- Company Name
- Interactive Resources - iR
- Job Title
- HIPAA Compliance Consultant
- Job Description
-
**Job Title:** HIPAA Compliance Consultant
**Role Summary:**
Provide hands‑on design, documentation, and operationalization of HIPAA Security and Privacy compliance programs across a national healthcare portfolio of 23 brands. Focus on creating incident response, ransomware, disaster recovery, and PHI data‑flow documentation, performing risk assessments, and ensuring audit readiness.
**Expectations:**
- Deliver comprehensive compliance documentation within a 6‑month contract, with high potential for permanent placement.
- Drive regulatory updates, emerging threat assessments, and vendor risk reviews to keep programs defensible.
**Key Responsibilities:**
- Design and implement HIPAA compliance programs aligned with HIPAA Security and Privacy Rules.
- Author and maintain ransomware response, incident response, and disaster recovery plans tailored to healthcare environments.
- Document PHI data flows across EHRs, claims platforms, and integrations, mapping creation, storage, transmission, and access points.
- Conduct HIPAA risk assessments, identify vulnerabilities, and recommend remediation.
- Map systems and document controls to support audit readiness.
- Partner with IT, legal, and compliance teams to develop security policies and governance structures.
- Track regulatory updates and emerging threats; update documentation accordingly.
- Support internal and external HIPAA compliance audits.
- Assist with vendor/vendor associate risk assessments and BAA reviews.
**Required Skills:**
- 5+ years in HIPAA compliance, GRC, or healthcare risk management.
- In‑depth knowledge of HIPAA Security Rule, Privacy Rule, and HITECH Act.
- Proven experience creating ransomware, incident response, and disaster recovery plans in healthcare.
- Ability to document PHI data flows in EHR, claims, and integration environments.
- Familiarity with NIST Cybersecurity Framework, HITRUST, or ISO 27001 in healthcare settings.
- Strong documentation and analytical skills; deliverable‑focused.
- Experience with multi‑entity or multi‑brand organizations.
- Preferred: GRC platform experience (Drata, Vanta, ServiceNow GRC), cloud security (AWS, Azure, GCP), and vendor risk management.
**Required Education & Certifications:**
- Bachelor’s degree in Information Security, Health Informatics, or related field (or equivalent experience).
- Certifications such as HCISPP, CHPC, CISM, CISSP, or equivalent are preferred.