1

Healthcare Information Security Privacy Jobs (NOW HIRING)

Knowledge of clinical workflows and healthcare operations. * Knowledge of information security principles and data privacy regulations, including Health Insurance Portability and Accountability Act ...

New

Knowledge of clinical workflows and healthcare operations. * Knowledge of information security principles and data privacy regulations, including Health Insurance Portability and Accountability Act ...

New

... CISSP) HealthCare Information Security and Privacy Practitioner (HCISPP) or Certified Controls Self Assessment (CCSA) preferred. Sanford is an EEO/AA Employer M/F/Disability/Vet. If you are an ...

next page

Showing results 1-20

Healthcare Information Security Privacy information

See salary details

$29.5K

$94.9K

$170.5K

How much do healthcare information security privacy jobs pay per year?

As of Aug 14, 2026, the average yearly pay for healthcare information security privacy in the United States is $94,926.00, according to ZipRecruiter salary data. Most workers in this role earn between $49,500.00 and $127,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in healthcare information security privacy roles?

Professionals in Healthcare Information Security Privacy often face the challenge of balancing robust data protection with the need for timely access to patient information. Navigating complex regulatory requirements like HIPAA, coordinating with clinical and IT teams, and responding to evolving cybersecurity threats are frequent parts of the job. Additionally, educating staff on privacy best practices and managing incidents such as data breaches require strong communication and problem-solving skills. These challenges make the role dynamic and critical to maintaining trust in healthcare organizations.

What are the key skills and qualifications needed to thrive as a healthcare information security privacy professional, and why are they important?

To thrive as a Healthcare Information Security Privacy professional, you need expertise in healthcare regulations (such as HIPAA), risk assessment, and data protection, often supported by a degree in information security or healthcare IT and relevant certifications like CISSP or HCISPP. Familiarity with security tools, incident response systems, and healthcare IT infrastructure is typically required. Attention to detail, problem-solving abilities, and strong communication skills help ensure effective policy implementation and stakeholder collaboration. These skills and qualities are crucial to safeguard patient information, maintain regulatory compliance, and protect organizations from data breaches.

What is healthcare information security and privacy?

Healthcare information security and privacy involves protecting sensitive patient data from unauthorized access, breaches, and misuse. Professionals in this field implement policies, technologies, and best practices to ensure that health information remains confidential, accurate, and accessible only to authorized personnel. Their work is crucial for maintaining patient trust, complying with regulations such as HIPAA, and safeguarding organizations against cyber threats. These experts also educate staff on privacy policies and respond to potential security incidents.

What is the difference between Healthcare Information Security Privacy vs Healthcare Data Analyst?

AspectHealthcare Information Security PrivacyHealthcare Data Analyst
CertificationsHIPAA, CISSP, CISACertified Health Data Analyst (CHDA), HIPAA familiarity
Work EnvironmentHospitals, clinics, healthcare organizationsHealthcare providers, research institutions, insurance companies
Primary FocusProtecting patient data, ensuring privacy complianceAnalyzing healthcare data for insights, improving patient care

Healthcare Information Security Privacy professionals focus on safeguarding patient data and ensuring compliance with privacy laws, while Healthcare Data Analysts interpret healthcare data to support decision-making. Both roles require knowledge of HIPAA, but their daily tasks and objectives differ significantly.

More about Healthcare Information Security Privacy jobs

What job categories do people searching Healthcare Information Security Privacy jobs look for?

The top searched job categories for Healthcare Information Security Privacy jobs are:

Infographic showing various Healthcare Information Security Privacy job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 22% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $94,926 per year, or $45.6 per hour.

Healthcare Information Security Manager (NY HELPS) - FT - Day Shift

ECMC

Buffalo, NY

$52.51 - $72.97/hr

Full-time

Re-posted 23 days ago


Job description

HOURLY RANGE: $52.51 - $72.97

NY HELPS

This title is part of the New York Hiring for Emergency Limited Placement Statewide Program (NY HELPS).
For the duration of the NY HELPS Program, this title may be filled via a non-competitive appointment, which means NO EXAMINATION IS REQUIRED, but all candidates must meet the minimum qualifications of the title for which they apply.
At a future date (within one year of permanent appointment), it is expected employees hired under NY HELPS will have their non-competitive employment status converted to competitive status, WITHOUT HAVING TO TAKE A CIVIL SERVICE TEST.
Employees will then be afforded with all of the same rights and privileges of competitive class employees of New York State.
While serving permanently in a NY HELPS title, employees may take part in any promotion examination for which they are qualified.

DISTINGUISHING FEATURES OF THE CLASS: The work involves assisting the Chief Healthcare Information Security Officer (CISO) in managing the Information Security Program at the Erie County Medical Center Corporation (ECMCC). The work involves addressing the electronic systems architecture and functionality as it affects safeguards of protected health information (PHI) and business information assets, as directed by the Healthcare Information Security Director or CISO. The incumbent monitors, assesses the IT business continuity and disaster recovery program and performs network penetration tests, application vulnerability assessment scans, and risk assessment reviews. The work is performed under the general direction of the Healthcare Information Security Director or CISO. Supervision may be exercised over lower-level technical staff. Does related work as required.

TYPICAL WORK ACTIVITIES:

Manages the Information Security Program procedures, technical systems and workforce training to maintain the confidentiality, integrity, and availability of data within all information systems;

Coordinates resources (staff, equipment, vendors, and consultants) across projects, manages the budget for assigned projects), monitors project progress (risks & issues) and adjusts resources and priorities accordingly;

Drives adoption of secure hardening and configuration practices in the systems security deployment cycle throughout central technology and line of business technical engineering teams;

Performs information security awareness and training to educate workforce about information risks;

Prepares and presents progress reports for management and ensure technologies are appropriately integrated to support the objectives of Cybersecurity Program;

Provides subject-matter-expertise in the discipline of Core Platform security to Cybersecurity operation team and others;

Provides consultancy for secure system design, development, engineering, and operation;

Provides project management and operational responsibility for administrative coordination and implementation of the organization’s security program;

Assists in development of Security Program Policies and enforces policies and procedures;

Assists with enforcement of access control needs of the organization;

Identifies and helps implement continuous process enhancements/improvements to Cybersecurity Operations;

Assists in managing information security directives as mandated by Federal and State regulations, including but not limited to the Health Insurance Portability and Accountability Act (HIPAA);

Assists with disaster recovery, business continuity, incident response, and risk management programs;

As directed by the Healthcare Information Security Director of CISO, performs or works with third-party consultants to perform information risk assessments, security audits, and accreditation surveys, ensuring that information systems are adequately protected and meet HIPAA certification requirements;

Participates in accreditation surveys;

Attends and participates in meetings, seminars, and training sessions.

FULL PERFORMANCE KNOWLEDGE, SKILLS, ABILITIES AND PERSONAL CHARACTERISTICS: Thorough knowledge of state of the art computer security; good knowledge of project management and development; good knowledge of internal computer logic, programs and facilities; good knowledge of technical infrastructure security components and integrated computerized rules-based systems; familiarity with Federal and State privacy and security laws and regulations and industry best practices as they relates to healthcare information security; ability to enforce programs to ensure the security of health information across a widely dispersed workforce with a variety of information mediums; ability to read, interpret and apply technical information; ability to analyze and resolve security problems quickly; ability to supervise others; ability to establish and maintain effective working relationships with a diverse constituency; critical thinking skills; problem solving skills; technical skills; capable of performing the essential functions of the position with or without reasonable accommodation.

MINIMUM QUALIFICATIONS:

  • Possession of a Master’s Degree* in Health Information Systems, Computer Science/Computer Programming, or related computer technology or healthcare related field and one (1) year of experience in computer or information security** which included experience with federal and state privacy and security laws, regulations and accreditation standards for maintaining information security and confidentiality; or:
  • Possession of a Bachelor’s Degree* in Health Information Systems, Computer Science/Computer Programming, or related computer technology or healthcare related field and three (3) years of experience in computer or information security**, one (1) year of which included experience with federal and state privacy and security laws, regulations and accreditation standards for maintaining information security and confidentiality; or:
  • An equivalent combination of training and experience as defined by the limits of (A) and (B).

**Information Security, for the purpose of qualifying applications, is defined as the processes designed and implemented to protect information, systems, and networks against unauthorized access, use or disruption utilizing various forms of technology.

NOTE*: Your degree must have been awarded by a college or university accredited by a regional, national or specialized agency recognized as an accrediting agency by the U.S. Department of Education/U.S. Secretary of Education. If your degree was awarded by an educational institution outside the United States and its territories, you must provide independent verification of equivalency. A list of acceptable companies who provide this service can be found on the internet at http://www.cs.ny.gov/jobseeker/degrees.cfm. You must pay the required evaluation fee.

NOTE 2: Verifiable part-time and/or volunteer experience will be pro-rated toward meeting full-time experience requirements.


ECMC logo

About ECMC

Sourced by ZipRecruiter

Industry

Finance and insurance

Company size

201 - 500 Employees

Headquarters location

Saint Paul, MN, US

Year founded

1994