Job Description
Location: Remote (US-based)
We are hiring for a HIPAA Privacy and Security Analyst with a healthcare compliance organization supporting hospitals, physician groups, and digital health companies in building and maintaining HIPAA-compliant privacy and security programs. This position is a full-time, direct hire opportunity.
As digital health tools, remote care infrastructure, and third-party data relationships have expanded, HIPAA compliance has shifted from a documentation exercise into an active risk management discipline. This position is ideal for a compliance professional who can think across legal, technical, and operational dimensions while serving as a credible privacy resource for clinical and business teams.
Responsibilities:
- Conduct annual and event-driven HIPAA risk assessments across covered entity and business associate operations
- Investigate potential privacy incidents and breaches from initial report through root cause review and notification determination
- Maintain breach logs, incident tracking records, and required regulatory documentation
- Develop and deliver HIPAA privacy and security workforce training programs
- Review and update Notices of Privacy Practices, policies, procedures, and business associate agreements
- Respond to patient rights requests including access, amendment, restriction, and accounting of disclosures
- Monitor changes to OCR guidance, state privacy laws, and emerging regulatory developments
- Support OCR complaint response, audit readiness, and documentation preparation activities
- Advise clinical and operational teams on privacy considerations for new workflows and technology implementations
Qualifications:
- Bachelor’s degree in Health Administration, Health Information Management, Compliance, or related field preferred
- Minimum of 3 years of HIPAA privacy and security compliance experience in a healthcare setting required
- Working knowledge of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule required
- Experience conducting risk analyses using NIST or equivalent frameworks preferred
- Familiarity with state privacy laws and breach notification requirements preferred
- CHPC, CHPS, or CIPP/H certification preferred or in progress
- Strong written communication skills for policies, training content, and incident documentation
Schedule:
- Full-time, remote position
- Monday through Friday, standard business hours
- Standard full-time schedule of 40 hours per week
Salary Range:
The salary range for this position is approximately $58,000 – $80,000 annually ($27.88 – $38.46 per hour), based on experience and qualifications.
Interview Process:
Selected candidates will participate in a multi-step interview process, including an initial screening with TalentLNX followed by interviews with department leadership.
Equal Opportunity Employer: TalentLNX is committed to equal employment opportunity and a diverse, inclusive workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.