About Us We are an established provider of HIPAA-compliant managed hosting and security services for healthcare, research, and government organizations. We operate as a Business Associate to covered entities across the country, which means compliance isn't a support function here — it's central to what our customers buy from us. We're a small, close-knit, fully remote team that invests in our people and funds their certifications. The Role We're looking for a HIPAA Compliance Analyst to own our governance, risk and compliance function — and to be the compliance authority in the room when a security incident is live. Two halves to the job. The steady half is the compliance program: policies, BAAs, audit responses, and the customer security questionnaires our clients depend on when they are being audited. The sharp half is incident work: when a vulnerability or a compromise hits our fleet, you tell the engineers exactly what to verify, you produce the breach risk assessment, and you make the notification recommendation that our Director of Information Security decides on. You are not the person running the forensics — we have a security team for that. You are the person who says "check for this specific file at this path, and if it's there we have a notification obligation." That distinction is the job. What You'll Do Incident and risk work Produce the breach risk assessment. Distinguish a vulnerability from an exploited system from an actual data exfiltration, and translate that into a clear, written notify / don't-notify recommendation. The final decision sits with our Director of Information Security; the analysis and the recommendation are yours. Track the notification clock — the 60-day HIPAA requirement plus any shorter or stricter terms written into individual customer contracts. You are expected to know which customers carry those and to raise the deadline before anyone has to ask. Define the verification steps, in directive form. When a vendor advisory drops, translate it into specific instructions an engineer can execute under pressure: this file, this path, this command — not a list of considerations. This is the part of the job we care most about. Produce the written breach risk assessment and the customer notification language. Third-party and supply-chain risk — evaluate vendor advisories, coordinate with security vendors on analysis and virtual patching, and help shape our update/patching policy so a compromised upstream release doesn't propagate automatically. Compliance program Own and respond to customer security questionnaires and vendor assessments — accurately, and within committed timeframes. Draft, maintain, and version our HIPAA policies and procedures . Execute and track Business Associate Agreements (BAAs) and NDAs. Coordinate audit and certification evidence — SOC 2 requests, auditor attestations, and framework documentation — including chasing third-party vendors when the evidence sits with them. Perform Covered Entity vs. Business Associate analysis and advise customers on where responsibility sits. Own a ticket queue end to end — acknowledge quickly, set realistic commitments, meet them, and tell the customer when the work is done. Maintain a gap register : track compliance gaps you identify, with owners and decisions, so nothing lives only in someone's head. Required 3+ years in HIPAA security/compliance, healthcare privacy, or healthcare security audit Direct, hands-on experience with BAAs, HIPAA policy documentation, and customer security questionnaires Working security literacy. You don't need to run the forensics, but you must be fluent in indicators of compromise, the difference between a vulnerability and an exploited host, web application compromise patterns, and what log and file evidence can and cannot prove Breach risk assessment experience — you have made, or directly supported, a real notify / don't-notify determination against the HIPAA breach rule The ability to give clear, directive instructions under time pressure. During a live incident our engineers need "do this, check that file, report back" — not a list of considerations. If your instinct is to send everything you know into a Slack thread, this is not the right seat Demonstrable follow-through. You track your own commitments, close loops, and tell people when something is done rather than assuming they'll notice Comfort working independently and remotely with minimal supervision Willing to flex your hours within the week during an active incident. Our on-call security team covers nights and weekends; your part is the risk and notification analysis, which follows the evidence rather than the alarm. No on-call rotation. Reliable high-speed home internet Preferred certifications (one of these is a strong plus; none is required) CHPC — Certified in Healthcare Privacy Compliance (HCCA) CHPS — Certified in Healthcare Privacy and Security (AHIMA) CHC — Certified in Healthcare Compliance (HCCA) CCSFP — HITRUST Certified CSF Practitioner (we will fund this for the right person) CISSP, CIPP/US, CISA, or
ISO 27001
Lead Implementer also welcome Nice to have Experience on the Business Associate side — a vendor or hosting provider, not just a provider organization Familiarity with SOC 2 and HITRUST evidence cycles Background in WordPress / managed hosting compromise patterns, or in supply-chain risk Government, DoD, or regulated-industry security background Enough familiarity with cloud hosting environments to understand what you're attesting to Experience working a ticketing system (Zendesk, Jira Service Management, Zoho, or similar) What This Role Is Not ❌ Not a security engineering role. You will not be patching servers, tuning scanners, or running the forensic log review yourself — we have a security team and a security engineer for that. ❌ Not an incident commander. You are the compliance and risk authority during an incident, not the person directing the technical response. ❌ Not a pure policy-writing job either. If your compliance experience is entirely documentation and you've never been in the room during a live security event, this will not be a good fit. ❌ Not a full-time position , and we're not planning to convert it to one in the near-future. Location and Schedule This is a remote position within the United States. We're prioritizing candidates in the Central time zones so there is solid daily overlap with our West Coast operations and East Coast customers. The Midwest is of particular interest. 15-20 hours per week, with the specific schedule agreed on hire. We need predictable daily presence rather than one long block — compliance requests arrive continuously, and responsiveness is the core of this job. Why Join Us Real ownership. This is the compliance function, not a slice of it. Funded certifications. We pay exam fees and study materials, including CCSFP. Flexible, genuinely part-time. We're not going to quietly turn 20 hours into 40. Small team, visible work. You'll report to senior leadership and your work reaches customers every week.
Pay:
$50.00 - $59.00 per hour Expected hours: 15.0 - 20.0 per week
Education:
Bachelor's (Required)
Experience:
personally filling out audits & security questionnaires: 2 years (Required) hands-on security/compliance: 3 years (Required)