Privacy Specialist and Business Support
Privacy Support Specialist:
- Prepare Privacy Impact Assessments (PIA)
- Provide privacy training
- Support privacy policy and procedures review
- Respond to privacy inquiries
- Support privacy breach reporting and case file management
- Conduct research and create reports
- Coordinate project management documentation
- Assist to develop and implement strategies to ensure the organization remains effective and sustainable
- Project Management Assistance
Communications Management
- Ensure employees are aware of and understand Calgary Foothills PCN policies and procedures on privacy, confidentiality, and release of information
- Support custodians within the Calgary Foothills PCN sites and programs to be aware of their responsibilities and duties under the Health Information Act (HIA)
- Inform the organization of relevant changes to privacy legislation and/or decisions or recommendations of the Alberta Office of the Information and Privacy Commissioner (OIPC) as necessary
- Developing relationships to liaise with external expertise as required such as, but not limited to legal counsel, the OIPC, and the Alberta Health Minister
- Initiate and promote activities to foster privacy and security awareness and compliance
- Create and maintain all necessary privacy-related agreements including information management agreements, information sharing agreements, data sharing agreements, confidentiality and vendor agreements, and Privacy Impact Assessments
Process/Risk Management
- In the process of working closely with the Executive Director, Medical Director, and Data Stewardship Committee of the Foothills Primary Care Physician Corporation to review decisions of, and recommendations from OIPC.
- Developing skills in effective privacy processes and documentation
- Maintain records of any concerns submitted about Calgary Foothills PCN’s privacy policies
- Monitor privacy compliance on an ongoing basis, including conducting and reviewing internal EMR and privacy audits
- Active participation in ongoing risk assessment
- When needed, prepare Privacy Impact Assessments (PIAs) and manage the submission and acceptance process with the OIPC
- Provide the board(s) with a quarterly privacy report
- Shape the organization’s operations to fit external realities (e.g., client demands, government legislation, costs and prices, competitive/community pressures)
- Identify new ideas, techniques, and opportunities for improving effectiveness and compliance
- Interested and learning the CFPCN audit process of EMR's and Netcare
- Develop risk mitigation strategies about privacy and data security requirements in compliance with relevant organizational and legislative requirements
Education/Training
- Develop and implement training and education initiatives to ensure all employees and relevant third parties are appropriately informed of their responsibilities related to information privacy and data security and are conducting business appropriately
- Enforce the organizations’ privacy standards to all levels of the organization
Breach Control Management/Strategy
- Develop, maintain and communicate a privacy breach control strategy
- Identify and mitigate potential breach circumstances within the organization
- Manage, investigate and document all reports of information privacy and data security violations and report, as appropriate, to the OIPC
- Respond to privacy-related breaches/incidences jointly with the appropriate custodian while cooperating with the OIPC and Health Minister in the event of an investigation
Records Management
- Create, manage and implement all necessary records management practices for the dissemination of personal health information and retention of organizational information within the PCN. - In the process of developing a records management process and finishing the Records Retention Schedule.
- Develop and implement a records management, the release of information, and health records retention strategy for the organization - in progress.
- Developed team communications and information for meetings
- Exceeded goals through effective task prioritization and great work ethic