Job Overview
We are seeking an execution-driven IT Operations & HIPAA Security Analyst to support 23 healthcare centers across the U.S. In this part-time remote role (20 hrs/week), your primary focus will be executing the technical workstream of a HIPAA remediation plan, including MDM device enrollment, SSO deployment, and building audit-ready evidence files. Beyond security compliance, you will manage software licensing, handle endpoint administration, and provide first-line IT support to clinical staff. This is an operational role for an organized professional who excels at system documentation and enforcing security controls in a HIPAA-regulated environment.
Schedule: Mon-Fri, 8:00 AM - 5:00 PM CST (40 hrs per week)
Responsibilities
HIPAA Remediation Execution — Technology Workstream (Primary Mandate, First 6 Months) We are executing a structured, week-by-week HIPAA remediation plan through December 2026. This role owns execution of the plan's technology tasks under direction from the Vice President of Central Operations, COO, and internal IT team, including:
- Build and maintain the complete inventory of systems that touch PHI (practice management / EHR, communication, analytics, and productivity platforms), including who administers each, how access is granted, and how it is removed at offboarding.
- Drive MDM enrollment to 100% of company devices — iPads, laptops, and phones — with configuration profiles, compliance policies, encryption, and enforced screen lock applied; monitor compliance dashboards and remediate non-compliant or unenrolled devices promptly.
- Support the SSO rollout from pilot through full deployment across the company's application stack, including user communications, troubleshooting, and enrollment tracking.
- Verify — not just configure — key controls, and capture evidence: MFA enforcement on email, the EHR, and remote access; device encryption reports exported and filed on a quarterly cadence; a documented live remote lock/wipe test on a sample device.
- Execute and document offboarding controls: same-day deprovisioning at termination (remote lock/wipe, license reclamation, account deactivation across all systems) in coordination with HR, and support periodic termination sample audits.
- Support leadership decision gates (e.g., secure messaging and email encryption approaches) with requirements gathering, vendor research, cost comparisons, and written summaries for decision by leadership.
- Maintain the audit-ready evidence file for all technology remediation tasks — configurations, exports, screenshots, test results, and dated documentation — so completed work is provable, not just done.
Endpoint & Device Management (Ongoing)
- Administer our endpoint management platforms day to day: enrollment, configuration profiles, compliance policies, and security baselines for every company-managed device.
- Maintain a complete, accurate device asset inventory across all 23 centers and corporate/remote staff — assignment, condition, and replacement cycle.
- Manage OS and application patching baselines; report compliance status to the internal IT team monthly.
Software Licensing & Access Administration
- Own the company-wide software license inventory: every application, seat count, cost, renewal date, and business owner — reconciled against active headcount monthly to eliminate unused seats.
- Maintain the renewal calendar so no contract auto-renews unreviewed; produce an annual software cost roll-up for leadership.
- Track SSO/MFA coverage across the SaaS stack and flag applications where stronger authentication should be enforced, for action by the internal IT team.
IT Support (Bandwidth Relief for the Internal Team)
- Serve as first-line intake for IT questions and issues from staff across all centers and corporate functions: triage, resolve remotely where possible, and escalate to the internal IT team or vendors with clear documentation when not.
- Provide remote troubleshooting for hardware, operating systems, printing, connectivity, Google Workspace, EHR access, and SSO/MFA and password support — during agreed overlap hours, with a defined escalation path for urgent issues outside them.
- Build and maintain a knowledge base and job aids so common issues become self-service over time.
- Track tickets, response times, and resolution times; report trends and recurring root causes to the internal IT team monthly.
New Center Technology Onboarding
- Partner with Facilities and the internal IT team on new center openings: define device counts by role, coordinate procurement timing, and provide equipment cost inputs for the opening budget.
- Ensure every new-center device is enrolled in MDM and loaded with the approved, secured software stack before go-live — no exceptions — directing onsite staff and vendors for physical setup.
- Maintain the new-center IT readiness checklist (devices, peripherals, network requirements, printing/scanning) and drive it to verified completion remotely, with priority support through go-live week.
Data Security & PHI Handling Requirements — This role holds elevated administrative access to systems containing protected health information, performed from outside the United States. The following controls are strict conditions of the engagement:
- All work is performed on a company-managed or company-controlled environment (managed device or virtual desktop, per our determination) enrolled in our MDM, with SSO/MFA authentication. No personal devices.
- Administrative access is provisioned with least privilege, logged, and periodically reviewed. Elevated credentials are never shared, reused, or stored outside approved systems.
- PHI is never downloaded, printed, screenshotted, stored locally, or transferred to personal storage, email, or messaging tools. Systems containing PHI are accessed only as required to perform IT duties, and no PHI is retained outside our controlled systems.
- Work is performed from a private, secure workspace; screens containing sensitive data must not be visible to others.
- Completion of our HIPAA and security training before any system access is granted, with annual recertification; full compliance with all applicable business associate and data-handling agreements governing the engagement.
- Immediate reporting of any suspected privacy or security incident, and full cooperation with investigation and remediation.
- Continuity requirement: all runbooks, configurations, inventories, and procedures are documented in our owned systems as work is performed, so institutional knowledge remains internal.
Measures of Success — First 12 Months
- Within 30 days: Security and HIPAA onboarding complete; full device inventory and PHI system inventory captured and verified; support intake and ticket tracking operating; working rhythm established with the internal IT team and the weekly compliance meeting.
- Within 90 days: MDM enrollment complete across all active devices with compliance policies, encryption, and screen-lock enforcement applied; SSO rollout supported through pilot and deployment per the remediation plan; license inventory and renewal calendar live with no unreviewed auto-renewals.
- Within 6 months: All assigned technology tasks in the remediation plan complete with audit-ready evidence filed (MFA verification, encryption exports, remote wipe test, offboarding audit support); quarterly evidence cadence calendared and running; monthly license-to-headcount reconciliation running; knowledge base covering the top recurring support issues.
- Within 12 months: Sustained quarterly control-verification rhythm; measurable license cost savings from seat reconciliation; support resolution times trending down; every center opened in the period fully enrolled and secured at go-live; deferred technology items (e.g., backup/DR restore testing, removable-media restrictions, EHR role-based access review support) scoped and in motion as directed.
Requirements
Required
- Bachelor's degree or equivalent experience.
- 3–5+ years in IT support, endpoint administration, or IT operations supporting a distributed, multi-site organization.
- Hands-on experience administering an MDM / endpoint management platform (e.g., Mosyle, Jamf, Kandji, Microsoft Intune, or comparable), including Apple device management.
- Working experience with identity and access management: SSO/MFA administration in Google Workspace, Okta, Microsoft Entra ID, or comparable.
- Working knowledge of U.S. healthcare security requirements and control frameworks (HIPAA Security Rule; familiarity with NIST CSF or CIS Controls a plus).
- Demonstrated software asset/license management: seat tracking, renewals, and vendor coordination.
- Strong documentation discipline: the ability to produce clear runbooks, checklists, and evidence files without prompting.
- Exceptional written English and patient, jargon-free communication with non-technical staff.
- High integrity and discretion handling elevated access in a PHI environment.
- Reliable ability to work a schedule with at least 4 hours of daily overlap with U.S. Central Time.
Preferred
- Certification such as CompTIA A+, Network+, or Security+; Google Workspace or Microsoft administrator certifications.
- Experience supporting EHR / practice-management platforms (CentralReach a plus).
- Experience with helpdesk / ticketing platforms and remote support tools.
- Prior experience working as offshore/remote support for a U.S. healthcare organization under a business associate agreement.
Independent Contractor Perks
Permanent work from home
Immediate hiring
Health Insurance Coverage for eligible locations
Note
Please click the "Apply" button to complete your application, including the assessment questions, technical check, and voice recording. Your hourly pay rate will be established based on your performance in the application process; submissions with all requirements fulfilled will receive priority review.
Job Category
Information Technology
Job Type
Full Time (35 hours or more per week)
Work Schedule and Timezone
8am - 5pmCentral Time
Published on
Jul 27 2026
“BruntWork made the entire recruitment process smooth, transparent, and stress-free. They matched me with a client that genuinely fits my skills and values — and the support didn’t stop at placement... A reliable, professional partner I’d recommend without hesitation.”
— Zyrrah D, Bookkeeper
IT Operations & HIPAA Security Analyst
Job Category
Information Technology
Job Type
Full Time (35 hours or more per week)
Work Schedule and Timezone
8am - 5pmCentral Time
Published on
Jul 27 2026
“BruntWork made the entire recruitment process smooth, transparent, and stress-free. They matched me with a client that genuinely fits my skills and values — and the support didn’t stop at placement... A reliable, professional partner I’d recommend without hesitation.”
— Zyrrah D, Bookkeeper