Director, Privacy Office (Remote Eligible)
Vanderbilt University Medical CenterAbout the role
Discover Vanderbilt University Medical Center: Located in Nashville, Tennessee, and operating at a global crossroads of teaching, discovery, and patient care, VUMC is a community of individuals who come to work each day with the simple aim of changing the world. It is a place where your expertise will be valued, your knowledge expanded, and your abilities challenged. Vanderbilt Health is committed to an environment where everyone has the chance to thrive and where your uniqueness is sought and celebrated. It is a place where employees know they are part of something that is bigger than themselves, take exceptional pride in their work and never settle for what was good enough yesterday. Vanderbilt’s mission is to advance health and wellness through preeminent programs in patient care, education, and research.
Organization:
Privacy OfficeJob Summary:
Vanderbilt Health - Executive Search Team is conducting a national search for a Director, Privacy Office.The Director, Privacy Office provides leadership for the Privacy Office by developing goals, objectives, policies and procedures; supervising, coordinating, and evaluating the activities; preparing operating and capital expenditure budgets; and performing personnel administration functions. Lead the work processes for the development and deployment of privacy and information security policies and processes; new hire and annual HIPAA/Privacy training materials for staff, house staff, students, and faculty; and provide consultative services to other departments regarding application of the principles and policies of privacy and information security in the way work is done across the organization.
Department Summary
The Privacy Office is responsible for the oversight of HIPAA compliance for the Vanderbilt Affiliated Covered Entity. As VUMC continues to grow its patient volume and expand services geographically, the efforts to maintain organizational compliance with patient privacy regulations including HIPAA increase. In FY25, the team responded to over 2200 privacy matters including patient privacy rights requests, requests from staff for guidance, breach investigations and notifications, and requests for information related to privacy complaints files with the HHS Office for Civil Rights.
The Director role is critical for these efforts, program oversight, and daily management of regulatory activities performed by the Privacy Office team. This role provides leadership for the Privacy Office by developing goals, objectives, policies and procedures; supervising, coordinating, and evaluating daily activities. This role leads the work processes for the development and deployment of privacy and information security policies and processes; new hire and annual HIPAA/Privacy training materials for staff, house staff, students, and faculty; leads complex privacy investigations and VUMC’s breach incident response, provides consultative services to departments regarding application of principles and policies of privacy and information security, and responds to external regulatory inquiries and investigations.
.
Key Responsibilities:
- Develop goals, objectives, work plans, and priorities for the Privacy Office based on strategies and priorities defined by the Information Privacy and Security Executive Committee and the Chief Patient Experience and Service Officer.
- Define and secure approval for objectives and work plans to achieve institutional and departmental objectives and priorities.
- Ensure that the functions and processes required by federal and state laws and other regulatory agencies related to privacy and confidentiality of patient and other sensitive personal information are in place and compliant.
- Facilitate inter-departmental input, evaluation and participation in developing and implementing enterprise-wide policies and processes.
- Initiate changes in or develop new policies, procedures and/or methods.
- Analyze long-range impact of decisions and plans.
- Recommend and revise policies related to privacy and information security to promote compliance with federal and state laws and regulations, as well as VUMC strategies and priorities.
- Lead multi-disciplinary teams and work groups across the enterprise in the design of work flow processes and the development of proposed policy related to privacy and/or information security.
- Ensure processes related to receiving, investigating, responding to, and mitigating patient complaints and privacy breaches are compliant with regulatory and policy requirements and are documented according to standards and policies.
- Participates in and lead efforts to assure the consistent application of the Sanctions Policy to incidents determined to be a violation of privacy and information security policy.
- Author polic
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s