Mass General Brigham is seeking a Privacy Compliance Specialist II to advance its enterprise-wide privacy compliance program across its network. The Privacy Specialist II will support the enterprise privacy program with a focus on incident response, third-party risk, technology onboarding, and compliance with the new DOJ Data Transfer Rule governing sensitive personal data and bulk data transfers. This role will partner closely with clinical, research, Digital, and business operations teams to ensure appropriate handling of PII, PHI, and other regulated data across the organization. This role ensures compliance with health and data privacy laws, including the HIPAA Privacy and Security Rules, HITECH, 42 CFR Part 2, US state privacy laws, GDPR, international privacy laws, and the Department of Justice’s Data Transfer Rule. Key responsibilities include privacy incident investigations, documentation, mitigation and notifications to affected individuals and regulators; privacy audits; Privacy Impact Assessments; system/vendor privacy evaluations; data transfer reviews, website and application privacy consults, drafting Terms of Use; and advising on AI privacy risks. The Privacy Specialist II serves as a trusted business partner and privacy subject matter expert adviser to various stakeholders throughout the organization, including Human Resources, Supply Chain, Information Security, Health Information Management, Digital, and MGB’s Health Plan. The Privacy Specialist II leads privacy training presentations and partners with the Privacy Training Program leadership to design, deliver, and maintain the organization’s privacy compliance training program. The Specialist also leads process improvement initiatives for the department.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level