What are the responsibilities and job description for the PSO IT Security Specialist position at Novalink Solutions LLC?
NC DHHS - Privacy and Security Office (PSO) requiring services of an Electronic Health Record System IT Security lead to assist DSOHF.
The EHR Security Coordinator is responsible for overseeing and ensuring the security of the organization's Electronic Health Record (EHR) system. This role involves managing access controls, conducting security audits, developing security policies, and ensuring compliance with healthcare regulations such as HIPAA and HITECH. The EHR Security Coordinator will work closely with IT, clinical, and compliance teams to secure patient data and protect the integrity of the EHR system.
Key Responsibilities :
Security Management & Compliance :
- Ensure the EHR system is secure and compliant with federal, state, and organizational security policies, including HIPAA, HITECH, and other applicable regulations.
- Monitor and enforce the appropriate use of EHR access controls, ensuring that users have the correct level of access based on their roles.
- Conduct regular security audits of the EHR system, identifying and mitigating risks or vulnerabilities.
- Develop and maintain security policies, procedures, and guidelines specific to the EHR environment.
- Coordinate with the stakeholders to implement and maintain security tools, such as firewalls, intrusion detection / prevention systems, and encryption mechanisms, as applicable to the EHR system.
Access Controls & User Management :
Incident Response & Risk Management :
Collaboration & Coordination :
Continuous Improvement :
Qualifications : Education :
Experience :
Skills :
Working Conditions :
Requirements
Skill
Required / Desired
Amount
of Experience
Ability to manage security incidents and respond to them efficiently.
Required
Years
Risk Management - must be able to Identify gaps through risk management, and assist in the development of mitigation strategies.
Required
Years
5-7 years of experience in IT security, preferably within the healthcare industry.
Required
Years
Experience updating privacy and security policies based on gaps found through an assessment process.
Required
Years
Experience Performing risk assessments based on NIST 800-53 Rev 4. HIPAA,SSA and IRS Pub 1075.
Required
Years
Knowledge of role-based access control (RBAC), identity management, and data encryption as it relates to healthcare information systems.
Required
Years
Proficient in healthcare regulations and standards, including HIPAA, HITECH, and meaningful use.
Required
Years
Excellent problem-solving and analytical skills.
Required
Years
Experience documenting vulnerability assessment results in a accurate, clear, actionable, and available way to appropriate personnel
Required
Years
Familiarity with healthcare IT infrastructure, including networking, firewalls, and database security.
Required
Years
Strong communication skills, capable of working across departments and with clinical teams.
Required
Years