Back to Remote jobs   >   Legal   >   privacy officer
HIPAA Privacy Lead @AP MAX INC
Legal
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted Today

[Hiring] HIPAA Privacy Lead @AP MAX INC

Today - AP MAX INC is hiring a remote HIPAA Privacy Lead. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

The HIPAA Privacy Lead serves as the enterprise HIPAA Privacy SME for AHG's U.S. operations, owning day-to-day interpretation, application, and oversight of the HIPAA Privacy Rule. This individual-contributor role reports to the Chief Compliance Officer & Privacy Officer and formalizes work currently led directly by the CCO β€” BAA management, privacy risk assessment, policy development, de-identification governance, and workforce training β€” giving the Privacy program dedicated, sustained ownership as AHG grows. This is a full-time remote position. Candidates must be available to work during standard business hours.

Key Responsibilities

  • Privacy Program & Policy:
    • Maintain and mature HIPAA Privacy policies and procedures across all covered entities and business associates (Southend Pharmacy, Brello, HelloWellness, and AHG Enterprise); advise business, clinical, and IT teams on PHI handling and privacy risk mitigation.
    • Partner with GRC to define, implement, and monitor HIPAA controls and align privacy requirements with AHG's broader regulatory frameworks, including the parallel SOC 2 effort.
    • Review project designs, system implementations, and process changes for HIPAA alignment, embedding privacy-by-design into clinic and enterprise operations.
    • Own the BAA inventory β€” drafting, tracking, and remediating gaps β€” and support AHG's de-identification framework (Safe Harbor / Expert Determination under Β§164.514), including tokenization and egress governance.
    • Partner with outside counsel on privacy legal questions, data architecture reviews, and open-items tracking.
  • Risk Assessment & Incident Response:
    • Conduct HIPAA privacy risk assessments and breach risk analyses (four-factor framework); maintain the privacy risk register and drive remediation to closure.
    • Collaborate with Cyber & Privacy Operations during incidents on breach assessment, escalation/containment/notification decisions, and post-incident SOPs.
    • Serve as primary point of contact for privacy complaints, investigations, and regulatory inquiries, working closely with U.S. Privacy Legal Counsel.
    • Lead vendor risk assessments for third parties handling PHI, including HIPAA-specific due diligence.
  • Patient Rights & Data Governance:
    • Oversee patient requests for access, amendments, restrictions, and confidential communications, ensuring timely, appropriate responses; maintain documentation demonstrating HIPAA compliance.
    • Partner with Engineering and Data Engineering to map PHI/PII data flows and review new systems, AI/agentic tools, and vendor integrations before launch.
    • Develop self-service tools and templates so teams can independently handle routine privacy requirements.
  • Training & Reporting:
    • Design and deliver workforce HIPAA privacy and incident-management training; partner with clinical/operational leaders to embed HIPAA into day-to-day practice operations.
    • Represent AHG's privacy posture in regulatory, audit, and compliance forums; monitor regulatory developments (HHS/OCR, state privacy law, FTC) and report program status to the CCO.

Qualifications

  • 5+ years of hands-on HIPAA Privacy compliance experience in a regulated environment, specifically within a Specialty Pharmacy or other Covered Entity.
  • Hands-on experience with PHI/PII data flow mapping, leading a HIPAA Annual Risk Assessment, and designing/delivering HIPAA Incident Management training.
  • Working knowledge of the HIPAA Privacy Rule, Security Rule interplay, BAA requirements (45 CFR Β§164.504(e), Β§164.314(a)), and de-identification standards (Β§164.514).
  • Demonstrated experience drafting or managing BAAs, data-sharing agreements, or privacy policies, and working directly with outside counsel and technical stakeholders.
  • Experience using compliance and governance platforms (e.g., OneTrust, NAVEX, RSA Archer, ServiceNow GRC, or similar), document management systems, and Microsoft Office Suite (Excel, Word, PowerPoint, and Outlook) to support HIPAA privacy and compliance programs.
  • Strong written communication β€” able to translate legal/regulatory requirements into plain, actionable guidance for business and technical teams.

Requirements

  • Certification such as CHC (Certified in Healthcare Compliance), CHPC (Certified in Healthcare Privacy Compliance), or CIPP/US.
  • Experience with pharmacy, DTC health/wellness brands, or multi-brand healthcare holding structures.
  • Familiarity with BigQuery, cloud data warehouses, or tokenization/de-identification tooling (e.g., Protegrity) sufficient to engage credibly with engineering.
  • Exposure to SOC 2 programs or working alongside a parallel SOC 2 effort.

What Success Looks Like (First 6–12 Months)

  • Working with the CCO, HIPAA Privacy policies drafted and awareness created across the business unit.
  • Intercompany BAAs identified, drafted, and executed, with the BAA inventory as source of truth.
  • Privacy risk register stood up and actively tracked with clear ownership and remediation dates.
  • De-identification framework operationalized with Engineering and Security, including a defensible position on tokenized/egress data.
  • Workforce privacy training launched; CCO able to delegate day-to-day privacy operations with confidence, freeing capacity for SOC 2 and broader Healthcare Compliance work.

Benefits

  • Full benefits package including medical, vision, dental, 401(k) with company match, PTO, Flex days, holidays, and more!

Equal Opportunity Employer Statement

Allia Health Group is proud to be an Equal Opportunity Employer where we are committed to fostering a diverse and inclusive workplace. We are committed to cultivating a culture where all team members feel valued & respected. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetic information, disability, age, veteran status, or any other characteristics protected by applicable law.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   Legal   >   privacy officer
HIPAA Privacy Lead @AP MAX INC
Legal
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted Today
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later