Children's Hospital of Philadelphia Header
This job is expired.

Senior Privacy Specialist

Philadelphia, PA
Full-Time

Job Description

SHIFT:

Day (United States of America)

Seeking Breakthrough Makers

Children's Hospital of Philadelphia (CHOP) offers countless ways to change lives. Our diverse community of more than 20,000 Breakthrough Makers will inspire you to pursue passions, develop expertise, and drive innovation.

At CHOP, your experience is valued; your voice is heard; and your contributions make a difference for patients and families. Join us as we build on our promise to advance pediatric care-and your career.

CHOP's Commitment to Diversity, Equity, and Inclusion

CHOP is committed to building an inclusive culture where employees feel a sense of belonging, connection, and community within their workplace. We are a team dedicated to fostering an environment that allows for all to be their authentic selves. We are focused on attracting, cultivating, and retaining diverse talent who can help us deliver on our mission to be a world leader in the advancement of healthcare for children.

We strongly encourage all candidates of diverse backgrounds and lived experiences to apply.


A Brief Overview
The Senior Privacy Specialist will be responsible for supporting the enterprise-wide privacy program at Children's Hospital of Philadelphia that includes its hospitals, physician practices, primary and specialty care practices, the Research Institute and Foundation. Main areas of responsibility for this position include, assisting with privacy-related tasks such as incident investigations and data breach notification/reporting, policy development/updates, training, and various monitoring activities to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA) and other privacy-related laws and regulations. This position reports to the Manager, Privacy Operations within the Office of Compliance and Privacy.

What you will do

  • Triage and respond to privacy inquiries from workforce members, patient families and regulators on various privacy related matters, concerns, and questions.
  • Lead privacy incident investigations, including fact gathering, creating, and maintaining accurate documentation of required HIPAA breach assessment and notification to patient families and regulatory agencies and monitoring of corrective action plans as appropriate.
  • Collaborate with other internal stakeholders to investigate, respond to questions and resolve privacy issues involving the collection, use, sharing, etc. of protected health information, personally identifiable information and/or other personal data. Such stakeholders generally include Health Information Management, Digital Technology Services, Information Security, Office of General Counsel, the Research Institute, Human Resources and other clinical and administrative business units/leaders.
  • Lead the enterprise-wide proactive audit log monitoring program focused on detecting and investigating potential unauthorized access to electronic patient health information. This includes collaborating with and supporting business leaders and Human Resources through the investigation and sanctions process to ensure corrective/disciplinary action is applied in accordance with Hospital policy.
  • Create and deliver privacy awareness and educational materials/communications to increase workforce member's understanding of CHOP's privacy policies/job aids and data handling best practices.
  • Lead the creation and update of privacy content on the intranet and internet, CHOP policies/job aids, Notice of Privacy Practices and department standard operating procedures including recommending updates based on regulatory/operational changes as appropriate.
  • Provide privacy subject matter expertise on operational committees and otherwise serve as an enterprise resource on privacy regulatory requirements.
  • Generate reports on privacy program activities including, but not limited to privacy incidents, breaches, proactive monitoring program, and educational activities.
  • Participate in and/or manage projects to support the annual privacy work plan, board reporting, and enterprise risk assessment process.
  • Conduct ongoing routine audits to monitor compliance with privacy policies, job aids and regulatory requirements.
  • Support the Manager and Director, Privacy Operations on other duties to support privacy program operations.
  • From time to time, lead and/or support miscellaneous Office of Compliance & Privacy initiatives and/or projects.


Licenses and Certifications

  • Certified Information Security Professional/United States (CIPP/US) - International Association of Privacy Professionals (IAPP) - - Preferred


Education

  • Bachelor's Degree Health or Business Administration, Health Information Management, Information Security, law or related field. Required


Experience

  • At least five (5) years Professional work experience showing increasing levels of responsibility. Required
  • At least two (2) years Healthcare, health information management, compliance, or law setting. Preferred
  • At least two (2) years Experience with HIPAA, and other privacy-related laws/regulations/standards (including, but not limited to, state data privacy or international data privacy), data protection standards/controls, health information management, general compliance or healthcare operations preferred
  • Experience with data technologies and tools preferred
  • Experience within a Compliance, Legal or Risk Management role in a hospital setting preferred.


Knowledge, Skills and Abilities

  • Superior interpersonal skills, including individual and group interactions, and ability to communicate appropriately and effectively with a wide variety of individuals at all levels in the organization. (Required proficiency)
  • Excellent analytical and problem-solving skills. (Required proficiency)
  • Ability to communicate thoughts, ideas, and complex topics clearly in both verbal and written formats. (Required proficiency)
  • Ability to manage, multi-task and prioritize high volume workload with competing priorities, while exercising appropriate professionalism and judgment. (Required proficiency)
  • Strong attention to detail and organizational skills with the ability to meet deadlines. (Required proficiency)
  • Ability to handle sensitive information and business affairs with discretion and confidentiality. (Required proficiency)
  • Highly motivated and demonstrates initiative to learn new concepts and develop additional skills and expertise in a fast-paced complex organization. (Required proficiency)
  • Proficiency with Microsoft (MS) Office (Word/Excel/Power Point/Teams). (Required proficiency)
  • Demonstrated leadership and project management. (Required proficiency)
  • Experience with MS Access and SharePoint. (Preferred proficiency)
  • Ability to understand government regulations, federal, state and international privacy laws and requirements relating to data privacy and its application to healthcare operations, including, but not limited to the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and the Breach Notification Rule. (Preferred proficiency)
  • A firm understanding of electronic health record applications such as Epic. (Preferred proficiency)
  • A firm understanding of information security requirements including those that impact the healthcare industry. (Preferred proficiency)
  • Experience with assessing privacy risk related to new technology. (Preferred proficiency)
  • Proficiency with data collection, analytics, and reporting tools. (Preferred proficiency)
  • Industry certification in privacy, health information management or information security. (Preferred proficiency)
  • Knowledge and experience in an academic research setting. (Preferred proficiency)


To carry out its mission, CHOP is committed to supporting the health of our patients, families, workforce, and global community. As a condition of employment, CHOP employees who work in patient care buildings or who have patient facing responsibilities must be fully vaccinated against COVID-19 and receive an annual influenza vaccine. Learn more.

Employees may request exemptions for valid religious and medical reasons. Start dates may be delayed until candidates are immunized or exemption requests are reviewed.

EEO / VEVRAA Federal Contractor | Tobacco Statement

PDN-9d318277-b02c-4d03-84d8-413962681a66

SHIFT:

Day (United States of America)

Seeking Breakthrough Makers

Children's Hospital of Philadelphia (CHOP) offers countless ways to change lives. Our diverse community of more than 20,000 Breakthrough Makers will inspire you to pursue passions, develop expertise, and drive innovation.

At CHOP, your experience is valued; your voice is heard; and your contributions make a difference for patients and families. Join us as we build on our promise to advance pediatric care-and your career.

CHOP's Commitment to Diversity, Equity, and Inclusion

CHOP is committed to building an inclusive culture where employees feel a sense of belonging, connection, and community within their workplace. We are a team dedicated to fostering an environment that allows for all to be their authentic selves. We are focused on attracting, cultivating, and retaining diverse talent who can help us deliver on our mission to be a world leader in the advancement of healthcare for children.

We strongly encourage all candidates of diverse backgrounds and lived experiences to apply.


A Brief Overview
The Senior Privacy Specialist will be responsible for supporting the enterprise-wide privacy program at Children's Hospital of Philadelphia that includes its hospitals, physician practices, primary and specialty care practices, the Research Institute and Foundation. Main areas of responsibility for this position include, assisting with privacy-related tasks such as incident investigations and data breach notification/reporting, policy development/updates, training, and various monitoring activities to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA) and other privacy-related laws and regulations. This position reports to the Manager, Privacy Operations within the Office of Compliance and Privacy.

What you will do

  • Triage and respond to privacy inquiries from workforce members, patient families and regulators on various privacy related matters, concerns, and questions.
  • Lead privacy incident investigations, including fact gathering, creating, and maintaining accurate documentation of required HIPAA breach assessment and notification to patient families and regulatory agencies and monitoring of corrective action plans as appropriate.
  • Collaborate with other internal stakeholders to investigate, respond to questions and resolve privacy issues involving the collection, use, sharing, etc. of protected health information, personally identifiable information and/or other personal data. Such stakeholders generally include Health Information Management, Digital Technology Services, Information Security, Office of General Counsel, the Research Institute, Human Resources and other clinical and administrative business units/leaders.
  • Lead the enterprise-wide proactive audit log monitoring program focused on detecting and investigating potential unauthorized access to electronic patient health information. This includes collaborating with and supporting business leaders and Human Resources through the investigation and sanctions process to ensure corrective/disciplinary action is applied in accordance with Hospital policy.
  • Create and deliver privacy awareness and educational materials/communications to increase workforce member's understanding of CHOP's privacy policies/job aids and data handling best practices.
  • Lead the creation and update of privacy content on the intranet and internet, CHOP policies/job aids, Notice of Privacy Practices and department standard operating procedures including recommending updates based on regulatory/operational changes as appropriate.
  • Provide privacy subject matter expertise on operational committees and otherwise serve as an enterprise resource on privacy regulatory requirements.
  • Generate reports on privacy program activities including, but not limited to privacy incidents, breaches, proactive monitoring program, and educational activities.
  • Participate in and/or manage projects to support the annual privacy work plan, board reporting, and enterprise risk assessment process.
  • Conduct ongoing routine audits to monitor compliance with privacy policies, job aids and regulatory requirements.
  • Support the Manager and Director, Privacy Operations on other duties to support privacy program operations.
  • From time to time, lead and/or support miscellaneous Office of Compliance & Privacy initiatives and/or projects.


Licenses and Certifications

  • Certified Information Security Professional/United States (CIPP/US) - International Association of Privacy Professionals (IAPP) - - Preferred


Education

  • Bachelor's Degree Health or Business Administration, Health Information Management, Information Security, law or related field. Required


Experience

  • At least five (5) years Professional work experience showing increasing levels of responsibility. Required
  • At least two (2) years Healthcare, health information management, compliance, or law setting. Preferred
  • At least two (2) years Experience with HIPAA, and other privacy-related laws/regulations/standards (including, but not limited to, state data privacy or international data privacy), data protection standards/controls, health information management, general compliance or healthcare operations preferred
  • Experience with data technologies and tools preferred
  • Experience within a Compliance, Legal or Risk Management role in a hospital setting preferred.


Knowledge, Skills and Abilities

  • Superior interpersonal skills, including individual and group interactions, and ability to communicate appropriately and effectively with a wide variety of individuals at all levels in the organization. (Required proficiency)
  • Excellent analytical and problem-solving skills. (Required proficiency)
  • Ability to communicate thoughts, ideas, and complex topics clearly in both verbal and written formats. (Required proficiency)
  • Ability to manage, multi-task and prioritize high volume workload with competing priorities, while exercising appropriate professionalism and judgment. (Required proficiency)
  • Strong attention to detail and organizational skills with the ability to meet deadlines. (Required proficiency)
  • Ability to handle sensitive information and business affairs with discretion and confidentiality. (Required proficiency)
  • Highly motivated and demonstrates initiative to learn new concepts and develop additional skills and expertise in a fast-paced complex organization. (Required proficiency)
  • Proficiency with Microsoft (MS) Office (Word/Excel/Power Point/Teams). (Required proficiency)
  • Demonstrated leadership and project management. (Required proficiency)
  • Experience with MS Access and SharePoint. (Preferred proficiency)
  • Ability to understand government regulations, federal, state and international privacy laws and requirements relating to data privacy and its application to healthcare operations, including, but not limited to the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and the Breach Notification Rule. (Preferred proficiency)
  • A firm understanding of electronic health record applications such as Epic. (Preferred proficiency)
  • A firm understanding of information security requirements including those that impact the healthcare industry. (Preferred proficiency)
  • Experience with assessing privacy risk related to new technology. (Preferred proficiency)
  • Proficiency with data collection, analytics, and reporting tools. (Preferred proficiency)
  • Industry certification in privacy, health information management or information security. (Preferred proficiency)
  • Knowledge and experience in an academic research setting. (Preferred proficiency)


To carry out its mission, CHOP is committed to supporting the health of our patients, families, workforce, and global community. As a condition of employment, CHOP employees who work in patient care buildings or who have patient facing responsibilities must be fully vaccinated against COVID-19 and receive an annual influenza vaccine. Learn more.

Employees may request exemptions for valid religious and medical reasons. Start dates may be delayed until candidates are immunized or exemption requests are reviewed.

EEO / VEVRAA Federal Contractor | Tobacco Statement

PDN-9d318277-b02c-4d03-84d8-413962681a66

About Children's Hospital of Philadelphia

At Children’s Hospital of Philadelphia (CHOP), our team of 16,000 employees is as diverse as the community we serve. We know that diverse teams provide the best care and come up with the most creative solutions, because we see the results every day. We’re finding new treatments for the most challenging diseases. We’re addressing health disparities to give every child a healthier future. And we’re making amazing breakthroughs in every area of our Hospital and Research Institute.

Diversity Initiatives

At CHOP, we believe that diversity and inclusion are critical to the ideal patient experience, foundational to the success of workforce recruitment, retention, and development, and imperative in addressing healthcare disparities in our community. Examples of some of the programs, initiatives, and strategies that CHOP employs enterprise-wide in support of these beliefs include:

Diversity Council

The CHOP Diversity Council provides oversight and support in the execution of the CHOP Diversity and Inclusion Strategic Plan. Members are positioned to embed a culture of inclusion across the organization and work with leaders and employees within departments to support diversity objectives.

Cultural Awareness Council

The CHOP Cultural Awareness Council provides advisory and strategic guidance in the execution of various cultural awareness events, experiences, and opportunities offered across the hospital to employees and patients/families.

Employee Resource Groups and Affinity Groups

These groups provide our employees with a sense of connection to the broader mission of the organization beyond their day-to-day tasks. Members provide each other with an enhanced sense of belonging by broadening access to personal and professional development and growth through mentoring, volunteerism, and community involvement. Groups also provide opportunities that allow the voices of employees to be heard and the power of diverse thinking to influence the policies, protocols, and practices that define the workplace. For more information about any of the below groups, please email diversityandinclusion@email.chop.edu.

  • All Abilities Resource Group — This group aims to develop and enhance CHOP’s workplace diversity efforts by expanding the visibility of people with disabilities in the workplace, and offering recommendations for adequate accommodations and resources available for employees and families throughout the organization.
  • LGBTQ+ Pride — This group works to foster a positive work environment that supports employees, patients, and patient families identifying as lesbian, gay, bisexual, transgender, and questioning (LGBTQ) and our allies (non-LGBT advocates).
  • Multicultural Professionals Network — This diverse group of employees — representing multiple racial, cultural and ethnic groups — seeks to continue their career development, provide outreach within the community, and foster a positive work environment that supports employees, patients and patient families of all ethnicities.
  • Young Professional Network — This group focuses on generational diversity in the workplace, networking, professional development, and engagement of early-career professionals at Children’s Hospital of Philadelphia, the CHOP Research Institute, and associated networks.
  • U.S. Military — This group aims to create a comfort zone for military and veteran employees by providing networking, helping with integration into the civilian workforce, and advocating for more inclusion.
  • iSTEM — This group focuses on inclusion in the biomedical science, technology, engineering, and math workforce, and works to engage employees and serves the patient population by addressing disparities.
  • WOMEN — This group works to support women in their career growth and provides resources for women in order to maximize work/life balance.
  • Multicultural Physician’s Alliance — This group is composed of ethnic minority residents, fellows and attending physicians whose interest is to maintain and expand the diversity of Children's Hospital of Philadelphia's medical staff. The MPA is composed of more than 40 physicians who meet several times a year to organize activities for recruitment and to provide a supportive social network for its members. Through the support of Children's Hospital of Philadelphia’s Pediatric Residency Program and the Office of Diversity and Inclusion, this unique organization has become an integral part of the CHOP community.
Veterans and Individuals With Disabilities

Children’s Hospital of Philadelphia is committed to being an employer of choice. In doing so, CHOP seeks to develop and nurture its diversity and believes that diversity among its workforce strengthens the organization, stimulates creativity, promotes the exchange of ideas, and enriches the work lives of all employees. CHOP is committed to working with and providing reasonable accommodation to persons of all abilities, including persons with disabilities. CHOP is also proud to employ active-duty military and veterans; leverage your military background, skills, and experiences to launch a CHOP career.

Diversity Awareness, Education and Programs

At CHOP, increasing staff capacity to work with one another and our diverse patients and families happens in a variety of ways. The Office of Diversity and Inclusion partners across the hospital to provide diversity, inclusion, and cultural competence education through broad offerings both in-person and online. Diversity, Inclusion, and Cultural Competence are also a CHOP Leadership Competency. We apply this standard not only in rating a leader’s performance but at all phases of the annual performance cycle — and at all phases of a leader’s career. We also collaborate on key events to bring our workforce into our surrounding community, including the annual MLK Day of Service and ADL’s Walk Against Hate. For more information about our diversity awareness and education programs, please contact the Office of Diversity and Inclusion.

Supplier Diversity

CHOP is committed to providing opportunities to small, disadvantaged businesses, women and minority-owned, LGBTQ-owned, veteran-owned, and small businesses located in historically underutilized business zones. CHOP encourages all small, local, diverse and disadvantaged businesses to register on our online bidding system to be made aware of all large order or term contract bids that are available via Supply Chain.


Since its start in 1855 as the nation's first hospital devoted exclusively to caring for children, The Children's Hospital of Philadelphia has been the birthplace for many dramatic firsts in pediatric medicine. The Hospital has fostered medical discoveries and innovations that have improved pediatric healthcare and saved countless children’s lives.

Today, The Children's Hospital of Philadelphia is one of the leading pediatric hospitals and research facilities in the world. Our 150 years of innovation and service to our patients, their families and our community reflect an ongoing commitment to exceptional patient care, training new generations of pediatric healthcare providers, and pioneering significant research initiatives.

Related Jobs

Apply For This Job
Senior Privacy Specialist
Children's Hospital of Philadelphia
Philadelphia, PA
Oct 8, 2024
Full-time
Your Information
First Name *
Last Name *
Email Address *
This email belongs to another account. Please use a diferent email address or Sign In.
Zip Code *
Password *
Confirm Password *
Create your Profile from your Resume
By clicking the Apply button, you agree to the terms of use and privacy policy and consent to receive emails from us about job opportunities, career resources, and other relevant updates. You can unsubscribe at any time.
Ace your interview with
AI-powered interview practice

Get comfortable talking to hiring managers, receive personalized feedback on areas for improvement, sharpen your ability to answer the most common questions, and build confidence in formulating strong responses on the spot. Click the button below to begin your three free virtual interviews!

©2025 International Association of Women.
Powered by TalentAlly.