Post Job Free
Sign in

Manager Security

Location:
Stockbridge, GA
Posted:
September 28, 2017

Contact this candidate

Resume:

SARINA L. FOREMAN, J.D., MBA, CIPP/US (C) 612-***-****; (H) 678-***-****

Metro Atlanta ***********@*****.***

www.linkedin.com/in/sarina-foreman-jd-cipp-8829655

EXECUTIVE PROFILE

Privacy executive and attorney responsible for privacy and compliance across distinct business solutions in healthcare and government agencies. Certified Information Privacy Professional (CIPP) and attorney with more than 14 years of experience in the areas of privacy, compliance, technology and ethical issues. Consistently demonstrates a unique ability to balance proprietary business needs with evolving legal requirements. Background includes practical applications of FTC Fair Information Practices, COPPA, CAN SPAM, HIPAA, HI-TECH, and U.S. Department of Commerce. Strong record of success in achieving inter-departmental consensus between legal, engineering, product development, sales, marketing, and human resources teams.

PROFESSIONAL EXPERIENCE

McKesson Technology Solutions (now Change Healthcare), Alpharetta, GA 2016 - 2017

Senior Manager, Privacy (Government Security Clearance)

Developed and implemented multiple business unit privacy and related policies for an expansive product line of IT-healthcare solutions including Enterprise Intelligence, Population Health, Clinical and Pharmacy Services with a client base that includes health plans, hospitals, providers, pharmacy networks, pharmaceutical companies and government programs.

Defined, implemented and managed programs that mitigated inherent risks to the business, including privacy program, vendor oversight program, extensive product and risk program which included privacy impact assessments and privacy threshold analysis.

Focused on strategic practices which allowed for business growth and the evolving product suite to integrate privacy requirements in a scalable, organized and sustainable fashion.

Created and trained on policies for data lifecycle initiative, which increased awareness and reduced risks.

Developed an online training for pharmacy team that was necessary to educate team on data protection.

Handled all privacy related matters relating to a Department of Defense (DoD) contract, such as SORNs, US-CERT entries, and following DoD regulations.

Conducted OCR readiness assessment for the major business functions to ensure preparedness for audit.

UnitedHealthcare Military & Veterans, Minnetonka, MN 2013 - 2016

Manager, Privacy and Compliance (2013 – 2016)

Interim Chief Privacy Officer (Government Security Clearance) (2014 – 2015)

Managed two attorneys and one analyst. Provided legal counsel on a variety of complex privacy and compliance issues. Negotiated all business associate agreements, third-party contracts, and other privacy, security and compliance addendums. Conducted on-site customer privacy and security assessments and internal privacy impact assessments, as well as privacy threshold analysis. Managed all customer-facing TRICARE communications to ensure legally compliant. Drafted and trained staff on the company’s policies and procedures, and on privacy and security laws.

Played a key role in creating a privacy program and required HIPAA forms for a newly formed business.

Investigated privacy and security incidents and ethics complaints and recommended corrective action plans and mitigation efforts.

Created agency-wide standardized contracts that were used throughout the organization to streamline negotiations.

Ensured compliance with TRICARE requirements and the Department of Defense (DoD) contract and other data privacy and security regulations.

Worked with various business unit leaders to support the development of comprehensive strategies relating to the improvement of data privacy and security policies, procedures, and practices.

Minnesota Department of Human Services, St. Paul, MN 2008 - 2013

Chief Privacy Officer

Started as a team of one and grew to a team of six, supervising attorneys, paralegal, and law clerks. Provided direction and oversight on the daily functions of the privacy office and ensured overall privacy compliance. Worked closely with the Chief Information Officer to ensure that the appropriate privacy and security controls were developed for the various technologies. Served on the Institutional Review Board and several other boards and committees as the privacy subject matter expert. Developed the privacy audit assessment program and conducted third- party audits. Investigated and responded to complaints received by the Office of Civil Rights. Drafted and negotiated various contracts. Consulted on a variety of complex laws and regulations. Created all the agency’s HIPAA forms. Provided guidance to the privacy team on handling privacy and security incidents. Managed, hired, and performed employment evaluation of the privacy team.

Created and launched privacy audit assessment program that helped to identify external and internal risks.

Developed statewide privacy notices that were reader-friendly to the citizens.

Conducted state-wide training to business partners on creating an effective privacy program, which increased awareness and reduced privacy and compliance incidents.

Played an instrumental role in the development of the foundation of the state of Minnesota’s health information exchange that met federal standards.

Minneapolis Public Housing Authority, Minneapolis, MN 2003 - 2008

Staff Attorney

Represented the agency in Housing Court. Litigated large caseloads, conducted legal research, and drafted legal opinions, briefs, and responsive pleadings. Represented the agency in depositions and internal grievance proceedings. Created policies related to employment law and labor relations. Trained staff on the state privacy laws. Investigated and responded to complaints received from the U.S. Department of Housing and Urban Development and Minnesota Department of Human Rights.

Won a case that set a positive precedence for the agency in similar future cases.

Developed a reasonable accommodation policy that was necessary for the agency to become compliant with the Americans with Disabilities Act.

Dorsey & Whitney, LLC, Minneapolis, MN 2001 – 2002

Corporate Attorney

Worked with a team of attorneys on various transactions, including mergers and acquisitions, initial public offerings, and joint-ventures. Drafted various corporate documents and contracts.

Closed on a major merger and acquisition deal that generated revenue for the firm.

Provided pro bono service to a newly formed business so that they could become operational.

EDUCATION & CERTIFICATION

Juris Doctor, 2000, Cum Laude - Thomas M. Cooley Law School, Lansing, MI

Masters of Business Administration, 1997 - Mercer University, Macon, GA

Bachelor of Arts in Journalism, 1994, Presidential Scholar - University of Georgia, Athens, GA

Certified Information Privacy Professional, 2015

PROFESSIONAL AFFILIATIONS

State Bar of Georgia

Minnesota State Bar Association

International Association of Privacy Professional



Contact this candidate