Director, PrivacyDepartment: Administration
Location: Dallas, Texas
Shift: Monday through Friday
Work Arrangement: Hybrid (Texas residency required)
Position Summary The Director of Privacy is responsible for managing the daily operations of the Children's Health System of Texas (CHST) Privacy Program, ensuring consistent execution of privacy initiatives across the organization. This position reports directly to the VP, Chief Privacy Officer (CPO), who retains primary oversight of the Privacy Program. Under the CPO's direction, the Director carries out operational responsibilities, manages Privacy Team activities and supports strategic initiatives. The Director serves as a key partner to the CPO, ensuring that privacy goals are met and that program activities are executed effectively and in alignment with regulatory expectations and organizational priorities.
The Director also provides leadership for privacy operations, investigations, team development, and process improvement initiatives and serves as a trusted delegate to the CPO as needed.
Responsibilities include: - In collaboration with the CPO, develops, oversees and maintains a Privacy Program that continually analyzes the changing regulatory environment and CHST operational goals and objectives to maximize the effectiveness of privacy compliance activities across the System.
- Manage daily operations of the Privacy Program under the direction of the CPO, including staff supervision, team development, performance management, and workflow coordination.
- Provide leadership, coaching, and support to Privacy Program staff, assessing team capabilities and identifying opportunities for professional development and operational effectiveness.
- Execute network-wide privacy initiatives in alignment with CPO directives.
- Maintain and ensure consistent application of privacy policies, HIPAA manuals and governance documents across the network.
- Collaborate with the CPO to draft, revise and update privacy policies and related documentation in alignment with developing regulations.
- Design and deliver privacy training programs for staff, faculty, medical staff and new employees.
- Promote privacy awareness in accordance with the CPO's strategic goals.
- Conduct and oversee investigations into privacy incidents, breaches and allegations of inappropriate access, use or disclosure of protected information.
- Maintain incident logs, prepare summaries and assist with breach notification and corrective action planning.
- Execute privacy risk assessments and targeted audits under CPO oversight.
- Evaluate privacy investigation workflows, identify process inefficiencies and delays, and recommend operational improvements that enhance quality, consistency and regulatory compliance.
- Partner with the CPO to identify high-risk areas, propose mitigation strategies and support reporting to leadership and regulatory agencies.
- Monitor privacy compliance trends and assist in evaluating internal practices.
- Prepare documentation and reports for submission to regulatory authorities during audits and investigations.
- Collaborate with Legal, IT and Cybersecurity teams to implement privacy controls and monitor HIPAA Security Rule compliance.
- Partner directly with clinical, operational and administrative business units to review requests involving data use cases and the use of emerging technologies, including Artificial Intelligence, that involve Personally Identifiable Information (PII), Protected Health Information (PHI), research data and sensitive organizational data. Analyze proposed uses to understand project scope, source and flow of data, and conduct comprehensive privacy risk assessments to identify risks prior to project implementation. Provide business units with actionable remediation strategies and alternative data handling approaches to support compliance with state and federal privacy regulations and organizational policies.
- Partner with Compliance, department heads and senior management to implement privacy initiatives under the CPO's leadership.
- Represent the Privacy Program on internal committees and cross-functional projects as delegated by the CPO.
- Serve as a delegate for the CPO as appropriate, providing guidance, leadership and decision support on privacy-related matters.
- Ensure privacy protections are embedded within technological systems in collaboration with IT and Information Systems teams.
- Track program performance metrics and analyze trends in privacy incidents and training outcomes.
- Recommend operational improvements for CPO review and approval.
Required Qualifications and Experience- At least seven (7) years of extensive experience in the practical application of state and federal privacy regulations, with three (3) to five (5) years of experience in an academic medical center or multi-organizational health system.
- Demonstrated knowledge and successful implementation of the elements of an effective privacy/compliance program, including policy and procedure development, training program development and delivery, risk assessment and auditing/monitoring processes, and appropriate and effective investigation processes.
- Experience with electronic health record (EHR/EMR) systems and healthcare privacy/compliance technologies, including Epic, Compliance 360, NAVEX (EthicsPoint), or comparable governance, risk, compliance and incident management platforms.
- Extensive knowledge of HIPAA, state privacy laws, information blocking requirements and 42 CFR Part 2 regulations.
- Four-year Bachelor's degree or equivalent experience.
- Graduate or professional degree or equivalent experience preferred.
- Certified in Healthcare Privacy Compliance (CHPC) or equivalent.
- Certified in Healthcare Compliance (CHC) or equivalent.
- International Association of Privacy Professionals (IAPP) certification, such as Certified Information Privacy Professional/United States (CIPP/US), Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT), or Artificial Intelligence Governance Professional (AIGP), preferred.
Schedule & Work Location- This is a full-time hybrid position working Monday through Friday from 8:00 a.m. to 5:00 p.m.
- You may be required to travel occasionally to other Children's Health locations including Dallas, Plano and Texas Health Dallas Clinics. Start time flexibility may be discussed during the interview process.
Holistic Benefits - How We'll Care for You- Employee portion of medical plan premiums are covered after 3 years
- 4%-10% employee savings plan match based on tenure
- Paid Parental Leave (up to 12 weeks)
- Caregiver Leave
- Adoption and surrogacy reimbursement