HIPAA Compliance Officer Job Description Template

The HIPAA compliance officer owns an organization’s compliance with health information privacy and security requirements. The role covers policy, training, risk assessment, breach response and the ongoing monitoring that demonstrates the program actually operates. It requires the standing to raise problems with senior staff and the practicality to keep clinical work moving.

Typical Duties and Responsibilities

  • Own the privacy and security compliance program
  • Maintain policies and procedures and keep them current
  • Conduct and document periodic security risk assessments
  • Deliver workforce training and track completion
  • Investigate potential breaches and manage notification obligations
  • Monitor access to records and investigate inappropriate access
  • Manage business associate agreements and vendor risk
  • Respond to patient privacy complaints and access requests
  • Prepare for audits and regulatory inquiries
  • Report compliance status to leadership and the board

Education

  • Bachelor’s degree in healthcare administration, law, information security or a related field

Required Skills and Experience

  • 5+ years in healthcare compliance or privacy
  • Detailed knowledge of the HIPAA privacy, security and breach notification rules
  • Experience conducting security risk assessments
  • Experience managing a breach investigation and notification
  • Ability to work with both clinical and technical teams
  • Strong documentation and evidence practice
  • Willingness to escalate difficult findings
  • Training and communication skills across a large workforce

Preferred Qualifications

  • Certified in healthcare privacy or compliance
  • Experience with state privacy laws in addition to federal
Contact us

Recruit with Nexus IT Group