Privacy Specialist - Hybrid
Listed on 2026-09-12
-
Pharmaceutical
Regulatory Compliance Specialist, Healthcare Compliance
This is a hybrid opportunity - must be local Richmond, VA to come onsite as needed The Privacy Specialist supports the organization’s privacy operations by performing privacy investigations and operational activities to help ensure compliance with applicable privacy laws and regulations governing patient health information. The role works across two core areas: conducting investigations, supporting risk assessments, and maintaining accurate, defensible documentation.
The Privacy Specialist also coordinates workflows, supports reporting and regulatory readiness, and contributes to policy and process updates. In this role, the individual works with internal stakeholders across Legal, Compliance, Information Security, HIM, and operational teams to support consistent and compliant privacy practices. Each Privacy Specialist is assigned a primary functional alignment (Investigations or Operations) based on organizational needs and may support cross-functional activities as required.
Job Statements Privacy Investigations
- Conduct privacy incident investigations from intake through resolution, including fact gathering, interviews, and documentation
- Perform access reviews and analyze audit logs to evaluate potential inappropriate access or disclosure
- Apply HIPAA breach risk assessment standards to determine whether an impermissible use or disclosure occurred
- Develop findings, conclusions, and recommendations, and prepare clear, defensible documentation
- Coordinate with Legal, Compliance, Information Security, HIM, and operational teams during investigations
- Ensure timely case progression and closure in alignment with established timelines and documentation standards
- Coordinate and execute privacy operations activities, including tracking initiatives, maintaining workflows, and coordinating cross-functional activities
- Support development, review, and maintenance of privacy policies, procedures, and standards
- Prepare and maintain reports, dashboards, and metrics to support leadership visibility and risk monitoring
- Contributes to regulatory readiness activities, including audits, assessments, and documentation reviews
- Participate in enterprise initiatives (e.g., research privacy, vendor data use, interoperability, AI governance), supporting coordination and follow-up actions
- Identify and elevate operational gaps, risks, and opportunities for process improvement
- Conduct privacy and compliance risk assessments in collaboration with business owners
- Analyze trends from investigations, audits, and reports to identify risk areas and recommend mitigation strategies
- Contribute to policy updates and operational changes based on regulatory requirements and identified gaps
- Maintain accurate and complete documentation to support audit and regulatory review
- Partner with stakeholders across Legal, Compliance, ISRM, HIM, IT/Epic, and operational teams
- Support training, education, and awareness activities based on identified risks and trends
- Serve as a resource for privacy-related inquiries within assigned functional areas
- Identify opportunities to improve investigation workflows, reporting processes, and documentation standards
- Contribute to development of standardized templates, tools, and tracking mechanisms to improve consistency and efficiency
- Contribute to strengthening privacy operations and investigation practices across the organization
Patient Population: N/A
Employment QualificationsRequired
Education:
Bachelor’s degree in healthcare administration, compliance, public health, health information management, business administration, or a related field.
Preferred Education:
Master’s degree in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).