About Allia Health Group
Allia Health Group (AHG) is a multi-brand healthcare holding company whose subsidiaries include Southend Pharmacy, Brello, HelloWellness, and AlliaCare. AHG is building a formal compliance program spanning HIPAA Privacy & Security, SOC 2 attestation, and broader healthcare regulatory compliance across a fast-moving, multi-entity structure.
Position Summary
The HIPAA Privacy Lead serves as the enterprise HIPAA Privacy SME for AHG's U.S. operations, owning day-to-day interpretation, application, and oversight of the HIPAA Privacy Rule. This individual-contributor role reports to the Chief Compliance Officer & Privacy Officer and formalizes work currently led directly by the CCO — BAA management, privacy risk assessment, policy development, de-identification governance, and workforce training — giving the Privacy program dedicated, sustained ownership as AHG grows.
This is a full-time remote position. Candidates must be available to work during standard business hours.
Key Responsibilities
Privacy Program & Policy
- Maintain and mature HIPAA Privacy policies and procedures across all covered entities and business associates (Southend Pharmacy, Brello, HelloWellness, and AHG Enterprise); advise business, clinical, and IT teams on PHI handling and privacy risk mitigation.
- Partner with GRC to define, implement, and monitor HIPAA controls and align privacy requirements with AHG's broader regulatory frameworks, including the parallel SOC 2 effort.
- Review project designs, system implementations, and process changes for HIPAA alignment, embedding privacy-by-design into clinic and enterprise operations.
- Own the BAA inventory — drafting, tracking, and remediating gaps — and support AHG's de-identification framework (Safe Harbor / Expert Determination under §164.514), including tokenization and egress governance.
- Partner with outside counsel on privacy legal questions, data architecture reviews, and open-items tracking.
Risk Assessment & Incident Response
- Conduct HIPAA privacy risk assessments and breach risk analyses (four-factor framework); maintain the privacy risk register and drive remediation to closure.
- Collaborate with Cyber & Privacy Operations during incidents on breach assessment, escalation/containment/notification decisions, and post-incident SOPs.
- Serve as primary point of contact for privacy complaints, investigations, and regulatory inquiries, working closely with U.S. Privacy Legal Counsel.
- Lead vendor risk assessments for third parties handling PHI, including HIPAA-specific due diligence.
Patient Rights & Data Governance
- Oversee patient requests for access, amendments, restrictions, and confidential communications, ensuring timely, appropriate responses; maintain documentation demonstrating HIPAA compliance.
- Partner with Engineering and Data Engineering to map PHI/PII data flows and review new systems, AI/agentic tools, and vendor integrations before launch.
- Develop self-service tools and templates so teams can independently handle routine privacy requirements.
Training & Reporting
- Design and deliver workforce HIPAA privacy and incident-management training; partner with clinical/operational leaders to embed HIPAA into day-to-day practice operations.
- Represent AHG's privacy posture in regulatory, audit, and compliance forums; monitor regulatory developments (HHS/OCR, state privacy law, FTC) and report program status to the CCO.
Qualifications
Required
- 5+ years of hands-on HIPAA Privacy compliance experience in a regulated environment, specifically within a Specialty Pharmacy or other Covered Entity.
- Hands-on experience with PHI/PII data flow mapping, leading a HIPAA Annual Risk Assessment, and designing/delivering HIPAA Incident Management training.
- Working knowledge of the HIPAA Privacy Rule, Security Rule interplay, BAA requirements (45 CFR §164.504(e), §164.314(a)), and de-identification standards (§164.514).
- Demonstrated experience drafting or managing BAAs, data-sharing agreements, or privacy policies, and working directly with outside counsel and technical stakeholders.
- Experience using compliance and governance platforms (e.g., OneTrust, NAVEX, RSA Archer, ServiceNow GRC, or similar), document management systems, and Microsoft Office Suite (Excel, Word, PowerPoint, and Outlook) to support HIPAA privacy and compliance programs.
- Strong written communication — able to translate legal/regulatory requirements into plain, actionable guidance for business and technical teams.
Preferred
- Certification such as CHC (Certified in Healthcare Compliance), CHPC (Certified in Healthcare Privacy Compliance), or CIPP/US.
- Experience with pharmacy, DTC health/wellness brands, or multi-brand healthcare holding structures.
- Familiarity with BigQuery, cloud data warehouses, or tokenization/de-identification tooling (e.g., Protegrity) sufficient to engage credibly with engineering.
- Exposure to SOC 2 programs or working alongside a parallel SOC 2 effort.
What Success Looks Like (First 6–12 Months)
- Working with the CCO, HIPAA Privacy policies drafted and awareness created across the business unit.
- Intercompany BAAs identified, drafted, and executed, with the BAA inventory as source of truth.
- Privacy risk register stood up and actively tracked with clear ownership and remediation dates.
- De-identification framework operationalized with Engineering and Security, including a defensible position on tokenized/egress data.
- Workforce privacy training launched; CCO able to delegate day-to-day privacy operations with confidence, freeing capacity for SOC 2 and broader Healthcare Compliance work.
What We Offer:
- Full benefits package including medical, vision, dental, 401(k) with company match, PTO, Flex days, holidays, and more!
Allia Health Group does not provide employment visa sponsorship now or in the future. Applicants must be legally authorized to work in the United States without the need for current or future sponsorship.
Equal Opportunity Employer Statement
Allia Health Group is proud to be an Equal Opportunity Employer where we are committed to fostering a diverse and inclusive workplace. We are committed to cultivating a culture where all team members feel valued & respected. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetic information, disability, age, veteran status, or any other characteristics protected by applicable law.