Background Information:
The purpose of this procurement of a Senior Privacy (PIA) Specialist is to acquire a contingent resource to act as a dedicated privacy subject matter expert to assist with supporting privacy matters related to a number of key Information Technology projects that include provincial Electronic Health Record (EHR) initiatives, AI Scribe; Homecare; Provincial Viewers, eReferral, Central Intake, etc.
Ontario Health is seeking a Privacy resource to ensure that Ontario Health maintains compliance with its legal and contractual privacy obligations, and builds privacy into the design of projects that involve personal health information (PHI), thus reducing risk for the organization and protecting the trust and privacy of individuals whose PHI we manage.
Must haves:
· Minimum of 3 years’ health privacy experience conducting privacy impact assessments (PIAs) on medium to high complexity projects
. Minimum 5 years’ direct operational level privacy experience preferably in a health sector and/or IT environment
· Minimum 5 years' experience drafting and reviewing privacy requirements for data sharing agreements
· Minimum 5 years’ experience developing privacy policies and procedures, requirements, or controls
· Familiarity with the Personal Health Information Protection Act (PHIPA), and its related requirements for Health Information Network Providers (HINP) and Electronic Service Providers (ESP)
. Familiarity with Application Programming Interface (API) functionality and management
· Familiarity with Electronic Medical Record (EMR) or Hospital Information System (HIS) infrastructure, design, and data flows
Responsibilities:
· Conducting/Completing Privacy Impact Assessments and associated documentation
· Providing Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiatives
· Identify and assess privacy risks, including developing risk mitigation plans
· Create or inform the creation of data flow diagrams and associated privacy controls and compliance requirements
· Reviewing and advising on agreements, including data sharing agreements
· Developing privacy requirements for new or changing projects
· Providing privacy advisory and support to business teams
· Other duties as required
Desired Skills:
Required Skills
Total - 100 Points
· Over the duration of the engagement, the Senior Privacy (PIA) Specialist will support work already in progress, as well as new work on Privacy Impact Assessments;
· Work with the project and product teams on risk mitigation of PIA findings as required under PHIPA;
· Support work related to update and/or developing new agreements;
· Other duties as required. Note that knowledge of current privacy and data protection policy and legislation, especially Ontario’s Personal Health Information Protection Act (PHIPA), will be critical to ensure success.
· Conducting/Completing Privacy Impact Assessments and associated documentation
· Providing Privacy Consultation on a diverse range of complex, multi-stakeholder health privacy issues and Information Technology (IT) initiatives
· Developing risk mitigation plans
· Create or inform the creation of data flow diagrams and associated privacy controls and compliance requirements
· Reviewing and advising on agreements, including data sharing agreements
· Developing privacy requirements for new or changing projects
The term of this engagement is 215 business days with an option to extend for 163 days at Ontario Health's discretion.
Ontario Health assets including laptops and related equipment cannot be removed from the province of Ontario without prior written approval from Ontario Health.
Assignment Type: This position is currently hybrid. The resource under this request will be required to work onsite upon Ontario Health request.
Knowledge Transfer Details:
· The Candidate will ensure full knowledge transfer is provided to the Ontario Health team before end of engagement. Some of this might occur at the end of the engagement but will also be shared as information is obtained/consolidated. Key deliverables will be shared with team, using an approved format.
· The Candidate must provide all related documentation as part of Knowledge transfer protocol. Documents will be reviewed by the appropriate leads and signed off by manager/director.
· The candidate will work collaboratively with Ontario Health team throughout the assignment and ensure key deliverables, milestones, and documentation are shared.
· A walkthrough of any demos, development, etc. will be required before end of engagement, as required.