Enable job alerts via email!

Privacy Impact Assessment (PIA) Specialist - Senior

Cleo Consulting

Ontario

Hybrid

CAD 70,000 - 110,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Senior Privacy Impact Assessment Specialist to support crucial IT projects. In this pivotal role, you will leverage your expertise in health privacy to conduct assessments, ensure compliance with privacy laws, and collaborate with diverse teams on data protection initiatives. Your contributions will safeguard personal health information and enhance project designs, ultimately protecting the trust of individuals. Join a dynamic team dedicated to improving health services while navigating complex privacy challenges in a hybrid work environment.

Qualifications

  • 3+ years' health privacy experience conducting PIAs.
  • 5+ years' operational privacy experience in health or IT sectors.
  • Experience developing privacy policies and data sharing agreements.

Responsibilities

  • Conduct Privacy Impact Assessments and documentation.
  • Provide privacy consultation on complex health privacy issues.
  • Develop risk mitigation plans and privacy controls.

Skills

Health privacy experience
Privacy impact assessments (PIAs)
Data sharing agreements
Privacy policies and procedures
Application Programming Interface (API)
Personal Health Information Protection Act (PHIPA)
Electronic Medical Record (EMR)
Hospital Information System (HIS)

Education

University degree in Health, Computer Science, Engineering, Law, or Security

Tools

MS Project
MS Teams

Job description

Assignment: RQ00309 - Privacy Impact Assessment (PIA) Specialist - Senior Requisition: RQ00309 Job Title: Privacy Impact Assessment (PIA) Specialist - Senior Client: Ontario Health Start Date: 2025-06-02 End Date: 2026-03-31 Department: Privacy Office Location: 525 University Avenue, Toronto Business Days: 252.00 Location: Remote Public Sector Experience: Preferred

Must Haves:

  • Minimum of 3 years' health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects
  • Minimum 5 years' direct operational level privacy experience preferably in a health sector and/or IT environment
  • Familiarity with Application Programming Interface (API) functionality and management
  • Minimum 5 years' experience drafting and reviewing privacy requirements for data sharing agreements
  • Minimum 5 years' experience developing privacy policies and procedures, requirements, or controls
  • Familiarity with the Personal Health Information Protection Act (PHIPA), and its related requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP)
  • Familiarity with Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure, design, and data flows

Description

About Ontario Health:

  • Ontario Health was established pursuant to The Connecting Care Act, 2019 and its objectives include the implementation of the health strategies of the Ministry of Health and the management of health service needs across Ontario consistent with those strategies. For detailed information on Ontario Health, its mandate and its objectives, please go to: https://www.ontario.ca/page/ontario-health-agency.

Background Information:

  • The purpose of this procurement of a Senior Privacy (PIA) Specialist is to acquire a contingent resource to act as a dedicated privacy subject matter expert to assist with supporting privacy matters related to a number of key Information Technology projects that include Patients Before Paperwork (PB4P) initiatives, enterprise products & services, business intelligence tools, and cloud migration.
  • Ontario Health is seeking a Privacy resource to ensure that Ontario Health maintains compliance with its legal and contractual privacy obligations, and builds privacy into the design of projects that involve personal health information (PHI), thus reducing risk for the organization and protecting the trust and privacy of individuals whose PHI we manage.

Responsibilities:

  • Conducting/Completing Privacy Impact Assessments and associated documentation
  • Providing Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiatives
  • Identify and assess privacy risks, including developing risk mitigation plans
  • Create or inform the creation of data flow diagrams and associated privacy controls and compliance requirements
  • Reviewing and advising on agreements, including data sharing agreements
  • Developing privacy requirements for new or changing projects
  • Providing privacy advisory and support to business teams
  • Other duties as required

Desired Skills:

  • Demonstrable knowledge of project management; Knowledge and understanding of Project Management's Institute's Project Management Body of Knowledge is an asset
  • Experience working on and delivering multiple projects
  • Demonstrated project management software skills and experience e.g. MS Project, MS Teams etc.
  • University undergraduate or graduate degree in Health, Computer Science, Engineering, Law, Security, or a related discipline from a recognized institution or equivalent experience desired
  • Familiarity with Prescribed Entities (PEs) or Prescribed Persons (PP) under the Personal Health Information Protection Act (PHIPA), and their related requirements, is an asset
  • Familiarity with audit logging and Security Information and Event Management (SIEM) technology is an asset
  • Familiarity with technical data protection controls and technology such as encryption and tokenization is an asset
  • Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards is an asset

Required Skills: 100 Points

  • Minimum 3 years' health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects.: 20 Points
  • Minimum 5 years' direct operational level privacy experience in a health sector and/or IT environment or both.: 20 Points
  • Minimum 5 years' experience in developing privacy policies and procedures, requirements, or controls.: 20 Points
  • Minimum 5 years' experience drafting and reviewing privacy requirements for data sharing agreements.: 15 Points
  • Familiarity with the Personal Health Information Protection Act (PHIPA), and requirements related to Health Information Network Provider (HINP) and Electronic Service Provider (ESP).: 10 Points
  • Familiarity with Application Programming Interface (API) functionality and management.: 7.5 Points
  • Familiarity with Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure, design, and data flows.: 7.5 Points

Deliverables:

  • Over the duration of the engagement, the Senior Privacy (PIA) Specialist will support work already in progress, as well as new work on Privacy Impact Assessments;
  • Work with the project and product teams on risk mitigation of PIA findings as required under PHIPA;
  • Support work related to update and/or developing new agreements;
  • Other duties as required. Note that knowledge of current privacy and data protection policy and legislation, especially Ontario's Personal Health Information Protection Act (PHIPA), will be critical to ensure success.
  • Conducting/Completing Privacy Impact Assessments and associated documentation
  • Providing Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiatives
  • Developing risk mitigation plans
  • Create or inform the creation of data flow diagrams and associated privacy controls and compliance requirements
  • Reviewing and advising on agreements, including data sharing agreements
  • Developing privacy requirements for new or changing projects

Additional Terms

  • Term: The term for this position is 252 days.
  • Ontario Health assets including laptops and related equipment cannot be removed from the province of Ontario without prior written approval from Ontario Health.
  • Assignment Type: This position is currently hybrid. The resource under this request will be required to work onsite upon Ontario Health request.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Privacy Impact Assessment (PIA) Specialist

Teckhorizon Inc

Toronto

Remote

CAD 70,000 - 110,000

Yesterday
Be an early applicant

Privacy Impact Assessment (PIA) Specialist - Senior

LanceSoft

Toronto

Remote

CAD 80,000 - 120,000

2 days ago
Be an early applicant

RQ00248 - Privacy Impact Assessment (PIA) Specialist - Senior

S M Software Solutions Inc

Toronto

Hybrid

CAD 70,000 - 110,000

10 days ago