Website EmpITsolutions EmpITsolutions
Job Description: Privacy Impact Assessment (PIA) Specialist – Senior x2 openings
# of positions: 2 submissions
Submission Closing: Sept 30 2pm
Start Date: 2024-10-15
End Date: 2025-03-31
Extension # of Days: 252.00
Max Extension Term(s): 2 Times
Assignment type: Remote
Location: 525 University Ave. Toronto, Ontario
Description
Background Information:
The Senior Privacy (PIA) Specialist will act as a dedicated privacy subject matter expert to assist with supporting privacy matters related to a number of key Information Technology projects that include Patients Before Paperwork (PB4P) initiatives, enterprise business intelligence tools, and cloud migration.
Ontario Health is seeking a Privacy resource to ensure that Ontario Health maintains compliance with its legal and contractual privacy obligations and builds privacy into the design of projects that involve personal health information (PHI), thus reducing risk for the organization and protecting the trust and privacy of individuals whose PHI we manage.
Responsibilities:
- Conducting/Completing Privacy Impact Assessments and associated documentation
- Providing Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiatives
- Identify and assess privacy risks, including developing risk mitigation plans
- Create or inform the creation of data flow diagrams and associated privacy controls and compliance requirements
- Reviewing and advising on agreements, including data sharing agreements
- Developing privacy requirements for new or changing projects
- Providing privacy advisory and support to business teams
- Other duties as required
Desired Skills:
- Demonstrable knowledge of project management; Knowledge and understanding of Project Management’s Institute’s Project Management Body of Knowledge is an asset
- Minimum 5 years’ experience developing privacy policies and procedures, requirements, or controls
- Familiarity with the Personal Health Information Protection Act (PHIPA), and its related requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP)
- Familiarity with Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure, design, and data flows
- Experience working on and delivering multiple projects
- Demonstrated project management software skills and experience e.g. MS Project, MS Teams etc.
- University undergraduate or graduate degree in Health, Computer Science, Engineering, Law, Security, or a related discipline from a recognized institution or equivalent experience – desired
- Familiarity with Prescribed Entities (PEs) or Prescribed Persons (PP) under the Personal Health Information Protection Act (PHIPA), and their related requirements, is an asset
- Familiarity with audit logging and Security Information and Event Management (SIEM) technology is an asset
- Familiarity with technical data protection controls and technology such as encryption and tokenization is an asset
- Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards is an asset
Must Haves:
- 3+ years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects
- 5+ years’ direct operational level privacy experience with familiarity in Application Programming Interface (API) functionality and management
- 5+ years’ experience drafting and reviewing privacy requirements for legal and data sharing agreements
Location: Remote
Public Sector Experience: Preferred Healthcare
Required Experience / Evaluation Criteria:
- Minimum 3 years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects. : 20 Points
- Minimum 5 years’ direct operational level privacy experience in a health sector and/or IT environment or both. : 20 Points
- Minimum 5 years’ experience in developing privacy policies and procedures, requirements, or controls.: 20 Points
- Minimum 5 years’ experience drafting and reviewing privacy requirements for data sharing agreements.: 15 Points
- Familiarity with the Personal Health Information Protection Act (PHIPA), and requirements related to Health Information Network Provider (HINP) and Electronic Service Provider (ESP).: 10 Points
- Familiarity with Application Programming Interface (API) functionality and management.: 7.5 Points
- Familiarity with Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure, design, and data flows: 7.5 Points
Total 100 points
Deliverables
- Over the duration of the engagement, the Senior Privacy (PIA) Specialist will support work already in progress, as well as new work on Privacy Impact Assessments;
- Work with the project and product teams on risk mitigation of PIA findings as required under PHIPA;
- Support work related to update and/or developing new agreements;
- Other duties as required. Note that knowledge of current privacy and data protection policy and legislation, especially Ontario’s Personal Health Information Protection Act (PHIPA), will be critical to ensure success.
Supplier Comments
MSP Notes
Shortlist Date: September 30, 2024 2:00 pm EST
# of submissions/supplier: 2
Kindly send resume to vijaychilwal@empitsolutions.com