Privacy Officer - Legal

Choctaw Nation of Oklahoma

$80K — $95K *
Legal & Accounting
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field such as Business Administration, Cybersecurity, or Healthcare Administration.
  • Five years of experience in privacy, compliance, and risk management.
  • Experience with privacy risk assessments and breach response activities.
  • Knowledge of HIPAA and federal/state privacy laws.
  • Strong analytical and leadership skills to influence organizational decisions.

Responsibilities

  • Direct daily operations of the Office of Privacy and ensure effective policy administration.
  • Oversee the organization's privacy compliance program and monitor adherence to regulatory requirements.
  • Lead risk management activities including assessments and breach response planning.
  • Advise on privacy governance and provide strategic guidance for compliance activities.
  • Cultivate a culture of privacy through training and awareness programs.
  • Manage privacy rights processes and data-sharing activities.
  • Collaborate with multiple departments to align privacy and security initiatives.

Benefits

  • Free gym membership
  • Free access to employee health clinic
  • Paid vacation/sick time
  • Medical, dental, and vision insurance
  • 401(K) with company match
  • College tuition reimbursement
  • Short-term and long-term disability coverage
  • Phased approach for earned wages access
  • Wellness programs that offer health insurance savings
  • Employee assistance program and resources for mental health issues.
Full Job Description
Job Description

Job Purpose or Objective(s): Provides strategic leadership and oversight of the organization's privacy and security program to ensure compliance, manage risk, protect information assets, and promote a culture of privacy, security, and accountability. The position provides strategic guidance to executive leadership and oversees the continuous improvement of privacy and security controls, processes, and services to support organizational objectives and regulatory requirements. You will report directly to the Executive Director of Legal.

Monday-Friday, 8:00am-4:30pm

Primary Tasks:
  1. Directs and manages the day-to-day operations of the Office of Privacy, ensuring effective administration of privacy policies, procedures, standards, and controls across the organization.
  2. You will oversee the organization's privacy compliance program and ensures continued adherence to applicable federal, state, Tribal, contractual, and regulatory privacy requirements through ongoing monitoring, assessments, and audits. Delivers metrics and executive reporting related to these activities.
  3. Leads privacy and information protection risk management activities, including risk assessments, compliance reviews, incident investigations, breach response, corrective action planning, and mitigation efforts.
  4. Serves as the organization's primary advisor on privacy governance and regulatory compliance matters and provides strategic guidance regarding information security governance, risk, and compliance activities.
  5. You will direct privacy awareness, education, and training programs to promote workforce understanding of privacy responsibilities and foster a culture of privacy, security, and accountability.
  6. Oversee privacy rights processes, information disclosure practices, data-sharing activities, contractual privacy requirements, business associate agreements, and third-party privacy controls.
  7. You will collaborate with Information Security, Compliance, Legal, Human Resources, Health Information Management, and operational leadership to ensure alignment of privacy, cybersecurity, data governance, and regulatory compliance initiatives.
  8. Develops and monitors departmental goals, objectives, budgets, staffing, performance metrics, and strategic initiatives to ensure effective operation and continuous improvement of the privacy and security program.
  9. Provides regular reports to executive leadership regarding privacy compliance, risk trends, incidents, regulatory changes, program effectiveness, and recommended improvements.
  10. Other duties may be assigned.


Requirements:
• Bachelor's degree in business administration, Information Systems, Healthcare Administration, Legal Studies, Public Administration, Cybersecurity, or related field.
• Five (5) years' experience working in privacy, compliance, information governance, risk management, healthcare operations, information security, or a related field.
• Experience conducting privacy risk assessments, compliance reviews, investigations, breach response activities, and corrective action planning.
• Experience developing, implementing, administering, and maintaining privacy policies, procedures, standards, and governance frameworks.
• Demonstrated knowledge of applicable federal, state, Tribal, and industry privacy laws and regulations.
• Demonstrated ability to collaborate across multiple business units and influence organizational decision-making.
• Experience leading enterprise governance, compliance, risk management, or cross-functional organizational initiatives.
• Strong analytical, investigative, communication, and leadership skills

Responsibilities

You will build a strategic and comprehensive privacy program that defines policies that allow privacy practices which minimize risk and ensure the confidentiality of protected health information (PHI), paper and electronic, across all media types. Ensure privacy forms and procedures are up-to-date.Collaborate with the information security officer to ensure understanding between security and privacy compliance programs including policies, investigations, and acts as a liaison to the information systems department.Establish with the information security officer, an ongoing process to track inappropriate access and disclosure of protected health information. Monitor patterns of inappropriate access and disclosure of protected health information.Work cooperatively with the Health Information Management (HIM) Director and other applicable organization units in overseeing patient rights to inspect access to protected health information.You will take a lead role, to ensure we have and maintain appropriate privacy and confidentiality consents, authorization forms and information notices and materials reflecting current organization and legal practices and requirements.Be information privacy resource to our organization regarding release of information and to all departments for all privacy related issues.Perform other tasks as assigned.

Qualifications

Bachelor's degree with Business Administration or related field or 4 years related experience.Knowledge of HIPAA and related Federal and State privacy laws and regulations.3+ years of experience in information access, release of information, and release control technologies.Skill in examining and re-engineering operations and procedures, formulating policy, and developing new strategies and procedures.4+ years of related experience.

Benefits
  • Free gym membership
  • Free access to employee health clinic
  • Free lunch for casino & resort associates
  • Earned wages access once per week for hourly Associates
  • Pet insurance
  • Paid vacation / sick time
  • Medical / Dental / Vision
  • 401(K) with company match
  • College tuition reimbursement
  • Short-term disability, long-term disability, and family leave
  • Employee assistance program
  • Employee prescription program
  • CNO Paid Life Insurance
  • Teladoc
  • On Site Dental Clinics (Jet Dental)
  • On Site Mammogram Services
  • Free diabetes and hypertension monitoring benefit (Livongo)
  • Accolade- Concierge Benefits Program
  • Wellness Program that equals savings on health insurance cost (Virgin Pulse)
  • Maternity Care Program
  • (Benefits provided by the Choctaw Nation are based on employment classification)

#LI-onsite

Similar Jobs

More Jobs at Choctaw Nation of Oklahoma

More Legal & Accounting Jobs

Find similar Privacy Officer - Legal jobs: