Director, Privacy and Data Protection

7 hours ago


MD United States UMMS Community Impact Grant Program Full time

The University of Maryland Medical System is a 14-hospital system with academic, community and specialty medical services reaching every part of Maryland and beyond. UMMS is a national and regional referral center for trauma, cancer care, Neurocare, cardiac care, women’s and children’s health and physical rehabilitation. UMMS is the fourth largest private employer in the Baltimore metropolitan area and one of the top 20 employers in the state of Maryland. No organization will give you the clinical variety, the support, or the opportunities for professional growth that you’ll enjoy as a member of our team.

Job Description

The Director, Privacy and Data Protection is a key system shared services role that is responsible for leading and overseeing UMMS privacy and data protection program development, implementation, and maintenance. This includes facilitating adherence to all relevant UMMS privacy and data protection policies and procedures, as well as privacy and data protection related laws and regulations. The seasoned, innovative leader in this position ensures a transparent, measurable and compliant data management processes and related activities within UMMS. This process reflects thoughtful design to ensure that privacy and data protection is baked into world class patient care and related business operations and includes metrics. This position also directs and develops the organization’s privacy and data protection strategy and work plan and works in coordination with other compliance leaders in a shared services model to inspire others in privacy awareness and to enhance the culture of compliance around privacy and data protection.

Principal Responsibilities and Tasks

The following statements describe the general nature of work performed by the individual assigned to this classification. This is not an exhaustive list of all job duties. Principal responsibilities of the Director, Privacy and Data Protection include:

  • Building a strategic and comprehensive privacy and data protection program that defines, develops, maintains and implements policies and processes that enable consistent, effective privacy practices which minimize risk and ensure the confidentiality of protected health information (PHI), paper and/or electronic, across all media types.
  • Ensuring that the UMMS privacy and data protection program includes the privacy components of the Health Insurance Portability and Accountability Act (HIPAA), state privacy laws and regulations, protection of the organization’s proprietary data, employee data privacy as well as other relevant and emerging privacy requirements including but not limited to the General Data Protection Regulation (GDPR).
  • Ensuring that all privacy and data protection related forms, policies, standards, and procedures within the UMMS organization are up to date.
  • Working effectively and collaboratively with executive leadership, Information Security, and compliance leaders to establish and maintain effective management and governance for the privacy and data security program.
  • Collaborating effectively with Information Security and Technology to ensure alignment between information security and privacy and data protection compliance programs including policies, practices, investigations, and acting as the compliance liaison to the UMMS Information Security and Technology Department.
  • Working effectively with compliance leaders, organization administration, legal counsel, and other related parties to represent UMMS information privacy interests with external parties (state or local government bodies) that adopt or amend privacy legislation, regulations, or related expectations.
  • Working effectively with representatives of the U.S. Department of Health and Human Service's Office for Civil Rights (OCR), state regulators and/or other legal entities as well as appropriate internal partners during government initiated privacy or data security related reviews, audits or investigations.
  • Building, mentoring, and developing a world class privacy team. Managing, hiring and retaining staff and being accountable for the performance of the team.
  • Collaboratively developing and implementing strategic vision and plans for the privacy and data protection program in accordance with best practices; setting long-range direction and making high-level decisions in coordination with leadership; proposing and managing the implementation of complex and significant programmatic change as determined necessary.
  • Perform other duties as assigned.
Qualifications

Education and Experience:

  • Bachelor’s degree in business or health care administration or similar field required. An advanced degree in law (JD), privacy, or a related field preferred.
  • One or more of the following existing and current certifications or obtaining an approved privacy or data security related certification within the first year of employment is required: CIPP, CIPM, HCISPP, PECB-CDPO, CDP or CHPC.
  • Five or more years of privacy, data security or IT security program leadership or related experience required.
  • Demonstrated successful and collaborative experience in a large academic medical center, integrated care delivery system or similarly complex organization preferred.
  • Success operationalizing a transparent, measurable privacy and or data protection program preferred.
  • A strong track record of timely, active and appropriate responses to privacy violation allegations, inquiries, incidents and investigations, including working effectively with legal counsel and stakeholders is desired.
  • Experience with privacy and data protection issues related to academic and medical research and health information preferred.
  • Experience navigating and coordinating activities between a university and health facilities preferred.
  • Membership and leadership in national privacy or data security organizations preferred.
  • HIPAA experience preferred.

Knowledge, Skills and Abilities

  • Demonstrated strength as a collaborative team leader in hiring, developing, and managing a high-producing team of privacy experts; experience in effectively managing staff and providing leadership to achieve the goals and vision of UMMS Compliance and the organization.
  • Demonstrated ability to build successful relationships with a wide range of staff while maintaining the ability to be transparent, decisive and forthright in a consensus-driven environment.
  • Demonstrated success in collaboratively engaging and educating a range of stakeholders on a comprehensive privacy and data protection plan as well as leading and facilitating appropriate responses to a variety of privacy and data security related incidents and investigations.
  • Demonstrated current working knowledge of relevant and emerging privacy and data protection laws and regulations.
  • Skilled at listening, collaborating, and executing measurable program components in a consensus driven organization.
  • Able to synthesize complex laws and regulations into communications that are meaningful, effective, and easy to understand as well as meaningfully partner with team members to edit and inspire their communication as well.
Additional Information

All your information will be kept confidential according to EEO guidelines.

#J-18808-Ljbffr

  • , MD, United States The University of Maryland Medical System Full time

    The University of Maryland Medical System is a 14-hospital system with academic, community and specialty medical services reaching every part of Maryland and beyond. UMMS is a national and regional referral center for trauma, cancer care, Neurocare, cardiac care, women’s and children’s health and physical rehabilitation. UMMS is the fourth largest...


  • , MD, United States The University of Maryland Medical System Full time

    The University of Maryland Medical System is a 14-hospital system with academic, community and specialty medical services reaching every part of Maryland and beyond. UMMS is a national and regional referral center for trauma, cancer care, Neurocare, cardiac care, women’s and children’s health and physical rehabilitation. UMMS is the fourth largest...


  • Evansville, IN, United States Atlas Full time

    Atlas Van Lines is comprised of a family of companies that deliver transportation and related services globally through a network of quality agents and select service partners. Atlas is distinguished by agent ownership and a shared commitment to help people go new places more easily and more securely. Through a continuing emphasis on service excellence, the...

  • Director of Privacy

    4 weeks ago


    Gaithersburg, MD, United States HireMinds Full time

    Our life science client in Maryland is looking to add a Compliance Privacy Officer (Associate Director) to their Legal team! This role will work collaboratively with a global network of privacy professionals and cross-functionally with other functions, including Commercial, Legal, IT, HR, and R&D, to continue to build and mature the company's privacy...


  • New York, NY, United States Pyramid Consulting, Inc Full time

    Immediate need for a talented Privacy Compliance Officer/Data Protection. This is a 06+ Months Contract opportunity with long-term potential and is located in New York NY (Onsite). Please review the job description below and contact me ASAP if you are interested.Job ID:24-46494Pay Range: $60 - $68/hour. Employee benefits include, but are not limited to,...


  • Los Angeles, CA, United States Data Privacy Full time

    Company : Albert Einstein College of Medicine POSITION RESPONSIBILITIES: Analyze and interpret complex biological data using advanced bioinformatics tools and techniques. Develop and implement machine learning and deep learning algorithms to drive data-driven insights. Manage and manipulate large datasets using SQL (Oracle and SQL Server) for data...

  • Data Privacy Analyst

    4 weeks ago


    Dallas, TX, United States System Soft Technologies Full time

    Job Description – Data and Privacy AnalystSystem Soft Technologies is a premier technology company providing exceptional consulting services and solutions that drive innovation, enhance business value, and boost competitiveness. For over 25 years, we have built trusted partnerships with our clients, helping us grow into a $200MM+ enterprise. With the...


  • , KS, United States Kansas Action for Children, Inc Full time

    at Clarivate Analytics US LLC in Overland Park, Kansas, United States Job Description We are looking for a Privacy Director, Assistant General Counsel to join the Clarivate Analytics privacy team! This role will report to the SVP, Chief Compliance and Privacy Officer. Clarivate has global operations and operates in 40+ countries. This role plays an...

  • Senior Consultant

    8 hours ago


    Río Grande, PR, United States College of Charleston Full time

    About the Business Risk Advisory Trust, resilience and security connecting for enduring success and responsible business. With competencies encompassing capital markets, control assurance, contractual exposure and insurance claims, and security services, our RA professionals offer a wealth of experience across a spectrum of industries. This is a great...


  • Washington, DC, United States Vanguard-IP Full time

    REQUIREMENTS Successful candidates are required to have experience in the data privacy and information security practice area. Understand how data flows through the organization and how to work with key stakeholders on developing compliance protocols, best data-related practices, and balancing legal risks with business needs. Ability to advise broadly...

  • Data Privacy Attorney

    4 weeks ago


    Houston, TX, United States Avalon Legal Search Full time

    - Exclusive, unpublished need for a Data Privacy partner. This firm has an established Houston office and needs data privacy and cyber security expertise. The firm is open to considering candidates with a growing book of business and solid experience in the data privacy field. Laid back, collaborative environment with cross-selling among practice groups and...

  • Data Privacy Attorney

    4 weeks ago


    Houston, TX, United States Avalon Legal Search Full time

    Exclusive, unpublished need for a Data Privacy partner. This firm has an established Houston office and needs data privacy and cyber security expertise. The firm is open to considering candidates with a growing book of business and solid experience in the data privacy field. Laid back, collaborative environment with cross-selling among practice groups and...


  • Richmond, VA, United States Webologix Ltd INC Full time

    Role: Senior Data Privacy ConsultantLocation: Richmond, VA / Stamford, CTType of hiring: FTEJob Description:At least 7 years of experience with Information TechnologyAt least 5 years of experience in data disciplines, with at least 3 years in relevant advisory roles in any of the following areas : - Data Warehouse strategy definition or solution design, Data...

  • Senior Legal Counsel

    7 hours ago


    San Francisco, CA, United States Databricks Full time

    GAQ225R54 Location: We are hiring for this position locally to our offices in Seattle, Bellevue, Denver, San Francisco, NYC, Chicago, Atlanta, Boston, San Diego, Mountain View or D.C. Databricks is seeking a Privacy Legal Counsel to help the Databricks legal team navigate rapidly evolving global privacy laws and regulations. You will initially report to the...

  • Senior Director

    7 hours ago


    Scottsdale, AZ, United States StandardAero Full time

    Build an Aviation Career You're Proud Of At StandardAero, we use our ingenuity and know-how to find solutions for the simple to the most complex challenges in aviation. Together, we get the job done and done well. Our stability, resources, and respectful culture supports you in building a solid career with a great team you can count on day in and day out...


  • Daytona Beach, FL, United States Brown & Brown Insurance Full time

    Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers.Brown & Brown is an independent insurance intermediary that through its licensed subsidiaries provides a variety of insurance and reinsurance products and services to corporate, public entity, institutional, trade,...


  • Irvine, CA, United States Solugenix Corp Full time

    HR Data Privacy CoordinatorWhile professional experience and qualifications are key for this role, make sure to check you have the preferable soft skills before applying if required.Flexible or Irvine, CA (Hybrid)6-Month ContractJob ID 24-09293Solugenix is assisting a client, a prestigious and large investment management company in their search for a HR Data...


  • Oakland, CA, United States Blue Shield of California Full time

    Your Role The Privacy Office develops and oversees Blue Shield's Privacy Program. The Privacy Program ensures that Blue Shield and its affiliated covered entities, including Blue Shield of California Promise Health Plan, are in compliance with state and federal privacy laws and regulations, including the Health Insurance Portability and Accountability Act of...


  • Chicago, IL, United States NTT DATA Full time

    Req ID: 298695 NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a AI: Data Analytics Consulting, Director to join our team in Plano, Texas (US-TX), United States (US).As an Gen AI...


  • Indiana, PA, United States Eli Lilly and Company Full time

    At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities...