Job DescriptionThe responsibilities of the Data Privacy Strategist include:
Interpret and apply Ontario Freedom of Information and Protection of Privacy Act (FIPPA) and Personal Health Information Protection Act (PHIPA) and Data Sharing Agreements (DSA) and Health Information Network Provider (HINP) agreements as it relates to the project
- Assess existing policies and regulations to existing privacy frameworks, and data access models as they relate to the project
- Develop an integrated project plan and provide weekly status reports as it relates to progress on project deliverables, risks and mitigation strategies
- Coordinate across branches and develop communication materials such as briefing notes and presentations for project, program and executive level updates
- Consult and gather input from specific individuals within the organization on privacy topics either independently or as part of a team
- Communicate with technical and business teams and non-privacy experts
- Provide privacy advice and supporting deliverables for this project
Requirements- Strong understanding of the healthcare system, structures, processes, stakeholder groups and affected populations and how healthcare services are delivered in Ontario.
- Strong understanding of the role of the ministry and its delivery partners, and the levers and instruments of change.
- Strong knowledge of provincial health system data (e.g., clinical, administrative, statistical and financial data on population health).
- Strong knowledge of the digital health systems, programs, vendors, assets and solutions in Ontario.
- Strong understanding of Ontario's privacy regulations/policies/frameworks, and how they are applied to individuals and organizations in the use and protection of personal health information.
- Demonstrated experience with conducting or leading privacy impact assessments in the health context.
- Demonstrated experience with interpreting and applying information management legislation (PHIPA, FIPPA, Public Hospitals Act, Fixing Long-Term Care Act, Primary Care Act etc.) and how it applies to the collection, use and disclosure of health data.
- Demonstrated knowledge and experience of health data and information solutions, information management legislation (e.g., PHIPA, FIPPA, Public Hospitals Act, Fixing Long-Term Care Act, Primary Care Act) and experience with privacy policy, and privacy impact analysis related to collection, storage, use and disclosure of data and information.
- Demonstrated experience in providing privacy risk assessments and analysis and developing mitigation strategies to minimize privacy risk during implementation.
- Demonstrated experience in identifying and mapping business processes and developing data flow diagrams to represent current and future state data collection, management, and disclosure practices.
- Develop options to address privacy issues / business goals and provide recommended solutions
- Demonstrated experience working collaboratively with diverse stakeholders and business partners.
- Strong ability to clearly communicate with technical and business audiences and non-privacy experts.
- Ability to communicate with diverse audiences and synthesize complex ideas into plain language.
- Strong ability to develop internal reporting, demonstrating progress on deliverables and communicating/presenting results of their analysis to various audiences, including to senior and executive management.
- Demonstrated experience of excellent time management and organizational skills; ability to work on long-term strategies as well as day-to-day tasks.
- Demonstrated project management skills to plan and organize work, prioritize and work on multiple project-related activities simultaneously and effectively.
- You have demonstrated planning and organizational skills to manage concurrent projects and coordinate activities with clients, stakeholders and partners