The University of Arizona has been recognized for our innovative work-life programs. For more information about working at the University of Arizona and relocations services, please click here.
Duties & Responsibilities
HIPAA
Compliance Program:
- Coordinates program activities across departments and colleges designated as HIPAA Covered Components within the HIPAA Privacy Program.
- Participates in the annual review of HIPAA Covered Components and the annual HIPAA risk assessment process.
- Documents results of the annual assessments; tracks action items and remediation activities.
Vendor
Privacy Support:
- Coordinates the review and tracking of Business Associate Agreements; performs vendor privacy risk assessments; coordinates the Authorization to Operate process for certain applications storing or processing regulated data.
- Partners with cross-functional teams to ensure appropriate safeguards and documentation are in place.
Training
and Awareness Support:
- Supports privacy communication and training initiatives, including the development and updating of privacy training and marketing communications.
- Coordinates with human resources on training delivery, tracking, and reporting.
Privacy
Incident Intake and Investigation:
- Supports privacy incident response activities, including incident intake, investigation, documentation, issue tracking, and remediation.
- Prepares summary reports for presentation to senior management and other stakeholders.
Privacy
Program Support:
- Maintains current knowledge of applicable federal, state, and international privacy related laws, regulations, and accreditation standards.
- Supports the development, maintenance, and annual review of university privacy policies and procedures.
- Other Duties as Assigned.
Knowledge, Skills, and Abilities:
- Knowledge of privacy laws (e.g., GDPR, HIPAA) and compliance standards.
- Understanding of other key subjects including cyber security and risk management.
- Strong communication skills for articulating privacy risks and policies.
- Strong critical thinking skills and the ability to assess how state, federal, and international privacy requirements apply to specific situations.
- Strong interpersonal skills and a commitment to fostering productive, respectful partnerships across teams and roles.
- Ability to collaborate with stakeholders on privacy matters.
- Ability to develop and enforce privacy policies.
- Ability to meticulously review contracts and data access requests for privacy compliance.
- Ability to translate complex privacy concepts into practical, easy-to-understand guidance for a variety of audiences.
- Familiarity with HIPAA requirements, Business Associate Agreements, or other regulated-data environments.
- Demonstrated curiosity and willingness to learn new and often complex topics, including privacy, legal regulations, and information security.
This job posting reflects the general nature and level of work expected of the selected candidate(s). It is not intended to be an exhaustive list of all duties and responsibilities. The institution reserves the right to amend or update this description as organizational priorities and institutional needs evolve.
Minimum Qualifications
- Bachelor's degree or equivalent advanced learning attained through professional level experience required.
- Minimum of 3 years of relevant work experience, or equivalent combination of education and work experience.
Preferred Qualifications
- Experience in data privacy, business, information security, law, compliance, or a similar field
- Direct privacy experience is not required; relevant and transferable experience will be strongly considered for those with:
- Experience conducting or supporting investigations, incident response, audits, assessments, or other fact-finding activities
- Experience documenting findings, tracking remediation activities, and preparing clear reports for leadership and other stakeholders
- Experience coordinating projects or compliance activities across multiple departments
- Experience developing or delivering training, guidance, or communications for varied audiences
- Experience handling sensitive or confidential information with discretion and sound judgment
- Experience working in a higher education setting
- Certification from a relevant professional association, such as the International Association of Privacy Professionals (IAPP), Health Care Compliance Association (HCCA), or Information Systems Audit and Control Association (ISACA)
- Experience in privacy risk assessments and compliance monitoring.
FLSA: Exempt
Full Time/Part Time: Full Time
Number of Hours Worked per Week: 40
Job FTE: 1.0
Work Calendar: Fiscal
Job Category: Legal Compliance
Benefits Eligible: Yes - Full Benefits
Rate of Pay: $65,687 - $85,393
Compensation Type: salary at 1.0 full-time equivalency (FTE)
Grade
9
Compensation Guidance
The Rate of Pay Field represents the University of Arizona's good faith and reasonable estimate of the range of possible compensation at the time of posting. The University considers several factors when extending an offer, including but not limited to, the role and associated responsibilities, a candidate's work experience, education/training, key skills, and internal equity.
The Grade Range represent a full range of career compensation growth over time. The university offers compensation growth opportunities within its career architecture. To learn more about compensation, please review our Applicant Compensation Guide and our Total Rewards Calculator.
Career Stream and Level
PC2
Job Family
Compl & Regulatory Affairs
Job Function
Legal & Compliance
Type of criminal background check required: Name-based criminal background check (non-security sensitive)
Number of Vacancies: 1
Contact Information for Candidates
James "Jim" Lee,
jamesmlee2@arizona.edu
Open Until Filled: Yes
Documents Needed to Apply: Resume and Cover Letter
Notice of Availability of the Annual Security and Fire Safety Report
In compliance with the Jeanne Clery Campus Safety Act (Clery Act), each year the University of Arizona releases an Annual Security Report (ASR) for each of the University's campuses. These reports disclose information including Clery crime statistics for the previous three calendar years and policies, procedures, and programs the University uses to keep students and employees safe, including how to report crimes or other emergencies and resources for crime victims. As a campus with residential housing facilities, the Main Campus ASR also includes a combined Annual Fire Safety report with information on fire statistics and fire safety systems, policies, and procedures.
Paper copies of the Reports can be obtained by contacting the University Compliance Office at cleryact@arizona.edu.