We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Enterprise Privacy, Principal

VNS Health
paid time off, tuition reimbursement
United States, New York, New York
220 East 42nd Street (Show on map)
Jul 12, 2025
Overview

Leads VNS Health's enterprise-wide Privacy Program through the development, implementation, and enforcement of VNS Health's privacy and confidentiality policies, ensuring compliance with HIPAA, 42 CFR Part 2, and other applicable federal and state regulations. Maintains VNS's culture of privacy awareness and accountability across the organization and is responsible for managing privacy incidents and breach reporting.
Directs HIPAA and Part 2 privacy initiatives, particularly the organization's response to and implementation of action plans for new and updated regulatory requirements. Develops and delivers communications, trainings and education, and related projects based on regulatory updates and identified regulatory gaps. Works under general supervision.

What We Provide

  • Referral bonus opportunities
  • Generous paid time off (PTO), starting at 30 days of paid time off and 9 company holidays
  • Health insurance plan for you and your loved ones, Medical, Dental, Vision, Life Disability
  • Employer-matched retirement saving funds
  • Personal and financial wellness programs
  • Pre-tax flexible spending accounts (FSAs) for healthcare and dependent care
  • Generous tuition reimbursement for qualifying degrees
  • Opportunities for professional growth and career advancement
  • Internal mobility, generous tuition reimbursement, CEU credits, and advancement opportunities

What You Will Do

  • Drafts, implements, and maintains HIPAA and privacy policies, including those governing the use and disclosure of PHI, minimum necessary standards, and patient rights. Maintains a regulatory reference library that is searchable and user-friendly.
  • Monitors federal and state regulations pertaining to privacy, security, data governance, generative AI, and other related regulations; update policies and procedures accordingly. Acts as the interface among the Legal and Compliance teams, IT Security, and the business areas regarding the impact of regulatory changes and clarification of regulatory guidance.
  • Serves as the subject matter expert on 42 CFR Part 2, ensuring compliant handling of substance use disorder (SUD) treatment records.
  • Provides privacy training and guidance to workforce members, including on oral and written communications, fax transmissions, and electronic disclosures.
  • Oversees administrative, technical, and physical safeguards to protect PHI, in alignment with VNS Health's policies & procedures. Monitor compliance and efficacy of these safeguards.
  • Collaborates closely with the VNS Health IT Security team to ensure alignment between privacy and cybersecurity protocols, including incident response, risk assessments, and technical safeguards.
  • Investigates all privacy incidents and potential breaches of PHI, including root cause analysis, documentation, and mitigation planning. Acts as internal and external lead for privacy-related projects; regularly interact and communicate with staff, patients, members, and other partners.
  • Leads breach notification processes, including timely reporting to federal, state, and local government authorities as required by law. Manage the submission of all additional, applicable privacy regulatory filings.
  • Maintains breach logs and ensure that all required documentation is complete and audit-ready.
  • Manages the process for the issuance, development, remediation, and validation of internal and external corrective action plans (CAPs) for the privacy program. Coordinate updates to and reporting of CAPs with the Compliance department.
  • Prepares privacy program reports to management, Board of Directors, and Compliance & Information Security Risk Management Committee; delivers regular updates to leadership regarding efficacy of program and related resource needs.
  • Participates in special projects and performs other duties as assigned.

Qualifications

Licenses and Certifications:

  • Certification in healthcare privacy and compliance (e.g., CHPC, CHC, CIPP/US) or related data governance, information management offerings preferred

Education:

  • Bachelor's Degree in health information management, public health, or related field required
  • Master's Degree in law, health information management, public health preferred

Work Experience:

  • Minimum of six years healthcare privacy compliance, with demonstrated expertise in HIPAA and 42 CFR Part 2. healthcare privacy compliance, with demonstrated expertise in HIPAA and 42 CFR Part 2 required
  • Strong understanding of health information management practices and electronic health record systems required
  • Proven experience in breach investigation and regulatory reporting required
  • Excellent organization, time management and project management skills required
  • Fluent in Word, Excel, and Power Point required

Pay Range

USD $98,200.00 - USD $130,800.00 /Yr.
About Us

VNS Health is one of the nation's largest nonprofit home and community-based health care organizations. Innovating in health care for more than 130 years, our commitment to health and well-being is what drives us - we help people live, age and heal where they feel most comfortable, in their own homes, connected to their family and community. On any given day, more than 10,000 VNS Health team members deliver compassionate care, unparalleled expertise and 24/7 solutions and resources to the more than 43,000 "neighbors" who look to us for care. Powered and informed by data analytics that are unmatched in the home and community-health industry, VNS Health offers a full range of health care services, solutions and health plans designed to simplify the health care experience and meet the diverse and complex needs of the communities and people we serve in New York and beyond.
Applied = 0

(web-8588dfb-dbztl)