Information Security Compliance Analyst
Core
Managing the annual HIPAA compliance program, including risk assessments, IT system assessments, and policy updates to safeguard patient data.
Role type
Information Security Compliance Analyst
Builds
HIPAA compliance posture and risk management frameworks
Domain
Healthcare / Information Security
Deliverable
client delivery
Required skills
HIPAA program management, Security Risk Assessment (SRA) planning and execution, IT system security assessments, OneTrust record management, HIPAA policy and procedure development, stakeholder management, program scheduling
Preferred skills
Privacy Law knowledge, CISA/CISSP/CHPS certifications, prior experience with third-party consultancy management
Technologies
OneTrust
Responsibilities
Manage annual HIPAA program activities and competing risk assessments; Perform HIPAA Security Assessments on IT systems and track remedial actions; Monitor HIPAA law changes and propose policy updates; Report HIPAA risks to leadership; Organize stakeholders and external resources for program execution
Seniority
Mid-Senior, hands-on IC