Location:
Position Overview
Insight Therapy Solutions is seeking a freelance consultant to audit our WordPress website for HIPAA compliance, privacy, and security risks. The consultant will assess how sensitive data, including potential PHI, is collected, stored, processed, and shared, then provide actionable recommendations to strengthen compliance and security.
Responsibilities
- Audit WordPress setup, hosting, plugins, forms, integrations, tracking tools, and user access.
- Identify HIPAA, privacy, and security gaps related to PHI handling, encryption, access control, backups, logging, and third-party vendors.
- Assess risks involving CRMs, analytics tools, email platforms, payment tools, APIs, and form builders.
- Review overall website security posture and identify vulnerabilities or misconfigurations.
- Provide a concise audit report with findings, risk levels, and prioritized remediation steps.
Requirements Skills
- Strong WordPress security and technical audit experience.
- Hands-on HIPAA compliance experience for healthcare or regulated websites.
- Knowledge of website privacy, consent management, data retention, and third-party risk.
- Familiarity with OWASP, SSL/TLS, firewalls, malware scanning, backups, and least-privilege access.
- Clear communication and documentation skills.
Deliverables
- HIPAA, privacy, and security audit report
- Risk and data flow summary
- Prioritized remediation plan
Details
