Overview
HIPAA Compliance Officer Jobs in Chicago, IL at Heuristic Quest HeadQuarters (HQ2)
Heuristic Quest HeadQuarters (HQ2)HIPAA Compliance Officer Job Description
Position Title: HIPAA Compliance Officer
Employment Status: Part-Time, W-2, Grant-Funded, Nonexempt
Reports To: Executive Director/Program Director
Work Arrangement: Hybrid; remote, office-based, and on-site work as assigned
Compensation and Hour Limitations
- HIPAA compliance work: $40.00 per hour
- Required meetings: $30.00 per hour
- Initial orientation and training: $25.00 per hour
- Average recurring hours: Approximately 12.5 hours per month
- Maximum recurring hours: 13 hours per month without prior written approval
- Orientation allowance: Up to 30 additional one-time hours
- Maximum annual hours: 180 hours, including orientation
Authorized hours are maximum limits and are not guaranteed minimums. The employee may not exceed the approved monthly, annual, or work-category limits without prior written authorization from the Executive Director or Program Director.
Position Summary
The HIPAA Compliance Officer provides privacy, security, and confidentiality oversight for HQ2’s behavioral health, substance use, telehealth, electronic health record, and technology operations. The position helps ensure compliance with HIPAA, the HITECH Act, 42 CFR Part 2, grant requirements, and HQ2 policies.
The Officer must be able to work independently, identify compliance risks, recommend corrective actions, maintain required documentation, and collaborate with leadership, clinical staff, technology staff, vendors, and workforce members.
Primary Responsibilities
- Conduct HIPAA privacy and security risk assessments and compliance reviews.
- Review telehealth, EHR, Microsoft 365, device, network, remote-access, and information-sharing practices.
- Identify privacy, security, confidentiality, and documentation deficiencies.
- Develop corrective-action recommendations and monitor completion.
- Create, review, and update HIPAA, privacy, security, breach-response, telehealth, and confidentiality policies.
- Support compliance with 42 CFR Part 2 requirements for substance use disorder records.
- Review user-access procedures, minimum-necessary access, password controls, multifactor authentication, device security, backups, logging, and secure communications.
- Review business associate agreements and vendor compliance documentation.
- Assist with privacy complaints, suspected breaches, security incidents, investigations, and required response documentation.
- Provide HIPAA orientation, workforce education, and required annual training.
- Maintain training records, risk-assessment records, audit findings, corrective-action plans, incident logs, and compliance reports.
- Advise leadership regarding compliance risks, policy enforcement, and required corrective action.
- Participate in approved grant meetings, compliance meetings, audits, and technical-assistance activities.
- Coordinate with the Technology Manager, Clinical Coordinator, Data Manager, and other staff regarding privacy and security requirements.
- Complete required reports, deliverables, timesheets, and grant documentation accurately and on time.
Qualifications
- Bachelor’s degree in healthcare administration, health information management, cybersecurity, compliance, law, business, behavioral health, or a related field preferred.
- Relevant HIPAA privacy, security, healthcare compliance, information security, audit, or risk-management experience required.
- Knowledge of HIPAA Privacy, Security, and Breach Notification Rules.
- Knowledge of 42 CFR Part 2 strongly preferred.
- Experience with behavioral health, substance use services, telehealth, electronic health records, or healthcare technology preferred.
- Ability to conduct assessments, interpret regulations, prepare written findings, and recommend practical corrective actions.
- Strong documentation, communication, training, organization, and independent follow-through skills.
- Appropriate HIPAA, privacy, security, compliance, auditing, or health-information certification preferred.
Work-Hour Requirements
The recurring budget includes:
- Up to 98 annual hours for compliance duties at $40.00 per hour.
- Up to 52 annual meeting hours at $30.00 per hour.
- Up to 30 one-time orientation and training hours at $25.00 per hour.
All time worked must be accurately recorded under the correct work category. Preparation, research, documentation, training, meetings, and follow-up work count as compensable time and must remain within approved limits.
Continued employment and assigned hours depend on available grant funding, satisfactory performance, organizational need, and timely completion of required deliverables.
Job Types: Part-time, Contract, Temporary
Pay: $40.00 per hour
Benefits:
- Flexible schedule
Work Location: In person
Title: HIPAA Compliance Officer
Company: Heuristic Quest HeadQuarters (HQ2)
Location: Chicago, IL
Category: