Privacy Impact Assessment (PIA) Specialist - Senior
SUMMARY
Ontario Health seeks a Senior Privacy (PIA) Specialist to lead privacy initiatives in home and community care, including Ontario Health Team deployment. The role involves conducting Privacy Impact Assessments (PIAs), developing policies, assessing privacy risks, and advising on compliance with the Personal Health Information Protection Act (PHIPA). Candidates should have over 5 years of operational privacy experience, preferably in health or IT sectors, and expertise in drafting privacy requirements for data sharing agreements. Strong knowledge of PHIPA, Health Information Network Providers (HINP), and Electronic Service Providers (ESP) requirements is essential. The position is hybrid, offering both onsite and remote work options.Description

Background Information

The purpose of this procurement of a Senior Privacy (PIA) Specialist is to acquire a contingent resource to act as a dedicated privacy subject matter expert to assist with supporting privacy matters related home and community care, including Ontario Health Team (OHT) deployment.

Ontario Health is seeking a Privacy resource to ensure that Ontario Health maintains compliance with its legal and contractual privacy obligations, and builds privacy into the design of projects that involve personal health information (PHI), thus reducing risk for the organization and protecting the trust and privacy of individuals whose PHI we manage.

Must haves:

·      Minimum of 3 years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects        

·      Minimum 5 years’ direct operational level privacy experience preferably in a health sector and/or IT environment

·      Minimum 5 years' experience drafting and reviewing privacy requirements for data sharing agreements

·      Familiarity with the Personal Health Information Protection Act (PHIPA), and it’s related requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP)

Responsibilities:

·      Develop privacy policies and procedures

·      Conduct privacy impact assessments for medium to high complex initiatives and/or implement mitigations activities in response to recommendations from PIAs

·      Identify and assess privacy risks

·      Provide privacy advisory and support to business teams

·      Lead and/or participate on Ontario Health, regional or provincial committees or project teams as the privacy Subject Matter Expert (SME)

·      Identify privacy requirements

·      Develop strong relationships with various internal and external stakeholders to foster a culture of privacy

·      Respond and provide advice and legislative interpretation for information and access requests, consent management requests, complaints, or inquiries, appeals and privacy issues under the PHIPA                             

·      Support privacy program projects and activities to improve the efficiency and effectiveness of the Privacy Office

·      Other duties as required

 

 

Desired Skills:

·      Completion of a university undergraduate or master’s degree in health, policy, IT, security, law or a related discipline

·      Demonstrated knowledge and experience of access and privacy requirements and practices, preferably related to the health and public sectors

·      Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements

·      Knowledge and ability to interpret of Ontario’s Personal Health Information Protection Act, 2004 (PHIPA)

·      Knowledge and ability to interpret Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA)

·      Analytical skills to understand the current and future access and privacy implications of policies, decisions, and business initiatives        

·      Experience with conducting and/or providing oversight for Privacy Impact Assessments including developing privacy requirements, risk mitigation plans, corporate policies and developing and/or delivering training content

·      Working knowledge of digital health technologies and information security industry standards

·      Excel in a fast-paced and project focused environment

·      Exceptional analytic and creative problem-solving abilities

·      Good understanding of related disciplines, such as IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management

·      Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows

·      Excellent communication skills both verbal and written, and strong stakeholder engagement skills

·      Time management, with the ability to manage tight deadlines and prioritize multiple projects   

 Required Experience / Evaluation Criteria:  

• Minimum of 3 years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects: 20 pts

• Minimum 5 years’ direct operational level privacy experience preferably in a health sector and/or IT environments: 20 pts

• Minimum 5 years' experience drafting and reviewing privacy requirements for data sharing agreements: 20 pts

• Minimum 5 years’ experience developing privacy policies and procedures, requirements, or controls: 20 pts

• Familiarity with the Personal Health Information Protection Act (PHIPA), and it’s related requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP): 20 pts

Total Capabilities Criteria: 100 Points

 

 

Deliverables

 Deliverables:

·      Over the duration of the engagement, the Senior Privacy (PIA) Specialist will support work already in progress to implement mitigations plans in response to open PIAs related to home and community care, and the Client and Related Health Information System (CHRIS) that supports this sector;

·      Support development of risk assessments and identification of other privacy considerations related to OHT deployment and transfer of records;

·      Work with the project and product teams and/or CHRIS tenants on risk mitigation of PIA findings as required under PHIPA;

·      Develop policies and procedures to support CHRIS use for home and community care modernization;

·      Support work related to update and/or developing new agreements;

·      Support onboarding and analysis of privacy readiness assessments;

·      Support development of governance models to support ongoing CHRIS privacy operations/collaboration with OHTs;

·      Knowledge of current policy/legislation will be critical to ensure that we are collecting the relevant information.

Deliverables include:

·      Conducting/Completing Privacy Impact Assessments and associated documentation

·      Providing Privacy consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiatives related to home and community care modernization and OHT deployment

·      Developing risk mitigation plans

·      Create or inform the creation of data flow diagrams and associated privacy controls and compliance requirements

·      Reviewing and advising on agreements, including data sharing agreements

·      Developing privacy requirements for new or changing projects

Additional Terms

Term: The term of this position is 188 Business Days, with an option to extend for an additional 1 year, at Ontario Health's discretion.

Ontario Health assets including laptops and related equipment cannot be removed from the province of Ontario without prior written approval from Ontario Health.

The resource will comply with Ontario Health policies and procedures.

Assignment Type: This position is currently listed as "Hybrid". The resource under this request will be required to work onsite as per Hiring Manager sole discretion.

Ontario Health assets including laptops and related equipment cannot be removed from the province of Ontario without prior written approval from Ontario Health.

Knowledge Transfer Details:

• The resource will ensure full knowledge transfer is provided to the Ontario Health team before end of engagement. Some of this might occur at the end of the engagement but will also be shared as information is obtained/consolidated. Key deliverables will be shared with team.

• The resource must provide all related documentation as part of knowledge transfer protocol. Documents will be reviewed by the appropriate leads and signed off by manager/director.

• The resource will work collaboratively with the Ontario Health team throughout the assignment and ensure key deliverables, milestones, and documentation are shared.

• A walkthrough of any demos, development, etc. will be required before the end of the engagement.

Supplier Comments

MSP Notes

Must Haves:

·             Minimum of 3 years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects        

·       ·      Minimum 5 years’ direct operational level privacy experience preferably in a health sector and/or IT environment

·       ·      Minimum 5 years' experience drafting and reviewing privacy requirements for data sharing agreements

·       Familiarity with the Personal Health Information Protection Act (PHIPA), and it’s related requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP)

 

 

 

Location: Remote

Public Sector Experience: Yes

# of submissions/supplier: 1