Information Security Associate
Current Compliance: Worked with new and existing athenahealth vendors to ensure initial and continued compliance with Information Security requirements. Reviewed technical controls with vendors, document compliance and exceptions, and report out findings to athenahealth leadership. Project planning and facilitation: Created Information Security related project plans that included deliverables, responsible parties, timelines, budgets, etc. for both athenahealth and 3rd party vendors who work with athenahealth. Conducted check-ins with stakeholders (both internal and 3rd party) to ensure Information Security projects are on track, budget, etc. Process reviews: Ensured periodic reviews are being conducted by business stakeholders for internal and vendor practices to ensure athenahealth is compliant with all regulatory requirements such as HIPAA, HITRUST, etc. Reporting: Communicated and tracked exceptions to athenahealth Information Security policies by vendors.