Business Analyst – HIPAA Security Risk Assessment
Location: Onsite; Minneapolis MN
Duration: 2-Month W2 Contract
Pay Rate: $65–$76/hour (depending on experience)
Company: Russell Tobin (supporting a professional services client)
Russell Tobin is seeking a Business Analyst to support a HIPAA Security Risk Assessment engagement with one of our professional services clients.
This role will provide hands-on support to the assessment team by assisting with documentation review, evidence collection, stakeholder interviews, and compliance tracking across administrative, physical, and technical safeguards aligned to the HIPAA Security Rule.
The Business Analyst will work closely with senior team members to help evaluate existing security controls, identify potential gaps, and document assessment findings.
Key Responsibilities
- Support execution of a HIPAA Security Risk Assessment aligned to the HIPAA Security Rule
- Review and organize documentation and supporting evidence, including policies, procedures, logs, inventories, and system screenshots
- Assist with questionnaire analysis and identify gaps, inconsistencies, or areas requiring follow-up
- Participate in and document stakeholder interviews and control walkthroughs
- Maintain project trackers such as document request lists (DRL), gap logs, and assessment trackers
- Draft clear and concise workpapers, summaries, and preliminary observations
- Escalate issues, ambiguities, or potential risks to senior team members
- Follow established assessment methodologies and documentation standards
Preferred Qualifications
- Experience supporting HIPAA Security Risk Assessments or healthcare compliance reviews
- Background in IT audit, SOX ITGCs, risk assessments, or security/compliance programs
- Familiarity with security domains such as access controls, incident response, risk analysis, or contingency planning
- Experience reviewing policies, procedures, and other compliance evidence
- Experience using Excel, SharePoint, or similar tracking tools
- Certifications are a plus but not required (e.g., CISA, CISSP, HCISPP)
Ideal Candidate
- Strong documentation and analytical skills
- Experience supporting compliance, audit, or risk assessment engagements
- Comfortable collaborating with technical teams and business stakeholders in a remote environment
Pride Global offers eligible employee''s comprehensive healthcare coverage (medical, dental, and vision plans), supplemental coverage (accident insurance, critical illness insurance and hospital indemnity), 401(k)-retirement savings, life & disability insurance, an employee assistance program, legal support, auto, home insurance, pet insurance and employee discounts with preferred vendors.
#RTA
#LI-BK1
#JD-E2EProf