23 Aug
|
United Software Group
|
Toronto
23 Aug
United Software Group
Toronto
Job Title: Accountable Privacy Executive / Privacy Program Executive – PHIPA/FIPPA/PIPEDA
Location: Toronto, Ontario, Canada — Remote/Hybrid
Note: Only candidates who have resided in Toronto continuously for the previous 5 years will be considered; occasional travel to client sites in Ontario required)
: We're seeking an Accountable Privacy Executive to hold executive-level accountability for the privacy program across a major digital health transformation engagement. This is a named, signing-authority role — you'll own privacy governance, compliance attestations, and breach management end-to-end for services involving personal health information (PHI).
Day-to-Day Responsibilities:
- Serve as the named Accountable Privacy Executive, holding executive accountability for privacy across all in-scope services, systems, and personnel
- Sign and maintain privacy attestations, declarations, and compliance certifications (Attachment 1 requirements 1.7.15 and 1.7.18), keeping supporting evidence audit-ready
- Establish and oversee the privacy governance framework, policies, and operating procedures for PHI collection, use, disclosure, retention, and disposal
- Ensure ongoing compliance with PHIPA, FIPPA, and PIPEDA, along with provincial privacy/security policies
- Direct Privacy Impact Assessments (PIAs), coordinate Threat Risk Assessments (TRAs), and embed privacy-by-design into solution architecture
- Own privacy breach and incident management end-to-end — containment, investigation, root cause analysis, remediation tracking
- Chair privacy governance forums; act as single escalation point for privacy risks and decisions between delivery and client stakeholders
- Advise client executives and clinical stakeholders on privacy risk posture and regulatory exposure
- Embed privacy obligations into contracts, data sharing agreements, and vendor onboarding
- Oversee privacy training,
confidentiality undertakings, and role-based access governance for all PHI-access resources
- Lead privacy audits, self-assessments, and readiness reviews; respond to regulator and third-party assurance requests, including IPC reviews
- Report privacy program performance, KRIs, incidents, and remediation status to executive sponsors
Required Qualifications:
- 10+ years in privacy, data protection, or information governance, with solid focus on regulated environments (healthcare, public sector, or consulting)
- 5+ years in an executive or named accountable capacity (CPO, Privacy Director, Accountable Privacy Executive, or equivalent), including signing authority for attestations
- 7+ years hands-on experience with Canadian privacy legislation — PHIPA, FIPPA, PIPEDA
- 5+ years conducting/overseeing PIAs and coordinating TRAs for enterprise or province-wide systems
- 5+ years leading privacy breach/incident management, including regulator notification and executive reporting
- 5+ years in consulting or client-facing advisory roles with executive stakeholder management
- Demonstrated accountability track record under contractual/regulatory frameworks
- 5+ years exposure to frameworks such as NIST Privacy Framework, ISO/IEC 27001/27701, HITRUST
- 3+ years working with health information custodians, prescribed entities, or health information network providers
- Active privacy certification: CIPP/C, CIPM, or CIPT
- Bachelor's degree in Law, Health Informatics, Information Management, Business, Engineering, Technology, Information Systems, or related field (Master's or J.D. a plus)
Nice to Have:
- Consulting experience within the Canadian public healthcare sector
- Experience supporting IPC Ontario reviews or prescribed entity triennial reviews
- Additional certifications: CISSP, CISM, CISA, CHPC, or legal qualification in privacy/health law
- Bilingual proficiency in English and French
📌 Privacy Program Executive – PHIPA/FIPPA/PIPEDA (Toronto)
🏢 United Software Group
📍 Toronto