An application made for this job — a tailored resume and cover letter that speak straight to the posting.
University of Vermont Medical Center is seeking a System Director, Privacy Officer to lead a comprehensive patient privacy program across UVM Health. This role directs privacy staff, drives program improvement, and ensures compliance with HIPAA and related regulations.
The position partners with executive leadership, legal, information security, and operations to embed privacy into system-wide initiatives, oversee risk assessments, audits, training, and breach response, and to educate staff
Job Summary:
The System Director, Privacy Officer is responsible for the implementation of a comprehensive patient privacy program for UVM Health. The System Director, Privacy Officer oversees and supervises the Office of Compliance, Privacy and Internal Audit's privacy staff to ensure privacy and data protection compliance and provides leadership and subject matter expertise to drive the continued improvement and implementation of the system's privacy program. The System Director, Privacy Officer is responsible for providing guidance and education to physicians and non-physician practitioners, clinical department leaders, and other workforce members regarding compliance with federal and state rules, regulations, and laws on HIPAA and other privacy-related practices, maintains expertise in federal and state regulations, as well as the regulations of other authorities; and ensures that UVM Health is compliant with those standards. The System Director, Privacy Officer participates in annual risk assessments and the development and execution of an annual compliance workplan; performs audits and analyses; assists in implementation of recommendations; provides education both within the department and throughout the System on all HIPAA and other privacy-related matters.
The System Director, Privacy Officer is responsible for strategic leadership and enterprise-wide oversight of the UVM Health privacy program, ensuring effective implementation of a comprehensive privacy framework that complies with federal and state laws, regulations, and standards. This position directs a cross-functional team, including direct supervision of privacy staff across the network, and drives policy, operational, and cultural improvements related to patient privacy.
The System Director, Privacy Officer partners with executive leadership, legal counsel, information security, and operational leaders to embed privacy into system-wide initiatives, guide decision-making, and proactively manage the organization's compliance posture. They allocates resources, leads cross-functional projects, and ensures staff and leaders across the network are educated, supported, and held accountable for privacy practices. This leader participates in the annual compliance risk assessment and work plan and is responsible for the design, execution, and continuous improvement of the network's privacy monitoring, training, and breach response programs.
Education:
A four-year college degree is required; JD preferred. Certification in Healthcare Privacy Compliance (CHPC), Healthcare Information Security and Privacy Practitioner (HCISPP) or IAPP Certified Information Privacy Professional (CIPP) desired.
Experience:
Five or more years of experience with HIPAA and patient privacy.