HIPAA Privacy Lead - Policy, Risk & Compliance
Allia Health Group
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Full-Time Houston, TX, US 6 days ago Requisition ID: 1358 About Allia Health Group Allia Health Group (AHG) is a multi-brand healthcare holding company whose subsidiaries include Southend Pharmacy, Brello, HelloWellness, and AlliaCare. AHG is building a formal compliance program spanning HIPAA Privacy & Security, SOC 2 attestation, and broader healthcare regulatory compliance across a fast-moving, multi-entity structure. Position Summary The HIPAA Privacy Lead serves as the enterprise HIPAA Privacy SME for AHG's U.S. operations, owning day-to-day interpretation, application, and oversight of the HIPAA Privacy Rule. This individual-contributor role reports to the Chief Compliance Officer & Privacy Officer and formalizes work currently led directly by the CCO — BAA management, privacy risk assessment, policy development, de-identification governance, and workforce training — giving the Privacy program dedicated, sustained ownership as AHG grows. This is a full-time remote position. Candidates must be available to work during standard business hours. Key Responsibilities Privacy Program & Policy Maintain and mature HIPAA Privacy policies and procedures across all covered entities and business associates (Southend Pharmacy, Brello, HelloWellness, and AHG Enterprise); advise business, clinical, and IT teams on PHI handling and privacy risk mitigation. Partner with GRC to define, implement, and monitor HIPAA controls and align privacy requirements with AHG's broader regulatory frameworks, including the parallel SOC 2 effort. Review project designs, system implementations, and process changes for HIPAA alignment, embedding privacy-by-design into clinic and enterprise operations. Own the BAA inventory — drafting, tracking, and remediating gaps — and support AHG's de-identification framework (Safe Harbor / Expert Determination under §164.514), including tokenization and egress governance. Partner with outside counsel on privacy legal questions, data architecture reviews, and open-items tracking. Conduct HIPAA privacy risk assessments and breach risk analyses (four-factor framework); maintain the privacy risk register and drive remediation to closure. Collaborate with Cyber & Privacy Operations during incidents on breach assessment, escalation/containment/notification decisions, and post-incident SOPs. Serve as primary point of contact for privacy complaints, investigations, and regulatory inquiries, working closely with U.S. Privacy Legal Counsel. Lead vendor risk assessments for third parties handling PHI, including HIPAA-specific due diligence. Patient Rights & Data Governance Oversee patient requests for access, amendments, restrictions, and confidential communications, ensuring timely, appropriate responses; maintain documentation demonstrating HIPAA compliance. Partner with Engineering and Data Engineering to map PHI/PII data flows and review new systems, AI/agentic tools, and vendor integrations before launch. Develop self-service tools and templates so teams can independently handle routine privacy requirements. Training & Reporting Design and deliver workforce HIPAA privacy and incident-management training; partner with clinical/operational leaders to embed HIPAA into day-to-day practice operations. Represent AHG's privacy posture in regulatory, audit, and compliance forums; monitor regulatory developments (HHS/OCR, state privacy law, FTC) and report program status to the CCO. Qualifications Required 5+ years of hands-on HIPAA Privacy compliance experience in a regulated environment, specifically within a Specialty Pharmacy or other Covered Entity. Hands-on experience with PHI/PII data flow mapping, leading a HIPAA Annual Risk Assessment, and designing/delivering HIPAA Incident Management training. Working knowledge of the HIPAA Privacy Rule, Security Rule interplay, BAA requirements (45 CFR §164.504(e), §164.314(a)), and de-identification standards (§164.514). Demonstrated experience drafting or managing BAAs, data-sharing agreements, or privacy policies, and working directly with outside counsel and technical stakeholders. Experience using compliance and governance platforms (e.g., OneTrust, NAVEX, RSA Archer, ServiceNow GRC, or similar), document management systems, and Microsoft Office Suite (Excel, Word, PowerPoint, and Outlook) to support HIPAA privacy and compliance programs. Strong written communication — able to translate legal/regulatory requirements into plain, actionable guidance for business and technical teams. Preferred Certification such as CHC (Certified in Healthcare Compliance), CHPC (Certified in Healthcare Privacy Compliance), or CIPP/US. Experience with pharmacy, DTC health/wellness brands, or multi-brand healthcare holding structures. Familiarity with BigQuery, cloud data warehouses, or tokenization/de-identification tooling (e.g., Protegrity) sufficient to engage credibly with engineering. Exposure to SOC 2 programs or working alongside a parallel SOC 2 effort. What Success Looks Like (First 6–12 Months) Working with the CCO, HIPAA Privacy policies drafted and awareness created across the business unit. Intercompany BAAs identified, drafted, and executed, with the BAA inventory as source of truth. Privacy risk register stood up and actively tracked with clear ownership and remediation dates. De-identification framework operationalized with Engineering and Security, including a defensible position on tokenized/egress data. Workforce privacy training launched; CCO able to delegate day-to-day privacy operations with confidence, freeing capacity for SOC 2 and broader Healthcare Compliance work. What We Offer: Full benefits package including medical, vision, dental, 401(k) with company match, PTO, Flex days, holidays, and more! Allia Health Group does not provide employment visa sponsorship now or in the future. Applicants must be legally authorized to work in the United States without the need for current or future sponsorship. Equal Opportunity Employer Statement Allia Health Group is proud to be an Equal Opportunity Employer where we are committed to fostering a diverse and inclusive workplace. We are committed to cultivating a culture where all team members feel valued & respected. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetic information, disability, age, veteran status, or any other characteristics protected by applicable law. #J-18808-Ljbffr Allia Health Group
- Allia Health Group is seeking a HIPAA Privacy Lead to own day-to-day interpretation, application, and oversight of the HIPAA Privacy... .... The Privacy Lead will drive BAA management, privacy risk assessments, policy development, de-identification governance, and #J-18808...PolicyRemote jobFull time
- ALS seeks a Head of Compliance, North America to lead the implementation and ongoing enhancement... ..., identify regulatory risks, and drive consistent... ...will develop and implement policies, monitor US regulatory developments, coordinate privacy risk assessments, and oversee...Policy
- ...Requirements The Sensitive Data Compliance Lead Consultant role at FORVIS... ...clients by identifying key risks and gaps and documenting... ...system security plans (SSP), policies/procedures, strategy development... .... Cybersecurity and/or privacy‑related certifications (e.g....PolicyFor contractorsFlexible hours
- POSITION OVERVIEWThe Senior/Lead Analyst, Market Risk, reports directly to the Manager, Market Risk, and is responsible for developing... ..., including daily risk reporting to ensure compliance with Risk Policies and Limits as well as providing risk analysis for proposed...PolicyWork at officeWork from homeFlexible hoursWeekend work
$112.8k - $257k
Information Security Risk Specialist, LeadThe Opportunity: Cyber threats are everywhere... ...how to mitigate them? The answer is you, a lead information security risk specialist who... ...cyber risks, understanding applicable policies, and developing a mitigation plan. You’ll...PolicyFull timeContract workPart timeWork at officeLocal areaRemote work- Tailored Brands, Inc. seeks a GRC Analyst to develop and maintain privacy, security, and governance policies. Collaborate with business and technology stakeholders to align systems, data, and processes with industry standards and regulatory requirements. The position requires...Policy
- ...seeking an Information Security Analyst to support Governance, Risk Management and Compliance across Digital & IT environments. The role helps maintain... ...and collaborate with stakeholders to enforce security policies and respond to incidents, audits and regulatory...Policy
$155k - $175k
...together to support the most exciting missions in the world! As a Lead Cyber Risk Advisor, you will be a vital member of the Qualys Cyber Risk... ...highly competitive benefits package. Qualys is an Equal Opportunity Employer, please see our EEO policy. #J-18808-Ljbffr QualysPolicy$128.6k - $164k
...& Logistics Industries Sectors Research Lead will be accountable for shaping and delivering... ...of the role you're pursuing.JLL Privacy NoticeJones Lang LaSalle (JLL), together... ...copy of our Equal Employment Opportunity policy here.Jones Lang LaSalle (“JLL”) is an Equal...PolicyFull timeLocal areaShift work- Tailored Brands, Inc. is seeking a Privacy Analyst II to join the Information Security... ..., report, and mitigate data privacy risks, contributing to policy development and assurance across AI... ...to assess privacy risks, support compliance, and deliver training. Strong...PolicyRemote job
- VoltaGrid is seeking a Cybersecurity Risk & Compliance Analyst in Houston to formalize and scale our risk governance, compliance, and policy framework across IT and operational environments. You will drive clarity in risk management, controls, policies, and audit readiness...Policy
$172.5k - $225k
Circle (NYSE: CRCL) is one of the world’s leading internet financial platform companies,... ...Engineering, Data, Treasury, Legal, and Policy teams as we explore potential token design... ...@circle.com for support. We respect your privacy and will connect with you separately from...PolicyFlexible hours- A leading consulting firm seeks a Governance Risk Compliance Senior Manager to oversee GRC programs, ensuring effective policies and compliance standards are met. This role requires expertise in compliance frameworks, risk management, and leadership skills in a cross-functional...PolicyFull time
- ...just a job, it’s a chance to lead innovation, architecture and engineering... ..., resilience, security, and compliance, such as digital twins,... ...opportunities, while effectively managing risk. Coordinate with project teams... ...compliance lens: Support policy development, software...Policy
- Title:Lead eDiscovery AnalystKBR is seeking a highly skilled and... ..., Information Security, Compliance, Human Resources, and external... ...legal, regulatory, and data privacy requirements.In September 202... ...titles or levels, per internal policy or contractual designation. Additional...PolicyFull timeTemporary workLocal areaRemote workRelocation packageFlexible hours
- ...Intellectual Property and Data Privacy Corporate Counsel provides... ...commercialization, and leads the legal review of data-sharing... ...while managing legal risk and supporting compliance with applicable laws, regulations, and institutional policies. This position develops and...PolicyContract work
$14.5 per hour
...’re hands‑on leaders who set the tone for every shift. You’ll lead by example, work side‑by‑side with your team, and ensure every... ...you have read the Detailed Position Description, as well as our Privacy Policy. It is the policy of Five Guys to provide equal employment...PolicyShift work- ...Lead RDA Opportunity at Swish Dental Swish Dental is a privately owned... ...Adhere by State, Federal, and local compliance standards including OSHA, HIPAA, and Texas Dental Board Provide... ...duties in accordance with practice policies Review the schedule throughout the...PolicyTemporary workLocal areaShift work
$19 - $21 per hour
...Front End Lead - Eataly Houston (New Store Opening!) Eataly is the world's largest artisanal... ...employer. It is the Company's policy to not unlawfully discriminate against any... ...Resources if you require accommodation. Job Location I'm interested Privacy Notice EatalyPolicyHourly payWork at officeLocal areaFlexible hours- Day Shift At Houston Methodist, the Lead Patient Access Services position is responsible... ...and knowledge of the organization's policies and practices, operating a personal computer... ...met. Protects patient and family privacy rights and maintains confidentiality of patient...PolicyFull timeWork at officeShift workDay shift
- ...enterprises. Role & Responsibilities Lead, train and motivate fabrication... ...isometrics, and work orders, ensuring compliance with customer specifications Perform and... ...information click here, aquí). Sun-Source | Privacy Policy #ghxassc We may use artificial...PolicyFlexible hoursShift work
$145k - $205k
...analytically sound Compensation Lead to own the end-to-end... ...are set up to support Affirm’s policies, procedures, and employees. In... ...ability to establish and maintain compliance of all plans and programs... ...read Affirm's Global Candidate Privacy Notice and hereby freely and...PolicyWork at officeRemote workFlexible hoursShift work$89.57k - $111.97k
...About Vibrantz Technologies** Vibrantz Technologies is a leading global provider of specialty chemicals and materials... ...systems *Vibrantz is committed to protecting your privacy. We provide a Website Privacy Policy located on our site to explain the type of information...PolicyWork at officeLocal area$103.62k - $140.14k
...At Smiths Group plc, we apply leading-edge technology to design,... ...measures as needed (i.e. PM Compliance, Work Order management in Service... ..., safety and environmental policies Other duties as required Qualifications... ...‑party website's terms and privacy policy apply #J-18808-Ljbffr...PolicyFor contractors$105.05k - $152k
...America University Programs Lead Description - North... ...tracking. Maintain program policies, processes, governance standards, and compliance requirements. Track and... ...reviews. Identify risks and implement mitigation... ...want. Let’s grow together. Privacy, Terms of Use, and Accessibility...PolicyFull timeTemporary workWork at officeLocal areaRelocationFlexible hoursShift work$140k - $165k
...PMO Governance & Quality Lead is a strategic... ...frameworks that protect JLL's risk and reward position across... ...downstream monitoring, compliance, and improvement cycles... ...structures, workflows, policies, and procedures across... ...you're pursuing. JLL Privacy Notice Jones Lang...PolicyDaily paidContract workLocal areaNight shift$91k - $185.9k
...to the company’s success. As a Lead Product Owner within PNC's... ...business value, customer impact, risk, effort, and dependencies.• Define... ..., IT Standards, Procedures & Policies, Managing Multiple Priorities,... ...to the California Consumer Privacy Act Privacy Notice to gain understanding...PolicyFull timeTemporary workPart timeWork experience placementWork at officeImmediate start- ...are looking for a full-time Lead Veterinarian to join our Healthcare... .... Implementing the outlined policies and procedures, using... ...Oversee operating, safety, and compliance procedures as required by applicable... ...CPRA Job Applicant Privacy Policy, please click here. #J...PolicyFull timeShift work
$120k - $135k
...connect with you. What'll Do Lead enterprise‑wide vulnerability... ...efforts. Perform threat analysis, risk assessments, and security... ...protected categories. It is Jobot’s policy to comply with all applicable... ...submit is subject to Jobot’s Privacy Policy, as well as the Jobot...PolicyLocal area- ...JobCatalyst Labs is a leading talent agency with a specialized... ...in Legal, Regulatory Compliance, and Corporate... ...next decade of regulatory risk management, data governance... ...ComplianceData Privacy (GDPR / CCPA / global privacy... ...operations workflows:Policy drafting & governance frameworksRisk...PolicyContract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to HIPAA Privacy Lead - Policy, Risk & Compliance. Be the first to apply!
- education policy research Houston, TX
- public policy intern Houston, TX
- health policy Houston, TX
- public policy Houston, TX
- policy summer internship Houston, TX
- policy assistant Houston, TX
- healthcare policy Houston, TX
- education policy Houston, TX
- intern human rights policy Houston, TX
- environmental policy intern Houston, TX


