Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailHeres the updated job description reflecting that the role is fully remote rather than hybrid:
Job Title: Privacy Impact Assessment (PIA) Specialist Senior
About Ontario Health
Ontario Health was established pursuant to The Connecting Care Act 2019 with objectives that include implementing the health strategies of the Ministry of Health and managing health service needs across Ontario in alignment with those strategies. More details on Ontario Health its mandate and objectives can be found at: Ontario Health Agency.
Background Information
Ontario Health is seeking a Senior Privacy (PIA) Specialist to support privacy matters across key Information Technology projects including:
Patients Before Paperwork (PB4P) initiatives
Enterprise products & services
Business intelligence tools
Cloud migration
The Privacy Specialist will ensure compliance with legal and contractual obligations while integrating privacy into the design of projects handling personal health information (PHI). The role helps mitigate privacy risks and upholds the trust and confidentiality of individuals whose PHI is managed by Ontario Health.
Key Responsibilities
Conduct and complete Privacy Impact Assessments (PIAs) with associated documentation.
Provide privacy consultation on complex multistakeholder health privacy issues and IT initiatives.
Identify and assess privacy risks developing risk mitigation strategies.
Create or contribute to the creation of data flow diagrams privacy controls and compliance requirements.
Review and advise on agreements including datasharing agreements.
Develop privacy requirements for new and evolving projects.
Offer privacy advisory and support to business teams.
Perform additional duties as required.
MustHave Qualifications
3 years of experience conducting privacy impact assessments (PIAs) on medium to high complexity projects.
5 years of direct operationallevel privacy experience in a healthcare or IT setting.
5 years of experience drafting and reviewing privacy requirements for datasharing agreements.
5 years of experience developing privacy policies procedures requirements or controls.
Familiarity with the Personal Health Information Protection Act (PHIPA) and its requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP).
Understanding of Application Programming Interface (API) functionality and management.
Knowledge of Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure design and data flows.
Desired Skills
Knowledge of project management methodologies including PMIs Project Management Body of Knowledge (PMBOK).
Ability to work on and deliver multiple projects effectively.
Proficiency in project management tools (e.g. MS Project MS Teams).
University degree in Health Computer Science Engineering Law Security or a related discipline (or equivalent experience).
Familiarity with Prescribed Entities (PEs) or Prescribed Persons (PP) under PHIPA.
Experience with audit logging and Security Information and Event Management (SIEM) technologies.
Knowledge of data protection measures such as encryption and tokenization.
Understanding of the Accessibility for Ontarians with Disabilities Act (AODA) and related standards.
Deliverables
Provide ongoing support for existing and new Privacy Impact Assessments.
Work with project and product teams on risk mitigation strategies per PHIPA requirements.
Assist in updating and developing new privacy agreements.
Contribute key privacyrelated insights and recommendations to ensure compliance and best practices.
Conduct demos and walkthroughs of project components before engagement completion.
Ensure thorough knowledge transfer to Ontario Health teams.
Additional Terms
The position is remote.
Ontario Health assets (such as laptops) must remain within Ontario unless prior written approval is granted.
The candidate must collaborate with Ontario Health teams to ensure documentation milestones and deliverables are shared in an approved format.
Full Time