Salary : $112,091.20 - $160,056.00 Annually
Location : San Bernardino, CA
Job Type: Full-time
Job Number: 26-1078DAAS-01
Department: Human Services-DAAS/Public Guardian
Opening Date: 08/08/2026
Closing Date: 8/21/2026 5:00 PM Pacific
FLSA: Exempt
The Job
The Department of Aging and Adult Services-Public Guardian (DAAS-PG) is recruiting for a
HIPAA Privacy Officer to develop, implement, and maintain HIPAA privacy policies, oversee compliance with federal and state regulations, and provide technical leadership to safeguard protected health information (PHI). The Department of Aging and Adult Services-Public Guardian serves some of the county's most vulnerable adults, whose safety, dignity, and independence depend on strong privacy, security, and program integrity across all departmental operations. The HIPAA Privacy Officer will coordinate compliance monitoring activities, lead risk assessments, audits, and program reviews, and collaborate with department leadership and cross-functional stakeholders to integrate privacy and security requirements into all HIPAA-covered operations. As a member of the department's leadership team, the incumbent will ensure departmental privacy, security, and risk management programs comply with applicable HIPAA standards and organizational policies.
Duties include, but are not limited to, the following:
- Support department-wide ADA compliance by reviewing programs, services, and administrative processes to ensure accessibility for clients, families, and staff; collaborate with departmental leadership to integrate reasonable accommodations, accessible communication practices, and ADA-aligned procedures into broader departmental operations.
- Ensure department HIPAA privacy and security practices align with ADA requirements by reviewing policies, procedures, and program operations for accessibility; collaborate with program, facilities, IT, and HR staff to identify and mitigate barriers, integrate reasonable accommodations into privacy-related workflows, and support ADA-compliant communication of PHI and privacy notices.
- Develop, implement, and maintain DAAS-PG HIPAA privacy and security policies, standards, and procedures to ensure compliance with applicable federal and state laws and regulations.
- Provide technical leadership, guidance, training, and consultation to management and staff on HIPAA privacy, security, and the protection of protected health information (PHI).
- Plan, organize, and coordinate HIPAA compliance activities, including risk assessments, audits, internal reviews, corrective actions, and program evaluations to support regulatory compliance and continuous quality improvement.
- Review departmental security plans and coordinate activities related to access controls, incident response, disaster recovery, business continuity, and risk management to ensure HIPAA privacy and security requirements are integrated into departmental operations.
- Develop educational resources and lead HIPAA privacy, security, and information security awareness initiatives to promote compliance throughout DAAS-PG.
- Analyze compliance reports, audit findings, and operational data; prepare reports, presentations, and briefings for executive leadership, stakeholders, and elected officials regarding compliance, risk management, and program performance.
- Collaborate with departmental leadership and cross-functional partners to integrate HIPAA privacy and security requirements into strategic initiatives, program integrity, quality improvement, enterprise risk management, and organizational operations; may provide technical direction and work coordination to staff supporting HIPAA compliance activities
- Maintains extensive knowledge of health care relevant legislation and standards for the protection of health information and patient privacy; maintains expert knowledge of HIPAA security requirements and other information security laws, including NIST, PCI and all other applicable regulations.
For more detailed information, refer to the job description.
EXCELLENT BENEFITS
To review job-specific benefits, refer to:
Summary of Benefits and the
Exempt Compensation Ordinance.
CONDITIONS OF EMPLOYMENT
Pre-Employment Process: Prior to appointment, applicants must pass a background investigation which includes verification of employment history and education, fingerprinting, physical exam, and drug screening.
Travel/Driver License: Travel throughout the County may be required. Incumbent may be required to use personal vehicle for such travel; mileage reimbursement is available. At time of hire, a valid California Class C driver license and proof of automobile liability insurance must be produced and maintained for the individual providing the transportation. Overnight and/or out-of-state travel may be required.
Visa Sponsorship: Please note San Bernardino County is not able to consider candidates who will require visa sponsorship at the time of application or in the future.
Minimum Requirements
Candidates must meet both the education and one of the experience options below:
Education:A bachelor's degree from an accredited college or university in Healthcare Administration, Health Information Management, Public Administration, Public Health, Business Administration, Information Systems, Information Security, Law, or a closely related field.
-AND-
Option 1 - HIPAA Privacy Program Experience
Two (2) years of full-time equivalent, where the primary responsibility was developing, implementing, and administering HIPAA privacy and compliance programs within a healthcare organization, public health program, human services agency, government agency, health plan, business associate, or other HIPAA-covered entity, including responsibility for policy development, compliance monitoring, risk assessments, internal audits, incident response, workforce training, and regulatory compliance.
-OR-
Option 2 - Public Agency Compliance Experience
Three (3) years of full-time equivalent professional-level experience within a public agency where the primary duties were planning, coordinating, and evaluating regulatory compliance, privacy, information security, enterprise risk management, or similar compliance programs involving confidential, sensitive, or regulated information, including policy implementation, compliance monitoring, risk assessments, operational oversight, and ensuring compliance with applicable federal and state laws and regulations.
Desired Qualifications
The ideal candidate will possess:
- A master's degree in a related field.
- Experience serving as a designated HIPAA Privacy Officer or leading a HIPAA privacy compliance program.
- Experience advising executive leadership on complex privacy, compliance, and risk management matters.
- Candidates with professional certifications in health care privacy, information security, and compliance are strongly preferred. Other credentials demonstrating advanced knowledge of privacy, security, and regulatory requirements, and additional certifications supporting accessibility and compliance may further strengthen a candidate's qualifications.
Selection Process
There will be a
competitive evaluation of qualifications based on a review of the Application and Supplemental Questionnaire. It is to your advantage to be explicit in your responses on the Application and Supplemental Questionnaire.
Application Procedure: To be considered for this excellent opportunity, please complete and submit the online employment application and supplemental questionnaire by
5:00 pm, Friday, August 21st, 2026. Resumes will not be accepted in lieu of the application and/or supplemental questionnaires.
To ensure timely and successful submission of your online application, please allow ample time to complete and submit your application before the posted filing deadline. Applicants will be automatically logged out if they have not submitted the application and all required materials prior to the posted deadline. Once your application has been successfully submitted you will receive an onscreen confirmation and an email. We recommend that you save and/or print these for your records. Please note, if you do not receive an onscreen confirmation and an email acknowledging our receipt of your application, we have not received your application.
If you require
technical assistance, please to review the Government Jobs , or contact their Toll-Free Applicant Support line at (855) 524-5627. Please note that Human Resources is not responsible for any issues or delays caused by the internet connection, computer or browser used to submit the application.
EEO/ADA: San Bernardino County is an and Americans with Disabilities Act (ADA) compliant employer, committed to providing equal employment opportunity to all employees and applicants.
ADA Accommodation: If you have a disability and require accommodations in the testing process, submit the within one week of a recruitment filing deadline.
Veterans' Preference: Eligible veterans and their spouse or widow(er) who are not current County employees may be awarded additional Veterans' Preference points. For details and instructions on how to request these points, please refer to the
For more important details,
review the Applicant Information and County Employment Process
Exempt Unit-Group C
San Bernardino County offers a range of benefit programs for employees and their eligible dependents. These include health, dental, vision, and life insurance, as well as a variety of other voluntary benefits. Programs and benefit amounts vary and are based on bargaining unit, family size, hire date, plan selection, and number of hours worked.
Please review the appropriate * for more information
Refer to the appropriate MOU, contact the County's Employee Benefits and Services Division at (909) 387-5787 or visit the for more detailed information.
*Retirement benefits subject to change.
01
Instructions:The information from the Application and the Supplemental Questions below will be reviewed to determine your qualifications and will provide the basis for a competitive evaluation with other candidates in the selection process. It is to your advantage to provide complete, organized, and detailed responses to each question.
Note: Employers listed on this questionnaire must also be listed and fully detailed in the Work Experience section of your application.
- I have read and understand the above statement.
02
Education: What is the highest level of education you have completed?
- High School Diploma/GED
- Associate's Degree
- Bachelor's Degree
- Master's Degree
- Doctorate
03
Education: If you possess a bachelor's degree or higher, what was your major field of study? Select the option that best describes your degree.
- Healthcare Administration
- Health Information Management
- Public Administration
- Public Health
- Business Administration
- Occupational Health and Safety
- Law
- Environmental Health
- Other (please specify below)
- None
04
Education: If you selected "Other" above, please identify your major field of study and briefly describe how it is closely related to Healthcare Administration, Health Information Management, Public Administration, Public Health, Business Administration, Information Systems, Information Security, or Law. If this question does not apply to you, type "N/A."
05
Certifications: Select all certifications you currently possess.
- Certified in Healthcare Privacy Compliance (CHPC)
- Certified Information Privacy Professional (CIPP)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Internal Auditor (CIA)
- Certified Compliance & Ethics Professional (CCEP)
- ADA Coordinator Training or Certification
- Other applicable certification
- None
06
Certifications: If you selected "Other" above, please identify your certificate below. If this question does not apply to you, type "N/A."
07
Qualifying Experience: Indicate the option by which you qualify for this position. Your education and/or experience
must be included in the designated area of the County application.
- Option 1: Two (2) years of HIPAA Privacy Program Experience
- Option 2: Three (3) years of Public Agency Compliance Experience
- I do not qualify under either option as stated above.
08
Compliance Experience: Describe your experience developing tools to ensure compliance with regulatory agency requirements, monitoring program compliance, and developing program corrective action plans. If none, type "N/A".Be sure to include employer name, dates employed and program(s) you worked with.
09
Risk Assessment Experience: Describe your experience identifying, evaluating, and mitigating organizational risks. Include the assessment methods you used, your role in developing recommendations, and how risks were monitored or addressed. If none, type "N/A".Be sure to include employer name, dates employed and program(s) you worked with.
10
ADA Accessibility Experience: Describe your experience ensuring compliance with the Americans with Disabilities Act (ADA) and accessibility requirements within programs, policies, communications, services, or facilities. Include your specific responsibilities and any actions you took to promote or maintain accessibility. If none, type "N/A".Be sure to include employer name, dates employed and program(s) you w