- Salary
- $112k – $160k/yr
- Location
- San Bernardino, CA, CA, US
- Type
- Full-time
- Department
- Administration
- Education
- Master
- Source
- GovernmentJobs
Description
.png)
The Department of Aging and Adult Services–Public Guardian (DAAS-PG) is recruiting for a HIPAA Privacy Officer to develop, implement, and maintain HIPAA privacy policies, oversee compliance with federal and state regulations, and provide technical leadership to safeguard protected health information (PHI). The Department of Aging and Adult Services–Public Guardian serves some of the county’s most vulnerable adults, whose safety, dignity, and independence depend on strong privacy, security, and program integrity across all departmental operations. The HIPAA Privacy Officer will coordinate compliance monitoring activities, lead risk assessments, audits, and program reviews, and collaborate with department leadership and cross-functional stakeholders to integrate privacy and security requirements into all HIPAA-covered operations. As a member of the department's leadership team, the incumbent will ensure departmental privacy, security, and risk management programs comply with applicable HIPAA standards and organizational policies.
Duties include, but are not limited to, the following:
- Support department-wide ADA compliance by reviewing programs, services, and administrative processes to ensure accessibility for clients, families, and staff; collaborate with departmental leadership to integrate reasonable accommodations, accessible communication practices, and ADA-aligned procedures into broader departmental operations.
- Ensure department HIPAA privacy and security practices align with ADA requirements by reviewing policies, procedures, and program operations for accessibility; collaborate with program, facilities, IT, and HR staff to identify and mitigate barriers, integrate reasonable accommodations into privacy-related workflows, and support ADA-compliant communication of PHI and privacy notices.
- Develop, implement, and maintain DAAS-PG HIPAA privacy and security policies, standards, and procedures to ensure compliance with applicable federal and state laws and regulations.
- Provide technical leadership, guidance, training, and consultation to management and staff on HIPAA privacy, security, and the protection of protected health information (PHI).
- Plan, organize, and coordinate HIPAA compliance activities, including risk assessments, audits, internal reviews, corrective actions, and program evaluations to support regulatory compliance and continuous quality improvement.
- Review departmental security plans and coordinate activities related to access controls, incident response, disaster recovery, business continuity, and risk management to ensure HIPAA privacy and security requirements are integrated into departmental operations.
- Develop educational resources and lead HIPAA privacy, security, and information security awareness initiatives to promote compliance throughout DAAS-PG.
- Analyze compliance reports, audit findings, and operational data; prepare reports, presentations, and briefings for executive leadership, stakeholders, and elected officials regarding compliance, risk management, and program performance.
- Collaborate with departmental leadership and cross-functional partners to integrate HIPAA privacy and security requirements into strategic initiatives, program integrity, quality improvement, enterprise risk management, and organizational operations; may provide technical direction and work coordination to staff supporting HIPAA compliance activities
- Maintains extensive knowledge of health care relevant legislation and standards for the protection of health information and patient privacy; maintains expert knowledge of HIPAA security requirements and other information security laws, including NIST, PCI and all other applicable regulations.
For more detailed information, refer to the HIPAA Privacy Officer job description.
EXCELLENT BENEFITS
To review job-specific benefits, refer to: Summary of Benefits and the Exempt Compensation Ordinance.

Candidates must meet both the education and one of the experience options below:
Education:
A bachelor’s degree from an accredited college or university in Healthcare Administration, Health Information Management, Public Administration, Public Health, Business Administration, Information Systems, Information Security, Law, or a closely related field.
-AND-
Option 1 – HIPAA Privacy Program Experience
Two (2) years of full-time equivalent, where the primary responsibility was developing, implementing, and administering HIPAA privacy and compliance programs within a healthcare organization, public health program, human services agency, government agency, health plan, business associate, or other HIPAA-covered entity, including responsibility for policy development, compliance monitoring, risk assessments, internal audits, incident response, workforce training, and regulatory compliance.
-OR-
Option 2 – Public Agency Compliance Experience
Three (3) years of full-time equivalent professional-level experience within a public agency where the primary duties were planning, coordinating, and evaluating regulatory compliance, privacy, information security, enterprise risk management, or similar compliance programs involving confidential, sensitive, or regulated information, including policy implementation, compliance monitoring, risk assessments, operational oversight, and ensuring compliance with applicable federal and state laws and regulations.
The ideal candidate will possess:
- A master's degree in a related field.
- Experience serving as a designated HIPAA Privacy Officer or leading a HIPAA privacy compliance program.
- Experience advising executive leadership on complex privacy, compliance, and risk management matters.
- Candidates with professional certifications in health care privacy, information security, and compliance are strongly preferred. Other credentials demonstrating advanced knowledge of privacy, security, and regulatory requirements, and additional certifications supporting accessibility and compliance may further strengthen a candidate’s qualifications.
Application Procedure: To be considered for this excellent opportunity, please complete and submit the online employment application and supplemental questionnaire by 5:00 pm, Friday, August 21st, 2026. Resumes will not be accepted in lieu of the application and/or supplemental questionnaires.
ADA Accommodation: If you have a disability and require accommodations in the testing process, submit the Special Testing Accommodations Request Form within one week of a recruitment filing deadline.
Veterans’ Preference: Eligible veterans and their spouse or widow(er) who are not current County employees may be awarded additional Veterans’ Preference points. For details and instructions on how to request these points, please refer to the Veterans' Preference Information.
For more important details, review the Applicant Information and County Employment Process.