Identify Electronic Protected Health Information (ePHI): Locate all systems holding sensitive data
Identify Threats and Vulnerabilities: Determine potential, reasonably anticipated threats
Assess Security Measures: Evaluate current safeguards
Determine Likelihood and Impact: Evaluate the probability and impact of potential breaches
Document and Prioritize Findings: Create the formal report and risk mitigation plan
Requirements
5+ years of experience with HIPAA Assessments and Reporting
5+ years of experience with HIPAA guidelines, such as: NIST Special Publication 800-66 Rev. 2, NIST Cyber Security Framework to HIPAA Security Rule Crosswalk, HITRUST
Hands-on experience conducting privacy assessments / audits, PIA / DPIA
Strong understanding of data flows & data lifecycle, user data handling in web/mobile applications
Experience reviewing consumer-facing systems (apps, websites), consent, transparency, and privacy controls
Ability to translate regulations into practical findings and recommendations