Fresenius Medical Care

HIPAA Privacy Officer

Fresenius Medical Care$97K — $163K *
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required; preferred in Health Information Management, Healthcare Administration, or Law
  • 8-10 years of experience in privacy, compliance, or healthcare regulatory roles
  • Demonstrated expertise in HIPAA Privacy Rule requirements
  • Experience in clinical, operational, and IT environments providing privacy guidance
  • Ability to translate regulatory requirements into actionable solutions
  • Strong understanding of healthcare workflows and PHI data flows
  • Excellent communication skills for presenting complex concepts

Responsibilities

  • Serve as the enterprise HIPAA Privacy Officer for U.S. operations
  • Advise teams on handling and disclosure of PHI while identifying privacy risks
  • Develop and maintain privacy policies and procedures to meet HIPAA requirements
  • Support breach assessments and ensure timely incident responses
  • Collaborate with legal counsel on privacy complaints and investigations
  • Review project designs to ensure alignment with privacy requirements
  • Drive integration of privacy-by-design principles into operations

Benefits

  • Comprehensive medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off and parental leave
  • Potential for performance-based bonuses
  • Flexible working conditions, including potential for remote work and travel as needed
Full Job Description
PRINCIPAL DUTIES AND RESPONSIBILITIES:
  • Serves as the enterprise HIPAA Privacy Officer for U.S. operations, responsible for interpretation, application, and oversight of HIPAA Privacy Rule requirements across the organization.
  • Provides day-to-day guidance and subject matter expertise on HIPAA compliance across operational changes, initiatives, and projects of varying size and complexity.
  • Advises business, clinical, and IT teams on appropriate handling, use, and disclosure of PHI, including identification and mitigation of privacy risks.
  • Partners closely with Governance, Risk & Compliance (GRC) to:
    • Develop and maintain Privacy Policies, standards, and procedures that meet HIPAA requirements
    • Ensure HIPAA controls are defined, implemented, and monitored
    • Align privacy requirements with broader regulatory and control frameworks
    • Support reviews of third party vendors for compliance with HIPAA
    • Support audits, assessments, and regulatory inquiries
  • Collaborates with Cyber & Privacy Operations during privacy incidents to:
    • Support breach assessment and risk analysis
    • Ensure timely escalation, containment, and notification decisions
    • Contribute to post-incident remediation and continuous improvement efforts
    • Develop standard operating procedures (SOPs)
    • Develop and deliver training on PHI policies and procedures.
  • Works in close partnership with U.S. Privacy Legal Counsel to:
    • Assess regulatory requirements and enforcement expectations
    • Serve as primary point of contact for privacy complaints, investigations, breach risk assessments, and regulatory inquiries
    • Ensure alignment of operational practices with legal obligations
    • Support development and maintenance of privacy policies and notices
  • Reviews and provides input on project designs, system implementations, workflows, and process changes to ensure alignment with HIPAA and organizational privacy requirements.
  • Drives the integration of privacy-by-design principles into clinic operations and enterprise processes, ensuring sustainable and scalable compliance.
  • Maintain documentation required to demonstrate HIPAA compliance, including overseeing requests for access, amendments, restrictions, and confidential communications for patient medical records; and ensuring timely response and appropriate denials and approvals.
  • Develops practical, scalable self-service tools, templates, and guidance to enable teams to independently address routine privacy requirements.
  • Partners with clinical and operational leaders to ensure HIPAA requirements are consistently and effectively executed in day-to-day clinic and physician practices' operations.
  • Supports awareness and training efforts to promote understanding of privacy responsibilities across workforce members.
  • Participates in internal and external meetings, including regulatory, audit, and compliance forums, representing the organization's HIPAA privacy posture.

PHYSICAL DEMANDS AND WORKING CONDITIONS:
  • The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
  • Travel required per business need.


EDUCATION:
  • Bachelor's Degree required; degree in a related discipline such as Health Information Management, Healthcare Administration, or Law preferred


EXPERIENCE AND REQUIRED SKILLS:
  • 8-10 years of experience in privacy, compliance, or healthcare regulatory roles
  • Demonstrated expertise in HIPAA Privacy Rule requirements and real-world application in healthcare operations
  • Experience supporting clinical, operational, and IT environments with privacy guidance
  • Proven ability to translate regulatory requirements into actionable, business-friendly solutions
  • Strong experience working cross-functionally with Legal, Compliance, Security, and operational stakeholders
  • Experience supporting privacy incident response and breach risk assessments
  • Strong understanding of healthcare workflows, PHI data flows, and regulatory risk
  • Excellent communication skills, with the ability to present complex privacy concepts to non-technical and executive audiences
  • Strong analytical, problem-solving, and decision-making capabilities
  • High attention to detail and ability to operate in a fast-paced, evolving environment

PREFERRED CERTIFICATIONS / DESIGNATIONS:
  • Certified in Healthcare Privacy Compliance (CHPC) - HCCA
  • Certified Information Privacy Professional (CIPP/US or CIPP/E) - IAPP
  • Certified Information Privacy Manager (CIPM) - IAPP


The rate of pay for this position will depend on the successful candidate's work location and qualifications, including relevant education, work experience, skills, and competencies.

Annual Rate: $97,000.00 - $163,000.00

Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave and potential for performance-based bonuses depending on company and individual performance.

About Fresenius Medical Care

Fresenius Medical Care is a German company specializing in the production of medical supplies, primarily to facilitate or aid renal dialysis. The company is a leading provider of products and services for people with chronic kidney failure. Fresenius Medical Care operates in more than 120 countries and has over 120,000 employees. The company's products and services are used to treat approximately 3.4 million patients worldwide. The company is committed to improving the quality of life of patients with kidney disease and to providing innovative products and services that meet the needs of patients and healthcare professionals.
Learn more about Fresenius Medical Care
Size
122,635 employees
Market Cap
$9.2 billion
Industry
Net Income
$1.1 billion
Founded
1996
Revenue
$17.8 billion
NASDAQ

Similar Jobs

More Jobs at Fresenius Medical Care

More Healthcare Jobs

Find similar HIPAA Privacy Officer jobs: