Company Description
In a professional, multidisciplinary environment, while maintaining a broad knowledge of state-of-the-art technology, equipment and systems the Privacy and Security Officer is responsible for the administration of the information security program and maintaining the confidentiality, integrity and availability of data within the organization's information systems for the Health Information Exchange. The Privacy and Security Officer has oversight of the risk assessment process, development of policies, standards, and procedures, testing, and security reporting processes. The Privacy and Security Officer oversees the computer systems infrastructure to safeguard protected health information (PHI) and business information assets following HIPAA guidelines. The Privacy and Security Officer provides periodic updates to the board or senior management. The Privacy and Security Officer Role is supported through HealthInsight's Privacy and Security Management Program.
Job Description
โข Responsible for implementing, managing and enforcing information security derivatives within regulatory mandates to protect PHI including, the Health Insurance Portability and Accountability Act, the American Recovery and Reinvestment Act provisions
โข Ensures the ongoing integration of information security with business strategies and privacy requirements
โข Works closely with operational and support units for ongoing optimal application of technology functionality to protect PHI, including the identity management program
โข Leads information security awareness and training initiatives to educate workforce about policies, procedures and information risks; coordinates with state-based information systems security officers
โข Conducts risk analyses to assess the probability of risks occurring and the impact on the organization
โข Creates an information security risk mitigation plan based on sound risk analysis
โข Performs ongoing security audits to assess effectiveness of policies/procedures and systems security safeguards
โข Works with contractual and other activities with vendors, outside consultants, business associates, and other third parties to improve information security practices
โข Leads the security incident response team in prevention, investigation, mitigation, and reporting activities; ensures appropriate enforcement sanctions for information security breaches
โข Responsible for budget related activities for the security program
โข Manages complaint and incident preventative and investigative programs related to security policies
โข Carries out periodic security risk assessments in conjunction with privacy requirements
โข Manages the security audit program; coordinates action plans for applicable departments to make improvements, when necessary
โข Documents and maintains risk analysis and remediation actions taken by the organization to reduce information security risks
โข Manages retention of performance improvement activity documentation for security functions and compliance responsibilities
โข Recommends system enhancements via capital and operational budget planning to keep pace with privacy and security and technology advances
โข Coordinates security survey regulatory activities and participates in accreditation surveys with external survey bodies
โข Participates in HealtHIE Nevada's internal quality improvement activities as appropriate
โข May delegate certain duties to appropriate individuals
Qualifications
โข Bachelor's degree in information systems, computer sciences, health information management or related field, plus two years of experience in health care including public health, or other health care-related profession; or a Master's degree in health care-related field plus one year of experience in health care including health informatics, public health, or other health care-related profession; or a relevant combination of education and experience
โข Health Information Technology and/or information technology experience desirable but not required
โข Certified Information System Security Professional (CISSP), Certified Information Systems Manager (CISM), Certified in Healthcare Privacy and Security (CHPS) or other related security certifications preferred
โข Availability to travel as necessary
Additional Information
โข Two years of experience and skill in word processing, basic spreadsheet and presentation software applications; familiarity with database software programs (Microsoft Office).
โข Excellent oral and written communications skills.
โข Excellent interpersonal and problem-solving skills.
โข Ability to organize and coordinate multiple simultaneous tasks in a team environment.
โข Knowledge of health care and clinical information system related standards
โข Knowledge of information security standards, rules and regulations related to information security and data confidentiality (e.g. HIPAA, FISMA, NIST, etc.)
โข Knowledge of risk assessment and management methodology and principles for risk identification, analysis, and mitigation