We are seeking an EHR Security Analyst to support security, access, and user provisioning within the Oracle Health (Cerner) Electronic Health Record (EHR) environment. This role combines functional security configuration, role-based access control (RBAC), and Tier 1 end-user support with compliance enforcement (HIPAA/HITECH). The position works closely with clinical, application, ISO, and compliance teams to ensure access aligns with organizational security policies and best practices.
Client: Virginia Department of Health (VDH)
Location: 109 Governor St, Richmond, VA 23219
Work Arrangement: Hybrid
Role Type: Contract (10/05/2026 – 06/30/2027)
Submission Deadline: Open / Urgent
Interview Process: In Person Only
Key Responsibilities
- Security & Access Administration: Map and maintain EHR position definitions, Millennium Positions, Preferences, and OHPAC Security groups. Process, provision, modify, and terminate user access requests according to established role-based policies.
- Governance & Automation: Partner with the EHR Security Officer, ISO Office, and core teams to define, maintain, and automate user provisioning, offboarding, downtime procedures, and access control guidelines.
- Auditing & Monitoring: Perform internal security audits using monitoring tools like P2Sentinel to evaluate user behavior, identify risks, and mitigate system vulnerabilities.
- Incident Management & Support: Respond to and investigate security incidents involving the EHR application, deliver Tier 1 technical/functional support, and resolve access issues.
- System Maintenance & Upgrades: Participate in Cerner/OHPAC upgrades, security patch deployments, domain strategy planning, and third-party feature integrations.
- Compliance: Ensure the EHR application remains fully compliant with HIPAA, HITECH, Meaningful Use, and state security guidelines.
Required Skills & Qualifications
- Millennium & OHPAC Security: 3+ years mapping and managing Cerner Millennium positions, preferences, and OHPAC security groups.
- Healthcare IT & EHR Systems: 3+ years of technical experience supporting Electronic Health Record (EHR) systems within healthcare IT environments.
- Discern & CCL: 3+ years of experience utilizing Discern and Cerner Command Language (CCL).
- Troubleshooting & Support: 3+ years troubleshooting Cerner/OHPAC security issues, access control requests, and provisioning errors.
- Communication & Collaboration: 3+ years collaborating effectively across IT teams, compliance officers, clinical stakeholders, and end users.
Preferred Qualifications
- General IT Experience: 3+ years of broad IT technical support experience.
- Regulatory Compliance: Knowledge of HIPAA, HITECH, Meaningful Use, and healthcare data security regulations.
- Identity & Access Management (IAM): Hands-on experience with Active Directory (AD), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and enterprise identity tools.
- Healthcare Infrastructure: Understanding of healthcare IT infrastructure, network security, firewalls, and database protection.