Privacy Impact Assessment (Pia) Specialist - Senior (Toronto)

Privacy Impact Assessment (Pia) Specialist - Senior (Toronto)

31 Aug
|
ThoughtStorm
|
Toronto

31 Aug

ThoughtStorm

Toronto

OverviewPrivacy Impact Assessment (PIA) Specialist - Senior-EHR / Pb4P. Description: The purpose of this procurement is to acquire Senior Privacy (PIA) Specialists to provide dedicated privacy subject matter expertise to assist with supporting privacy matters related to a number of key Information Technology projects including, but not limited to provincial Electronic Health Record (EHR) initiatives, Provincial Viewers, Pb4P initiatives.Must havesMinimum of 5 years’ health privacy experience conducting privacy impact assessments on medium to high complexity projectsMinimum 5 years’ direct operational level privacy experience preferably in a health sector and/or IT environmentMinimum 5 years’ experience developing privacy policies and procedures, requirements or controlsHolds an undergraduate or graduate degree in health, policy, IT, security, law or a related disciplineExperience with the Personal Health Information Protection Act, 2004 (PHIPA), including requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP). Experience working with prescribed statuses is considered an asset.Familiarity with OntarioMD EMR certificationFamiliarity with EMR or HIS infrastructure, design, and data flowsFamiliarity with API functionality and managementResponsibilitiesThe Senior Privacy Impact Assessment (PIA) Specialist will lead and support various initiatives, include, but not limited to:Develop privacy policies and proceduresConduct privacy impact assessments for low to high complex initiativesInvestigations of privacy incidents, patient inquiries, and privacy requests as requiredIdentify and assess privacy risksProvide privacy advisory support to business teamsLead and/or participate in Agency, regional or provincial committees or project teams as the privacy Subject Matter ExpertDevelop robust relationships with various internal and external stakeholders to foster a culture of privacyRespond and provide advice and legislative interpretation for information and access requests, consent management requests, complaints or inquiries, appeals and privacy issues under the Personal Health Information Protection Act,



2004 and the Freedom of Information and Protection of Privacy ActSupport privacy program projects and activities to improve the efficiency and effectiveness of the Privacy OfficeDevelop and deliver privacy training for the AgencyOther duties as requiredDesired SkillsCompletion of a university undergraduate or master’s degree in health, policy, IT, security, law or a related disciplineDemonstrated knowledge and experience of access and privacy requirements and practices, preferably related to the health and public sectorsRecognized security certification or designation is an assetExcellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirementsKnowledge and ability to interpret Ontario’s Personal Health Information Protection Act, 2004 (PHIPA)Knowledge and ability to interpret Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA)Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiativesThorough understanding of “privacy-by-design” and best practicesExperience with conducting and/or providing oversight for Privacy Impact Assessments and Privacy Threshold Assessments, including developing privacy requirements, risk mitigation plans, corporate policies and developing and/or delivering training contentKnowledge of technology architecture and infrastructure, digital health solutions and services, enterprise and corporate IT including information and cyber security preferredWorking knowledge of digital health technologies and information security industry standardsExcel in a fast-paced and project focused environmentExceptional analytic and creative problem-solving abilitiesGood understanding of related disciplines, such as IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management,



project managementKnowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flowsExcellent Communication skills both verbal and written, and strong stakeholder engagement skillsTime Management, with the ability to manage tight deadlines and prioritize multiple projectsCriteriaMinimum 5 years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projectsMinimum 5 years’ direct operational level privacy experience in a health sector and/or IT environment or bothMinimum 5 years’ experience in developing privacy policies and procedures, requirements, or controlsMinimum 5 years’ experience drafting and reviewing privacy requirements for data sharing agreementsExperience with PHIPA (including HINP/ESP) and prescribed statuses is an assetFamiliarity with API functionality and managementFamiliarity with EMR or HIS infrastructure, design, and data flowsDeliverablesDeliverables include, but are not limited to:Conduct/complete Privacy Threshold Assessments and associated documentationConduct/complete Privacy Impact Assessments and associated documentationProvide Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and IT initiatives throughout the product/service development and deployment life cycleCreate or inform the creation of data flow diagrams and associated privacy controls and compliance requirementsReview and advise on agreements, including data sharing agreementsAdditional TermsTerm: The term of this Engagement Assignment is 252 Business Days, with an option to extend for up to 252 days at the Agency's discretion. The Engagement Assignment may also be extended for unused Business Days at the Agency's discretion.The resource will comply with Agency policies and procedures.The Agency's systems cannot be accessed from outside the province of Ontario, and Agency assets including laptops and related equipment cannot be removed from the province of Ontario, without prior written approval.Assignment Type: These positions are currently listed as "Hybrid". The resources under this request will be required to work onsite as per Hiring Manager sole discretion.Knowledge

📌 Privacy Impact Assessment (Pia) Specialist - Senior (Toronto)
🏢 ThoughtStorm
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: privacy impact assessment (pia) specialist - senior (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: privacy impact assessment (pia) specialist - senior (toronto) / toronto