Job ID: VA-811322 (94990918)
Hybrid/Local Cerner Millenium/OHPAC EHR (must) Security Analyst with HIPAA/HITECH, Active Directory/AD/SSO/MFA/IAM, networking/firewalls, database security, Discern/ccl experience
Location: Salem, VA (VDH)
Duration: 12 Months
Skills:
Understanding knowing of Millenium and OHPAC security positions Required 3 Years
healthcare IT experience Required 3 Years
IT experience Highly desired 3 Years
Strong Understanding of EHR Systems, specifically OH/Cerner Highly desired 3 Years
Understanding of HIPAA, HITECH, meaningful user and other healthcare security regulations Highly desired 3 Months
Experience with Active Directory (AD), single sign-on (SSO), multi-factor authentication (MFA), and identity management solutions. Highly desired 3 Years
Strong analytical, problem-solving, and troubleshooting skills related to Cerner/OHPAC security and access issues. Required 3 Years
Excellent communication and collaboration skills to work with IT teams, compliance officers, and end users. Required 3 Years
Familiarity with healthcare IT infrastructure, including networking, firewalls, and database security. Highly desired 3 Years
Knowledge of Discern and ccl Required 3 Years
Job Description:
The Virginia Department of Health (VDH) enterprise level EHR Security Analyst will be responsible for supporting the security, access, and user provisioning requirements of the Electronic Health Record (EHR) environment along with providing support tier 1 to the EHR end users on related areas.
This position provides technical and functional support for EHR security configuration, user access, security roles, authentication, auditing, and access-related troubleshooting. The Security Analyst works with clinical, operational, information technology, privacy, compliance, and application support teams to ensure users have appropriate access to EHR applications based on their job responsibilities and organizational policies.
The EHR Security Support Analyst provides technical and functional security support for the Cerner Electronic Health Record environment. This role is responsible for maintaining appropriate user access, supporting security configuration, monitoring access-related activities, troubleshooting security issues, and assisting with the implementation and sustainment of EHR security controls.
The EHR security Support Analyst is responsible for managing and help define user access policies, security policies and role-based permissions within the EHR. This role will work closely with the EHR Application team, ISO Team and HIPAA compliance officer among others to ensure that the application is compliance with HIPAA standards, organizational security policies and best practices.
Key Responsibilities
· Map and maintaining EHR positions definitions, which includes, Millenium Positions, Preferences and OHPAC Security groups with VDH Positions.
· Reviews and processes EHR access requests in accordance with established policies, procedures, organizational standards, and role-based access requirements.
· Creates, modifies, and terminates user access based on approved requests and established processes.
Monitor and enforce appropriate use of EHR Access Control Positions and Policies, ensuring that users have the correct level of access based on their roles and their job functions.
Work with EHR Security Officer, IT Technical team, Support Team and EHR Core team to help define and automate user provisioning and offboarding procedures.
Monitor and conduct internal security audits of the EHR application to identify and mitigate risks and/or vulnerabilities detected.
Work with EHR Security Officer to develop and maintain security policies, procedure and guidelines related to the Application.
Work with EHR Security Officer and ISO Office and EHR Core team to define and complete security documentation and downtime procedures according with VDH Security guidelines.
Work with EHR Security Officer to respond and investigate security incidents related to EHR Application ensuring timely resolution and proper reporting to stakeholders.
Collaborate with the EHR implementation and optimization teams to ensure that security measures are integrated into the deployment of new features, updates, and third-party applications.
Stay informed about emerging security threats, technologies, and best practices related to EHR systems.
Recommend improvements and optimizations to the EHR security environment based on industry trends and emerging threats.
Monitor user behavior by using tools like P2Sentinel to determine trends and possible incidents.
Work with EHR Security Officer and EHR Core team to assist on internal and external audits.
Participate in Cerner/OHPAC upgrades, security patches and system maintenance to ensure ongoing security.
Participate in the Domain Strategy for EHR Application.
Stay up to date with security updates, best practices and regulatory changes.
Required Experience
Three plus years of IT experience.
Three plus years of healthcare IT experience
Strong understanding knowing of Millenium and OHPAC security positions required
Strong Understanding of EHR Systems
Understanding of HIPAA, HITECH, meaningful user and other healthcare security regulations.
Experience with Active Directory (AD), single sign-on (SSO), multi-factor authentication(MFA), and identity management solutions.
Strong analytical, problem-solving, and troubleshooting skills related to Cerner/OHPAC security and access issues.
Excellent communication and collaboration skills to work with IT teams, compliance officers, and end users.
Familiarity with healthcare IT infrastructure, including networking, firewalls, and database security.
Knowledge of Discern and ccl.
