Source Code logo
Source CodePosted 1 month ago

RQ00514 - Sr. Privacy Impact Assessment (PIA) Specialist

On-siteToronto, Ontario, Canada

Full TimeSenior LevelMedium

Job Summary

Conduct Privacy Threshold Assessments and Privacy Impact Assessments for complex IT initiatives, including provincial Electronic Health Record projects. Develop privacy policies, risk mitigation plans, and data flow diagrams while advising on data sharing agreements. Investigate privacy incidents and respond to access requests under PHIPA and FIPPA. Lead and participate in agency committees as the privacy Subject Matter Expert, delivering training and fostering stakeholder relationships. Support privacy program projects to improve the Privacy Office's efficiency.

Required Qualifications

  • Minimum of 5 years of health privacy experience conducting privacy impact assessments on medium to high complexity projects
  • Minimum 5 years of experience developing privacy policies and procedures, requirements or controls
  • Experience with the Personal Health Information Protection Act, 2004 (PHIPA), including requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP)
  • Holds an undergraduate or graduate degree in health, policy, IT, security, law or a related discipline

Desired Qualifications

  • Completion of a university undergraduate or masters degree in health, policy, IT, security, law or a related discipline
  • Recognized security certification or designation is an asset
  • Experience working with prescribed statuses is considered an asset
  • Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements
  • Knowledge and ability to interpret Ontarios Personal Health Information Protection Act, 2004 (PHIPA)
  • Knowledge and ability to interpret Ontarios Freedom of Information and Protection of Privacy Act (FIPPA)
  • Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiatives
  • Thorough understanding of privacy-by-design and best practices
  • Experience with conducting and/or providing oversight for Privacy Impact Assessments and Privacy Threshold Assessments, including developing privacy requirements, risk mitigation plans, corporate policies and developing and/or delivering training content
  • Knowledge of technology architecture and infrastructure, digital health solutions and services, enterprise and corporate IT including information and cyber security preferred
  • Working knowledge of digital health technologies and information security industry standards
  • Excel in a fast-paced and project focused environment
  • Exceptional analytic and creative problem-solving abilities
  • Good understanding of related disciplines, such as IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management
  • Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows
  • Excellent Communication skills both verbal and written, and strong stakeholder engagement skills
  • Time Management, with the ability to manage tight deadlines and prioritize multiple projects

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce