HIPAA Compliance Engineer Job Description Template

The HIPAA compliance engineer builds and verifies the technical safeguards that protect health information within a product. The role sits between security engineering and compliance, translating the security rule into concrete controls such as access management, encryption, audit logging and transmission security, and then evidencing that those controls actually operate.

Typical Duties and Responsibilities

  • Implement technical safeguards required by the HIPAA security rule
  • Design access control and authentication for systems handling health data
  • Implement encryption for data at rest and in transit
  • Build audit logging that records access to protected health information
  • Conduct security risk assessments and document the findings
  • Support business associate agreement requirements technically
  • Review architecture changes for compliance impact
  • Support breach assessment and notification processes
  • Maintain evidence of control operation for audits
  • Train engineering teams on handling health information correctly

Education

  • Bachelor’s degree in computer science, information security or a related field

Required Skills and Experience

  • 3+ years in security engineering with healthcare data experience
  • Detailed understanding of the HIPAA privacy and security rules
  • Experience implementing encryption, access control and audit logging
  • Ability to conduct and document a security risk assessment
  • Understanding of what constitutes protected health information
  • Experience supporting compliance audits with technical evidence
  • Clear documentation of controls and their operation
  • Ability to advise engineers practically rather than only citing rules

Preferred Qualifications

  • CISSP, HCISPP or a comparable certification
  • Experience with HITRUST or SOC 2 assessments
Contact us

Recruit with Nexus IT Group