1

Grc Analyst Hipaa Jobs in Springfield, MA (NOW HIRING)

Grc Analyst Hipaa information

See Springfield, MA salary details

$36.4K

$97.3K

$227.7K

How much do grc analyst hipaa jobs pay per year?

As of Sep 8, 2026, the average yearly pay for grc analyst hipaa in Springfield, MA is $97,318.00, according to ZipRecruiter salary data. Most workers in this role earn between $54,800.00 and $110,600.00 per year, depending on experience, location, and employer.

What does a GRC analyst specializing in HIPAA do?

A GRC (Governance, Risk, and Compliance) Analyst specializing in HIPAA is responsible for ensuring that an organization complies with the Health Insurance Portability and Accountability Act (HIPAA) regulations. This role involves assessing risks, implementing policies, conducting audits, and monitoring compliance related to the privacy and security of protected health information (PHI). The GRC Analyst works closely with IT, legal, and healthcare teams to identify potential vulnerabilities and recommend improvements to safeguard sensitive data. They also help prepare the organization for external audits and respond to regulatory inquiries.

What are the key skills and qualifications needed to thrive as a GRC analyst specializing in HIPAA?

To excel as a GRC Analyst (HIPAA), you need a solid understanding of risk management, regulatory compliance, and healthcare privacy regulations, often supported by a relevant degree or certifications like CISA or HCISPP. Familiarity with GRC tools, security frameworks (such as NIST or HITRUST), and HIPAA compliance management systems is crucial. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations maintain compliance, avoid costly breaches, and protect sensitive health information.

How does a GRC analyst specializing in HIPAA typically collaborate with IT and compliance teams to ensure ongoing regulatory adherence?

A GRC Analyst focused on HIPAA regularly works alongside IT and compliance teams to assess risks, design and review security controls, and monitor for regulatory changes. They often facilitate communication between departments, translate HIPAA requirements into actionable policies, and help coordinate training or audits. This role requires balancing technical security measures with legal and procedural compliance, ensuring all stakeholders understand and implement HIPAA mandates effectively. Collaborative projects may include conducting risk assessments, incident response planning, and preparing documentation for internal or external audits.

What is the difference between Grc Analyst Hipaa vs Grc Analyst Privacy?

AspectGrc Analyst HipaaGrc Analyst Privacy
CertificationsHIPAA certifications, GRC certificationsGRC certifications, Privacy certifications
Work EnvironmentHealthcare, compliance teamsVarious industries, compliance teams
Employer & IndustryHealthcare providers, insurersMultiple sectors including healthcare, finance, tech

Grc Analyst Hipaa focuses on HIPAA compliance within healthcare organizations, ensuring data privacy and security standards are met. Grc Analyst Privacy has a broader scope, covering privacy regulations across various industries. While both roles require GRC knowledge and certifications, Grc Analyst Hipaa specializes in healthcare-specific laws, whereas Grc Analyst Privacy deals with general privacy policies and frameworks.

What are popular job titles related to Grc Analyst Hipaa jobs in Springfield, MA?

For Grc Analyst Hipaa jobs in Springfield, MA, the most frequently searched job titles are:

What job categories do people searching Grc Analyst Hipaa jobs in Springfield, MA look for?

The top searched job categories for Grc Analyst Hipaa jobs in Springfield, MA are:

What cities near Springfield, MA are hiring for Grc Analyst Hipaa jobs?

Cities near Springfield, MA with the most Grc Analyst Hipaa job openings:

Manager Information Security Architecture & Compliance - Full Time

Hartford, CT • On-site

Connecticut Children's
Health Care and Social Assistance • 1 - 5K employees

Full-time

Re-posted 4 days ago


Connecticut Children's Medical Center rating

7.8

Company rating: 7.8 out of 10

Based on 46 frontline employees who took The Breakroom Quiz

168th of 1,066 rated hospitals


Job description

The Manager of IS Architecture & Compliance supports the organization's information security and compliance initiatives, ensuring adherence to internal security policies, regulatory requirements, and architectural security standards. This role partners with cross-functional teams to assess risks, implement controls, and strengthen processes across Information Technology and business functions. This role also partners with technical teams to design, document and ensure implementation compliance for new and updated Information Technology architectures.  The role also develops security awareness programs, participates in disaster recovery and business continuity exercises, and assists with investigations of security incidents.

Connecticut Children's is the only health system in Connecticut that is 100% dedicated to children. Established on a legacy that spans more than 100 years, Connecticut Children's offers personalized medical care in more than 30 pediatric specialties across Connecticut and in two other states. Our transformational growth establishes us as a destination for specialized medicine and enables us to reach more children in locations that are closer to home. Our breakthrough research, superior education and training, innovative community partnerships, and commitment to diversity, equity and inclusion provide a welcoming and inspiring environment for our patients, families and team members.

At Connecticut Children's, treating children isn't just our job - it's our passion. As a leading children's health system experiencing steady growth, we're excited to expand our team with exceptional team members who share our vision of transforming children's health and well-being as one team. 

Education and/or Experience Required:

  • Education: High School Diploma, GED or equivalent.
  • Experience:  
    • 3-5 years of Information security or compliance related activities.
    • 2 years' supervisory or management experience.

Education and/or Experience Preferred:

  • Education:  Bachelor's degree in Computer Science, Information Security, or a related field.
  • Experience:  
    • Experience with Epic system.
    • Experience in a healthcare organization.

License and/or Certification Required:

  • CISSP, CISA, CRISC, CISM, CGRC, or equivalent.

Knowledge, Skills and Abilities:

Knowledge:

  • Information security principles, risk management, and mitigation strategies.
  • Regulatory and industry compliance standards (HIPAA, HITECH, SOX, PCI/DSS).
  • Governance, risk, and compliance (GRC) frameworks and internal control design.
  • Leadership and mentoring skills, with the ability to guide and develop junior staff.
  • Information security policies, procedures, and best practices.

Skills:

  • Strong verbal and written communication.
  • Analytical thinking and problem-solving.
  • Ability to prioritize and manage multiple tasks simultaneously.
  • Process improvement, project management, and audit facilitation.
  • Customer-focused and collaborative mindset.

Abilities:

  • Work independently and meet deadlines.
  • Partner with cross-functional teams to drive compliance initiatives.
  • Provide oversight, coaching, and feedback to team members in a supportive and constructive manner.
     

Security Architecture, Risk Management, and Compliance-50%

  • Partner with internal and external technical teams to design, document, and implement security architecture standards and configurations.
  • Ensure alignment and adherence to established security architecture and control frameworks.
  • Conduct security and compliance risk assessments across healthcare applications, systems, and business processes to identify gaps.
  • Recommend and implement mitigation strategies to address identified risks and vulnerabilities.
  • Monitor and evaluate the effectiveness of security controls to ensure ongoing compliance with regulatory and organizational requirements.
  • Collaborate with IS, clinical, and business teams to strengthen security controls, risk management practices, and compliance processes.
  • Identify and drive opportunities for process improvement, standardization, and automation across security and compliance functions.

Policy, Standards, and Governance-15%

  • Develop, review, and maintain information security and compliance policies, standards, and procedures aligned with healthcare operations.
  • Ensure alignment with applicable regulatory and industry standards (e.g., HIPAA, HITECH, SOX, PCI/DSS).
  • Provide guidance to leadership and stakeholders on security governance and compliance expectations.

Security Awareness, Incident Response, and Business Continuity-15%

  • Develop and deliver security awareness and training programs tailored to healthcare staff, including data privacy and cybersecurity best practices.
  • Provide guidance on the secure handling of sensitive and protected health information.
  • Assist in the investigation of security incidents, including documentation, root cause analysis, and corrective action recommendations.
  • Participate in cybersecurity preparedness activities, disaster recovery planning, and business continuity exercises.

Leadership and Team Development-10%

  • Provide day-to-day guidance and support to a small number of direct reports, including prioritization of work, coaching, and performance feedback.
  • Mentor junior team members and contribute to their professional development in information security and compliance practices.
  • Promote knowledge sharing and consistency in security and compliance approaches across the team.
  • Support the Director of Information Security in fostering a collaborative, accountable, and high-performing team environment.

Audit and Regulatory Support-10%

  • Serve as a liaison for internal and external audits, ensuring timely and accurate collection of required documentation.
  • Support audit activities, including control validation, evidence gathering, and remediation tracking.
  • Ensure organizational adherence to regulatory requirements and support responses to compliance inquiries and assessments.

Performs Other Duties as Assigned.
 


What Connecticut Children's Medical Center employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom