The Office of Compliance is seeking a Healthcare Privacy Partner who is responsible for assisting with the implementation of privacy policies and the sustenance of the privacy program designed to protect patient health information (PHI) and ensure compliance with federal and state privacy and security regulations and Emory Healthcare policies. This role collaborates with key stakeholders across legal, IT security, compliance, and clinical teams to mitigate risks, develop training programs, investigate potential breaches, and implement best practices for safeguarding PHI. This individual will:
- Serve as a resource for all privacy-related matters, ensuring adherence to HIPAA, HITECH, and other regulatory requirements governing the confidentiality, integrity, and availability of patient information.
- Primary Duties and Responsibilities Incident Management & Breach Response
- Lead investigations into potential privacy violations, coordinating with IT security, Compliance, Risk, and Legal teams Assist with the incident response plan for privacy/security breaches to ensure swift containment, remediation, and compliance with breach notification laws
- Manage internal and external reporting obligations for privacy/security incidents, ensuring regulatory authorities (e.g., HHS OCR) are notified as required by law Maintain accurate documentation of all incidents, responses, and corrective actions Employee Training & Awareness Programs.
- Develop and deliver comprehensive privacy training programs for employees, contractors, and vendors Ensure workforce members understand their responsibilities regarding PHI, access controls, and data handling protocols Foster a culture of privacy awareness through ongoing education campaigns, e-learning modules, workshops, and compliance walkthroughs at all Emory Healthcare locations Auditing and Monitoring.
- Collaborate with the IT security team to ensure appropriate access control and monitoring of employee access Conduct audits of patient chart access by employees upon request to ensure compliance Reporting & Documentation.
- Maintain comprehensive records of privacy policies, investigations, risk assessments, and regulatory correspondence Collaborate with the team to provide periodic privacy compliance reports to leadership Assist in preparing reports and documentation for regulatory submissions, audits, or accreditation bodies Policy Review and SOP Initiation and Review.
- Assist with reviewing policies and determine their applicability to system issues for problem-solving Initiate and maintain internal Standard Operating Procedures (SOPs) to ensure internal processes are clearly defined and followed
MINIMUM QUALIFICATIONS:
- Bachelors degree in Healthcare Administration, Law, Business Administration, or a related field Experience.
- Minimum of 5 years of experience in healthcare compliance Technical Expertise.
- Strong knowledge of HIPAA, HITECH, and other healthcare privacy regulations Experience with privacy risk assessments, audits, and compliance monitoring Prior experience handling privacy incidents, breach investigations, and regulatory reporting.
PREFERRED QUALIFICATION:
- Master's Degree in Healthcare Administration, Law, Business Administration, or a related field Certifications (Highly Recommended)
- Certified in Healthcare Privacy Compliance (CHPC) Certified in Healthcare Compliance (CHC) Key Competencies & Skills Regulatory Knowledge.
- Strong understanding of U.S. healthcare privacy laws and regulations Analytical & Problem-Solving.
- Ability to assess risks, investigate incidents, and implement effective solutions Communication & Training.
- Ability to educate staff at all levels on privacy best practices through effective training programs Project Management.
- Capability to develop and oversee privacy programs, policies, and compliance strategies Collaboration & Leadership.
- Experience working cross-functionally with IT, legal, compliance, and clinical teams to ensure alignment and operational effectiveness
JOIN OUR TEAM TODAY! Emory Healthcare (EHC), part of Emory University (EUV), is the most comprehensive academic health system in Georgia and the first and only in Georgia with a Magnet® designated ambulatory practice. We are made up of 11 hospitals-4 Magnet® designated, the Emory Clinic, and more than 425 provider locations. The Emory Healthcare Network, established in 2011, is the largest clinically integrated network in Georgia, with more than 3,450 physicians concentrating in 70 different subspecialties.