Information Security Officer

MedvidiSan Jose, CA

About The Position

MEDvidi is a multi-state telehealth practice delivering behavioral health and psychiatric services through a licensed Professional Corporation structure. As our organization and provider workforce continue to grow, protecting highly sensitive behavioral-health information and maintaining a strong, operational HIPAA security program are critical to our continued success. We are seeking an experienced Information Security Officer (ISO) to own and operate MEDvidi's HIPAA Security Program. The Information Security Officer will have end-to-end ownership of MEDvidi's information security program, with particular responsibility for safeguarding electronic protected health information (ePHI). You will inherit a completed Security Risk Analysis and be responsible for turning identified risks and recommendations into a sustainable operating program. This includes remediation execution, ongoing risk management, technical and administrative safeguards, vendor security, incident response, security policies, and security compliance. This is a hands-on ownership role for someone comfortable independently running a security program in a lean, fast-moving healthcare environment.

Requirements

  • 6+ years of information security experience.
  • 2+ years of experience in healthcare or another regulated ePHI/PII environment.
  • Demonstrated hands-on ownership of a HIPAA security program or equivalent regulated security program; advisory-only experience is not sufficient.
  • Strong working knowledge of the HIPAA Security Rule.
  • Working knowledge of at least one relevant security/control framework, such as: NIST Cybersecurity Framework (CSF) 2.0, NIST SP 800-66r2, HITRUST
  • Demonstrated ability to independently run a security program in a lean environment.
  • Strong risk-based prioritization, practical control implementation, and security documentation skills.

Nice To Haves

  • CISSP, HCISPP, CISM, or equivalent certification.
  • Experience securing telehealth platforms or other healthcare technology environments.
  • Cloud security experience with AWS, Azure, and/or GCP.
  • Experience leading security incident response.
  • Experience working with fractional or external security resources, penetration testers, and independent security advisors.
  • Familiarity with evolving HIPAA Security Rule requirements.

Responsibilities

  • Serve as MEDvidi's designated HIPAA Security Official under 45 CFR § 164.308(a)(2).
  • Own the organization's security risk analysis and ongoing risk-management cycle, including maintaining the risk register and driving remediation items to closure.
  • Develop, operate, document, and maintain HIPAA administrative safeguards, including workforce security, access authorization, security awareness and training, incident procedures, and contingency planning.
  • Partner with IT to implement and maintain technical safeguards involving access controls, authentication, audit controls, data integrity, logging, and encryption of ePHI in transit and at rest.
  • Maintain security policies for MEDvidi's distributed workforce, including workstation security, device and media controls, and remote-work ePHI handling.
  • Own the security incident response process, including detection, containment, forensics coordination, documentation, and annual tabletop exercises.
  • Partner with the Privacy Officer on breach investigations and other areas where privacy and security requirements overlap.
  • Lead vendor and Business Associate security diligence, including security questionnaires, SOC 2/HITRUST reviews, subcontractor risk, and remediation of security findings.
  • Support security architecture and tooling decisions involving telehealth platforms, EHR access, endpoint management, logging, and SIEM coverage.
  • Review the security implications of AI tools and AI-assisted security and compliance processes used within the organization.
  • Manage and operate MEDvidi's GRC platform in partnership with Compliance leadership.
  • Monitor changes to the HIPAA Security Rule and help MEDvidi assess and implement new requirements as they become applicable.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service