Posted:
2/22/2026, 4:00:00 PM
Location(s):
Massachusetts, United States ⋅ Somerville, Massachusetts, United States
Experience Level(s):
Junior ⋅ Mid Level
Field(s):
IT & Security
Workplace Type:
On-site
Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.
Job Summary
Mass General Brigham is seeking a Privacy Compliance Specialist II to advance its enterprise-wide privacy compliance program across its network. The Privacy Specialist II will support the enterprise privacy program with a focus on incident response, third-party risk, technology onboarding, and compliance with the new DOJ Data Transfer Rule governing sensitive personal data and bulk data transfers. This role will partner closely with clinical, research, Digital, and business operations teams to ensure appropriate handling of PII, PHI, and other regulated data across the organization.
Qualifications
Education
Bachelor's Degree in a related field of study required
Master's Degree Related Field of Study or Juris Doctor in related field of study preferred
Experience
5+ years of experience preferred in healthcare privacy compliance
Demonstrated experience interpreting and applying HIPAA, HITECH, and other federal, state, international privacy regulations preferred
Certifications:
CHPC, CIPP/US, CIPP/E, CIPM, or comparable privacy certifications preferred
Knowledge, Skills and Abilities
In-depth knowledge of privacy laws, regulations, and standards, including HIPAA, HITECH, and state privacy laws, as well as their application in healthcare settings.
Excellent communication and interpersonal skills to interact with hospital staff, patients, and regulatory authorities regarding privacy matters.
Strong analytical and problem-solving skills to conduct privacy risk assessments and respond to privacy incidents effectively.
Ability to manage multiple priorities and tasks, ensuring timely completion of privacy-related initiatives.
Ensure compliance with HIPAA Privacy and Security Rules, HITECH, 42 CFR Part 2, U.S. state privacy laws, GDPR, and international privacy regulations.
Plan for and guide implementation of emerging state privacy legislation, including the anticipated Massachusetts comprehensive privacy law expected in 2026.
Monitor and advise on data transfer requirements and safeguards, including developments related to DOJ-rule.
Monitor and implement safeguards for website privacy, geolocation data, and patient portal security.
Continuously track regulatory changes and translate requirements into updated policies, procedures, and controls.
Conduct HIPAA/HITECH privacy risk assessments and formal Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs), documenting findings and mitigation plans.
Perform vendor/business associate privacy assessments and contract reviews to ensure third-party compliance with regulatory and contractual obligations.
Advise on AI privacy risk assessments—evaluate data use, algorithmic transparency, model governance, and regulatory/ethical compliance in clinical and operational AI solutions.
Manage GDPR reporting obligations to controllers and, where applicable, supervisory authorities/Data Protection Authorities (DPAs).
Conduct proactive EHR audits (e.g., inappropriate access, snooping, break-the-glass events) and trend monitoring to detect and prevent privacy violations.
Design and implement privacy safeguards and terms of use for digital health services.
Conduct all aspects of privacy incident investigations—including root cause analysis, containment, and remediation planning, risk assessment, documentation and ensure timely notifications to affected patients, research participants, employees, and to state/federal agencies and regulators as required.
Develop, maintain, and operationalize privacy policies and standards tailored to healthcare provider operations
Embed privacy-by-design into clinical, administrative, and digital workflows;
Lead process improvement initiatives to strengthen privacy compliance and operational efficiency.
Coordinate corrective actions and remediation plans for identified compliance gaps, findings, and audit issues.
Partner with IT Security, Legal, Compliance, Research, HR, Health Plan Operations, and clinical leadership to align privacy practices and controls.
Develop privacy metrics and dashboards.
Prepare and present privacy metrics, audit results, and data-driven insights to leadership and regulatory bodies as needed; support committee reporting.
Act on behalf of the Privacy Program Manager when requested to represent the privacy function in meetings and initiatives.
Lead privacy training presentations tailored to clinical staff, administrative teams, researchers, students, interns and business associates.
Assist the Privacy Program Manager in designing, scheduling, and maintaining the privacy compliance training program;
Develop content for privacy awareness (e.g., website, newsletters, targeted communications) and foster a culture of privacy across the organization.
Performs other duties as assigned
Complies with all policies and standards
Working Schedule:
Hybrid, once per week onsite at Assembly Row in Somerville, MA. Onsite presence required for trainings as needed
Additional Job Details (if applicable)
Remote Type
Work Location
Scheduled Weekly Hours
Employee Type
Work Shift
Pay Range
$63,648.00 - $90,750.40/Annual
Grade
6
EEO Statement:
At Mass General Brigham, our competency framework defines what effective leadership “looks like” by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused, half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance, make hiring decisions, identify development needs, mobilize employees across our system, and establish a strong talent pipeline.
Website: https://www.massgeneralbrigham.org/
Headquarter Location: Somerville, Massachusetts, United States
Employee Count: 10001+
Year Founded: 1994
IPO Status: Private
Industries: Health Care ⋅ Home Health Care ⋅ Medical