2.
β’ Evaluate project designs, system implementations, and process modifications to ensure HIPAA compliance and a privacy-by-design approach.
β’ Manage the BAA inventory, which includes drafting, monitoring, and addressing any gaps.
β’ Assist with the de-identification framework, covering Safe Harbor, Expert Determination, tokenization, and egress governance.
β’ Collaborate with external legal counsel on privacy-related inquiries, data architecture evaluations, and tracking unresolved items.
β’ Perform HIPAA privacy risk assessments and analyses of breach risks.
β’ Maintain the privacy risk register and drive remediation efforts to completion.
β’ Work closely during incidents on breach evaluations, escalation, containment, notification decisions, and post-incident protocols.
β’ Act as the primary contact for privacy complaints, investigations, and regulatory inquiries.
β’ Lead vendor risk assessments for third-party entities managing PHI.
β’ Supervise patient requests for access, amendments, restrictions, and confidential communications.
β’ Collaborate with Engineering and Data Engineering to trace PHI/PII data flows and assess new systems, AI/agentic tools, and vendor integrations.
β’ Create self-service tools and templates for standard privacy requirements.
β’ Design and conduct workforce training on HIPAA privacy and incident management.
β’ Represent AHG's privacy stance in regulatory, audit, and compliance discussions.
β’ Keep abreast of regulatory changes and report on program status to the CCO.
β’ A minimum of 5 years of direct HIPAA Privacy compliance experience in a regulated setting, particularly within a Specialty Pharmacy or other Covered Entity.
β’ Practical experience in mapping PHI/PII data flows.
β’ Proven experience leading a HIPAA Annual Risk Assessment.
β’ Background in designing and delivering HIPAA Incident Management training.
β’ Familiarity with the interplay between the HIPAA Privacy Rule and Security Rule.
β’ Knowledge of BAA requirements (45 CFR Β§164.504(e), Β§164.314(a)).
β’ Understanding of de-identification standards (Β§164.514).
β’ Experience in drafting or managing BAAs, data-sharing agreements, or privacy policies.
β’ Direct experience collaborating with external counsel and technical stakeholders.
β’ Proficiency with compliance and governance platforms like OneTrust, NAVEX, RSA Archer, ServiceNow GRC, or similar tools.
β’ Familiarity with document management systems.
β’ Proficient in Microsoft Office Suite, including Excel, Word, PowerPoint, and Outlook.
β’ Strong writing skills to convert legal/regulatory requirements into practical guidance.
β’ Must possess legal authorization to work in the United States without current or future sponsorship.
β’ Preferred: Certifications such as CHC, CHPC, or CIPP/US.
β’ Preferred: Experience in pharmacy, DTC health/wellness brands, or multi-brand healthcare holding structures.
β’ Preferred: Knowledge of BigQuery, cloud data warehouses, or tokenization/de-identification tools.
β’ Preferred: Exposure to SOC 2 programs.
β’ Comprehensive benefits package including medical, vision, dental, a 401(k) plan with company matching, paid time off, flexible days, holidays, and more.
Terac
DSV - Global Transport and Logistics
Kin Insurance
Summit Therapeutics, Inc.
Get handpicked remote jobs straight to your inbox weekly.