Deliverables include, but are not limited to :
- Conducting / Completing Privacy Impact Assessments and associated documentation
- Providing Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiatives
- Developing risk mitigation plans
- Create or inform the creation of data flow diagrams and associated privacy controls and compliance requirements
- Reviewing and advising on agreements, including data sharing agreements
- Developing privacy requirements for new or changing projects
Responsibilities :
Conducting / Completing Privacy Impact Assessments and associated documentationProviding Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiativesIdentify and assess privacy risks, including developing risk mitigation plansCreate or inform the creation of data flow diagrams and associated privacy controls and compliance requirementsReviewing and advising on agreements, including data sharing agreementsDeveloping privacy requirements for new or changing projectsProviding privacy advisory and support to business teamsOther duties as requiredDesired Skills :
Demonstrable knowledge of project management; Knowledge and understanding of Project Management’s Institute’s Project Management Body of Knowledge is an assetExperience working on and delivering multiple projectsDemonstrated project management software skills and experience e.g. MS Project, MS Teams etc.University undergraduate or graduate degree in Health, Computer Science, Engineering, Law, Security, or a related discipline from a recognized institution or equivalent experience – desiredFamiliarity with Prescribed Organization (PO), Prescribed Entities (PEs) or Prescribed Persons (PP) requirements under the Personal Health Information Protection Act (PHIPA), and their related requirements, is an assetFamiliarity with audit logging and Security Information and Event Management (SIEM) technology is an assetFamiliarity with technical data protection controls and technology such as encryption and tokenization is an assetKnowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards is an assetExperience and Skill Set Requirements :
Evaluation Criteria :
1 : Minimum 5 years’ health privacy experience conducting privacy impact a3ssessments (PIAs) on medium to high complexity projects. 20 Points
2 : Minimum 5 years’ direct operational level privacy experience in a health sector and / or IT environment or both. 20 Points
3 : Minimum 5 years’ experience in developing privacy policies and procedures, requirements, or controls. 20 Points
4 : Minimum 5 years’ experience drafting and reviewing privacy requirements for data sharing agreements. 15 Points
5 : Familiarity with the Personal Health Information Protection Act (PHIPA), and requirements related to Prescribed Organization, Prescribed Entity, Health Information Network Provider (HINP) and / or Electronic Service Provider (ESP) . 15 Points
6 : Familiarity with Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure, design, and data flows. 10 Points
Must haves :
Minimum of 3 years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projectsMinimum 5 years’ direct operational level privacy experience preferably in a health sector and / or IT environment or bothMinimum 5 years and #x27; experience drafting and reviewing privacy requirements for data sharing agreementsMinimum 5 years’ experience developing privacy policies and procedures, requirements, or controlsFamiliarity with the Personal Health Information Protection Act (PHIPA), and its related requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP)Familiarity with Application Programming Interface (API) functionality and managementFamiliarity with Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure, design, and data flows