As a member of the privacy team, the Research Privacy Specialist supports the Manager of Privacy, FIPPA & Information Access in ensuring organizational compliance with relevant privacy legislation.
The primary role of the Information Access & Privacy Specialist position is three-fold:
- To assist the Manager to implement, sustain, monitor and improve a comprehensive privacy program in a complex healthcare environment,
- To complete privacy-related deliverables for new projects, including but not limited to PIAs, PIA summaries, obtaining risk mitigation sign off, self-assessments, construction of supportive policies & procedures focused on research, and
- To assist the Manager in implementing operational compliance programs (e.g. auditing, research documentation including protocols and consent forms)
The Specialist will promote and advance the adoption of privacy practices and standards, and providing both formal and informal analyses, consultation and guidance to a variety of stakeholders, with a primary focus on supporting research activities. . The Specialist serves as a key privacy resource for research initiatives, helping researchers and project teams navigate complex privacy, data governance, and regulatory requirements while enabling the responsible use of personal information in research. The Specialist has a considerable degree of interaction with a variety of internal and external stakeholders, including: researchers and their teams, project managers, vendors, consultants, government/regulatory bodies, expert peers in the healthcare field, clinicians, patients/clients, and members of the public. Strong leadership, collaboration, and communication skills are required to build credibility and trust, and to accomplish goals with the assistance of internal and external teams.
DUTIES & RESPONSIBILITIES:
- Supports the development of the privacy and information access program by:
- Identifying, escalating and tracking risks
- Providing guidance compliant with legislative requirements, regulator’s expectations, best practices, and organizational risk tolerance
- Planning activities to implement, sustain, monitor and/or improve pieces of the privacy and information access program
- Keeps abreast of changing requirements and trends in privacy and information access
- Conducts research and environmental scans on privacy controls and emerging trends
- Supports the development of projects and other initiatives by: (a) conducting privacy impact assessments (PIAs); (b) providing guidance on technical, manual, procedural and administrative controls recommended to enhance privacy; (c) assisting internal teams to implement recommended controls; and (d) providing feedback on contracts and research studies.
- Develops hospital policies & procedures
- Produces documentation to meet internal and external reporting requirements
- Conducts reviews of research applications & provides strategic guidance to researchers setting up research projects and/or programs
- Represents the organization externally
- Works closely with members of the Research Ethics Office
QUALIFICATIONS:
- University undergraduate degree in a related field (e.g., business, public or health administration, library sciences or information management).
- Canadian certification with the International Association of Privacy Professionals (CIPP/C) or an equivalent credential is an asset.
- At least 3 years work experience with interpreting and applying provincial and federal privacy and freedom of information legislation, including PHIPA and FIPPA. Experience in a hospital or long-term care environment required.
- At least 2 years of experience acting as the member knowledgeable in privacy on a research ethics board, or otherwise providing privacy guidance to researchers/research administration
- Demonstrated experience in the design and delivery of a piece of an operational privacy program (for example, implementing a training program, piloting an audit regime, operationalizing a policy on the clinical front-lines or administrative back offices).
- Demonstrated experience providing privacy guidance and conducting privacy impact assessments (PIAs). Completion of PIAs or provision of guidance on IM/IT projects required.
- Excellent presentation and training skills.
- Information Security training or experience is an asset.
- Project management experience an asset.
- Demonstrated strong analytical and problem-solving skills.
- Knowledge and skills in using Microsoft Office Suite, Adobe Acrobat and other office software.
- Excellent interpersonal, communications and customer service skills. Experience responding to complex inquiries from patients is an asset.
- Ability to work independently, with little day-to-day supervision
- Excellent organizational and time management skills and the ability to respond to a multiplicity of demands and prioritize work activities
- Demonstrated consensus-building capacity in working with internal and external stakeholder groups
Unity Health Toronto is committed to creating an accessible and inclusive organization. We strive to provide a recruitment process that is barrier-free and in compliance with the Accessibility for Ontarians with Disabilities Act (AODA) and the Ontario Human Rights Code. We understand that you may require an accommodation at any stage of the recruitment process. When you are contacted, please inform the Talent Acquisition Specialist and we will work with you to meet your accommodation needs. We want to emphasize that all accommodation requests are handled with the utmost confidentiality, respecting your privacy and dignity.
#LI-MR1