HIPAA Privacy Officer
Listed on 2026-08-30
-
Healthcare
HIPAA Privacy Officer
Agency 340 OKLAHOMA STATE DEPARTMENT OF HEALTH
Supervisory Organization 340 Office of General Counsel
Job Posting End Date Refer to the date listed at the top of this posting, if available. Continuous if date is blank.
Full/Part-Time Full time
Job Type Regular
Compensation The annual salary for this position is up to $99,000.00, based on education and experience
Why you’ll love it here!RESPECT. COLLABORATION. SERVICE. The Oklahoma State Department of Health (OSDH) is committed to leading Oklahoma to prosperity through health. Our mission is to protect and promote health, prevent disease and injury, and cultivate conditions by which Oklahomans can thrive. Check out why we are passionate about public health and believe it is the career for you!!!
Oh yeah, did we mention perks?We know that benefits matter and that is why we offer a competitive benefits package for all eligible employees.
- Generous state paid benefit allowance to help cover insurance premiums.
- A wide choice of insurance plans with no pre-existing condition exclusions or limitations.
- Flexible spending accounts for health care expenses and/or dependent care.
- Retirement Savings Plan with a generous match.
- 15 days of vacation and 15 days of sick leave the first year for full time employees.
- 11 paid holidays a year.
- Student Loan repayment options & tuition reimbursement.
- Employee discounts with a variety of companies and venders.
- Longevity Bonus for years of service
Location :
Oklahoma City - 123 Robert S Kerr Avenue
Salary : up to $99,000.00, based on education and experience
Full Time /Part Time :
Full Time
Work Schedule :
Monday - Friday
Primary Hours : 8 a.m.
- 5 p.m.
Description:
The HIPAA Privacy Officer will be within the Office of the General Counsel, responsible for leading and overseeing the agency's privacy program, ensuring compliance with Health Insurance Portability and Accountability Act (HIPAA), 42 CFR Part 2 and other applicable state and federal regulations. This position provides strategic guidance to OSDH leadership and oversees the continuous improvement of privacy controls, processes, and services to support organizational and regulatory requirements.
This role manages privacy risk, breach response, and regulatory reporting while promoting a culture of confidentiality, security and compliance.
- Oversees the establishment, implementation, maintenance of, and adherence to privacy policies and procedures; continually ensures that policies and procedures are in current compliance with Federal and State laws and regulations.
- Coordinates with OSDH leadership regarding the review of practices that may impact compliance with the Privacy Rule of HIPAA.
- Performs periodic risk analysis, internal audits and assessments of policies and procedures, staff activities, training programs; determines remediation priorities and resources necessary to address existing or potential privacy issues and problems.
- Establishes and administers a process for receiving, documenting, tracking, investigating, and coordinating responses for all complaints and issues pertaining to privacy compliance.
- Coordinates responses to compliance assessments or investigating initiated by HHS' Office of Civil Rights or State Attorney General and monitor regulatory updates to ensure the agency remains aligned with federal privacy and any state regulations that overlay HIPAA.
- Drafts and approves Business Associate Agreements, Data Use Agreements, and Data Sharing Agreements.
- Consult with legal counsel, as necessary, regarding privacy standard and other applicable federal and state law.
- Ensure mandatory and ongoing education and training programs for all members OSDH, including when material changes are made to the privacy policies and procedures.
- Organizes and maintains all privacy policies and procedures.
- Reviews contracts, data or sharing agreements, and policies to ensure legal and regulatory compliance.
- Advises on risk mitigation for privacy and cybersecurity issues, ensuring legal obligations are met while protecting sensitive data.
- Role may include participation in governance committees.
- Being present at the office is an essential function of the job.
- Other duties as assigned.
- Knowledge and understanding of data protection laws, such as HIPAA and related Federal and State privacy laws and regulations.
- Experience with policy development and conducting privacy risk assessments.
- Strong understanding of information security principles and best practices.
- Strong analytical, investigative, communication and leadership skills.
Demonstrates knowledge of and supports mission, vision, value stat
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).