Privacy Analyst

The University of Arizona•Tucson, AZ
•Onsite

About The Position

The Privacy Analyst supports the University of Arizona’s privacy program by assisting in the monitoring of compliance with federal, state, and international regulations, as well as internal policies and emerging privacy requirements. Reporting to the HIPAA Privacy Officer, this role supports the investigation of potential privacy incidents, contributes to breach risk assessments, and assists with required documentation, reporting, and mitigation activities. The Privacy Analyst collaborates with cross-functional teams to support privacy communication and training initiatives, participate in privacy assessments, and coordinate program activities across departments and colleges within the HIPAA Privacy Program.

Requirements

  • Knowledge of privacy laws (e.g., GDPR, HIPAA) and compliance standards.
  • Understanding of other key subjects including cyber security and risk management.
  • Strong communication skills for articulating privacy risks and policies.
  • Strong critical thinking skills and the ability to assess how state, federal, and international privacy requirements apply to specific situations.
  • Strong interpersonal skills and a commitment to fostering productive, respectful partnerships across teams and roles.
  • Ability to collaborate with stakeholders on privacy matters.
  • Ability to develop and enforce privacy policies.
  • Ability to meticulously review contracts and data access requests for privacy compliance.
  • Ability to translate complex privacy concepts into practical, easy-to-understand guidance for a variety of audiences.
  • Familiarity with HIPAA requirements, Business Associate Agreements, or other regulated-data environments.
  • Demonstrated curiosity and willingness to learn new and often complex topics, including privacy, legal regulations, and information security.
  • Bachelor's degree or equivalent advanced learning attained through professional level experience required.
  • Minimum of 3 years of relevant work experience, or equivalent combination of education and work experience.

Nice To Haves

  • Experience in data privacy, business, information security, law, compliance, or a similar field
  • Direct privacy experience is not required; relevant and transferable experience will be strongly considered for those with:
  • Experience conducting or supporting investigations, incident response, audits, assessments, or other fact-finding activities
  • Experience documenting findings, tracking remediation activities, and preparing clear reports for leadership and other stakeholders
  • Experience coordinating projects or compliance activities across multiple departments
  • Experience developing or delivering training, guidance, or communications for varied audiences
  • Experience handling sensitive or confidential information with discretion and sound judgment
  • Experience working in a higher education setting
  • Certification from a relevant professional association, such as the International Association of Privacy Professionals (IAPP), Health Care Compliance Association (HCCA), or Information Systems Audit and Control Association (ISACA)
  • Experience in privacy risk assessments and compliance monitoring.

Responsibilities

  • Coordinates program activities across departments and colleges designated as HIPAA Covered Components within the HIPAA Privacy Program.
  • Participates in the annual review of HIPAA Covered Components and the annual HIPAA risk assessment process.
  • Documents results of the annual assessments; tracks action items and remediation activities.
  • Coordinates the review and tracking of Business Associate Agreements; performs vendor privacy risk assessments; coordinates the Authorization to Operate process for certain applications storing or processing regulated data.
  • Partners with cross-functional teams to ensure appropriate safeguards and documentation are in place.
  • Supports privacy communication and training initiatives, including the development and updating of privacy training and marketing communications.
  • Coordinates with human resources on training delivery, tracking, and reporting.
  • Supports privacy incident response activities, including incident intake, investigation, documentation, issue tracking, and remediation.
  • Prepares summary reports for presentation to senior management and other stakeholders.
  • Maintains current knowledge of applicable federal, state, and international privacy related laws, regulations, and accreditation standards.
  • Supports the development, maintenance, and annual review of university privacy policies and procedures.
  • Other Duties as Assigned.

Benefits

  • health, dental, and vision insurance plans
  • life insurance and disability programs
  • paid vacation, sick leave, and holidays
  • U of A/ASU/NAU tuition reduction for the employee and qualified family members
  • retirement plans
  • access to U of A recreation and cultural activities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service