Jobs › HIPAA
HIPAA Compliance Jobs
HIPAA is the US law governing the privacy and security of protected health information.
The Health Insurance Portability and Accountability Act (HIPAA), through its Privacy Rule, Security Rule, and Breach Notification Rule, sets the federal standard for protecting health information in the United States. It applies to covered entities, health plans, providers, and clearinghouses, and to the business associates that handle protected health information (PHI) on their behalf. The Security Rule requires administrative, physical, and technical safeguards, and the HHS Office for Civil Rights enforces it with investigations and penalties.
In healthcare GRC, HIPAA is the baseline every program is built on, and it is increasingly entangled with AI, as health systems and digital-health companies deploy models on exactly the data HIPAA protects. Roles in this space want people who can run a HIPAA program, manage business-associate risk, and handle breaches, often alongside HITRUST certification.
HIPAA: Frequently Asked Questions
Who must comply with HIPAA?
Covered entities (health plans, health care providers, and clearinghouses) and their business associates that create, receive, maintain, or transmit protected health information.
What are the main HIPAA rules?
The Privacy Rule, the Security Rule, and the Breach Notification Rule, governing the use, protection, and breach reporting of protected health information.
Who enforces HIPAA?
The US Department of Health and Human Services Office for Civil Rights (OCR), which investigates complaints and can impose civil and, in some cases, criminal penalties.
Open HIPAA GRC jobs (51)
Data and AI Risk & Ethics Specialist
Governance, Risk, and Compliance Manager - FedRAMP
Governance, Risk, and Compliance Manager - Privacy
Security Compliance, GRC Engineer
Product GRC Subject Matter Expert, (V4G)
Subject Matter Expert, GTM GRC - V4G
GRC Pre-Sales Consultant / Solutions Engineer – EMEA
Director of Cybersecurity Governance, Risk and Compliance
Privacy Manager
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Digital Risk Services - SOC Reporting and HITRUST Managing Director
VP, Compliance & Risk
Staff+ Software Engineer, Privacy
Privacy Operations Program Manager
Senior Privacy and AI Counsel
Staff Program Manager, Compliance
Field CISO
Director of IT Governance
Director, Privacy Counsel
Governance, Risk & Compliance Analyst
Training Supervisor, Quality Assurance
Virtual CISO & Cybersecurity Practice Lead
Head of Security & AI Governance
Risk Partner
Security, Risk and Compliance Consultant
Director of IT Governance
Director of Governance, Risk, and Compliance
Director AI Governance & Business Integration
Senior Security Compliance Specialist
Clery Compliance Specialist
Security Compliance Analyst, Privacy
IT Enterprise Risk Analyst
Director of Compliance & Risk Management
Principal, AI Governance
Data and AI Governance Lead, Computing Services
Chief Information Security Officer
Director of Quality and Corporate Compliance
GRC Pre-Sales Consultant / Solutions Engineer – DACH market, EMEA
Senior Software Engineer, Trust and Third Party Risk Management
Director, Governance, Risk, and Compliance (GRC)
Senior Internal Auditor
Rev Cycle Internal Auditor
Security Controls Assurance Lead
Staff Security Assurance Engineer
HIPAA jobs: what the market looks like right now
A snapshot built from the 51 HIPAA roles currently on this page.
What these roles pay by level
| Level | Median midpoint | Postings |
|---|---|---|
| Mid-level | $153k | 6 |
| Director | $179k | 5 |
How these figures were calculated, and sources
Primary source: our own board. Every figure above is the median midpoint of the salary ranges published in the live postings on this page. Nothing is estimated, modelled, or carried over from a previous month. It is recalculated each time the board refreshes.
What is included. Only postings that publish a salary range. Hourly, weekly and monthly rates are annualised (2,080 hours, 52 weeks, 12 months). Ranges below $20,000 a year are excluded as data-entry placeholders. A seniority band is shown only when at least five postings support it; senior / lead / manager and executive / c-suite are present on this page but below that threshold, so no median is published for those bands.
What this is not. These are advertised ranges, not accepted offers. Advertised ranges tend to run wider than what is actually paid, and roles that do not publish a range are missing from the calculation entirely, which can bias the result upward.
For an independent benchmark, compare against the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics for SOC 13-1041 — Compliance Officers, published annually at bls.gov/oes. BLS reports actual wages across all employers rather than advertised ranges, so its medians normally sit below job-board figures.
Where the work is
- Work mode: 9 remote, 1 hybrid, 41 on-site or unstated.
- Seniority mix: mid (24), senior (12), director (10), executive (5)
- Employers hiring more than one: SEI (9), Vanta (5), Penn State University (3), Decagon (2), Anthropic (2), Albany Medical Center (2)
Skills these postings ask for
- policy and procedure writing
- control testing and evidence collection
- regulatory change management
- SOX and SOC 2 readiness
- issue management and remediation tracking
How to get a compliance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in HIPAA postings to be worth knowing: CCEP, CRCM, CAMS, CIPP/US, AIGP. The certification academy covers what each one actually tests and who it is for.
Hiring for HIPAA?
We have 51 open HIPAA roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
All GRC jobs · Job alerts