The Epic Security Coordinator is responsible for the administration, governance, maintenance, and optimization of security access within the Epic electronic health record (EHR) system. The role oversees user provisioning, role-based security design, access audits, compliance monitoring, and security governance to ensure appropriate access to Epic applications and protected health information (PHI). The Epic Security Coordinator serves as the primary liaison between operational leaders, Human Resources, Information Security, Compliance, Information Technology, and Epic application teams to ensure user access is granted, modified, and removed in accordance with organizational policies, regulatory requirements, and Epic best practices.
Baptist Health Care is a not-for-profit health care system committed to improving the quality of life for people and communities in northwest Florida and south Alabama. The organization includes three hospitals, four medical parks, Andrews Institute for Orthopaedic & Sports Medicine, and an extensive primary and specialty care provider network. With more than 4,000 team members, Baptist Health Care is one of the largest non-governmental employers in northwest Florida.
Baptist Health Care, Inc. is an Equal Opportunity Employer. BHC maintains and enforces a policy that prohibits discrimination against any workforce members or applicants for employment because of sex, race, age, color, disability, marital status, national origin, religion, genetic information, or other category protected by federal, state or local law. Certain positions may require a Level 2 Background check through AHCA. Additional information about this requirement can be found here: Florida Care Provider Background Screening Clearinghouse
- 3 years of experience supporting Epic, healthcare information systems, identity management, information security, or healthcare operations, required.
- 1 year of experience administering user access and security within healthcare applications, required.
- 1 year of experience with Epic security concepts and access management, preferred.
- 1 year of experience supporting HIPAA compliance activities, preferred.
- 1 year of experience with healthcare regulatory and accreditation environments, preferred.
- Bachelor''s degree in business administration, Cybersecurity, Health Care Administration, Health Informatics, Information Technology, Related field, required OR four years of directly related experience may be considered in lieu of bachelor's degree requirement.
- Administers Epic security access using Epic Security Class, User Record, Role, Template, and related security tools. Configures and maintains role-based access models to support clinical, operational, and business workflows. Creates, modifies, validates, suspends, and terminates Epic user access. Ensures security assignments align with job responsibilities and the principle of least privilege. Supports new department, clinic, service line, and organizational security requests. Maintains security standards and documentation for Epic security configurations.
- Coordinates access requests for new hires, transfers, role changes, contractors, students, and providers. Partners with Human Resources and operational leaders to ensure security assignments remain current. Facilitates timely access terminations and role modifications. Monitors access workflows to ensure adherence to established service-level agreements. Validates user affiliations and organizational relationships before granting access.
- Supports Epic security governance structures and approval processes. Participates in security committees and accesses governance meetings. Develops and maintains security policies, procedures, standards, and work instructions. Ensures compliance with HIPAA, HITECH, CMS, Joint Commission, and organizational requirements. Assists in responding to audit findings and regulatory reviews. Maintains evidence supporting security controls and access decisions.
- Conducts routine user access reviews and security audits. Monitors segregation of duties and identify potential access conflicts. Reviews security reports and investigates inappropriate or excessive access. Partners with Compliance, Information Security, and Internal Audit teams on security investigations. Assists with monitoring privileged and elevated access assignments. Generates reports and dashboards supporting ongoing access compliance.
- Collaborates with Information Technology and Information Security teams to support identity management initiatives. Assists with integration of Epic security processes and enterprise identity management systems. Participates in single sign-on (SSO), multifactor authentication (MFA), and authentication management initiatives. Supports security testing and validation activities for Epic upgrades and implementations. Coordinates security support during mergers, acquisitions, and organizational restructuring efforts.
- Supports Epic implementation, optimization, upgrade, and expansion projects. Participates in workflow analysis and security design sessions. Evaluates existing access models and recommends improvements. Implements security enhancements that improve user experience while maintaining compliance. Supports security remediation efforts resulting from audits or risk assessments.
- Serves as the primary point of contact for Epic security-related questions and requests. Educates leaders and users regarding Epic security policies and access standards. Develops reference materials, user guides, and security training resources. Communicates security changes, enhancements, and governance requirements to stakeholders. Provides regular reports regarding access activity, compliance trends, and audit findings.
- Assists in other duties as assigned to support the operational needs of the department and organization.
- May be required to remain on campus immediately before, during, and after severe weather and/or disasters.
As part of our selection process, candidates being considered for this position will be required to complete a Sphinx Assessment, which is used to evaluate job-related competencies and determine overall suitability for the role. Successful completion of the assessment is a required component of the hiring process.
This position also requires active participation in various phases of the Epic application lifecycle, including but not limited to implementation, go-live support, stabilization, optimization, and system upgrades. Candidates must be willing and able to accommodate the demands associated with these activities, which may include:
- This position operates in a hybrid work environment and may require a minimum of 25% onsite presence to support operational and business needs.
- Working additional hours outside of regularly scheduled business hours, including evenings and weekends, as project needs dictate.
- Participating in on-site go-live and support activities across multiple organizational locations.
Traveling occasionally for Epic training, certification, project meetings, or other work-related purposes, including travel outside of the state.
- Traveling between organizational facilities to provide operational, project, and end-user support.
Candidates should be prepared to maintain flexibility in their schedules to support critical project milestones and organizational operational needs.
- Administers Epic security access using Epic Security Class, User Record, Role, Template, and related security tools. Configures and maintains role-based access models to support clinical, operational, and business workflows. Creates, modifies, validates, suspends, and terminates Epic user access. Ensures security assignments align with job responsibilities and the principle of least privilege. Supports new department, clinic, service line, and organizational security requests. Maintains security standards and documentation for Epic security configurations.
- Coordinates access requests for new hires, transfers, role changes, contractors, students, and providers. Partners with Human Resources and operational leaders to ensure security assignments remain current. Facilitates timely access terminations and role modifications. Monitors access workflows to ensure adherence to established service-level agreements. Validates user affiliations and organizational relationships before granting access.
- Supports Epic security governance structures and approval processes. Participates in security committees and accesses governance meetings. Develops and maintains security policies, procedures, standards, and work instructions. Ensures compliance with HIPAA, HITECH, CMS, Joint Commission, and organizational requirements. Assists in responding to audit findings and regulatory reviews. Maintains evidence supporting security controls and access decisions.
- Conducts routine user access reviews and security audits. Monitors segregation of duties and identify potential access conflicts. Reviews security reports and investigates inappropriate or excessive access. Partners with Compliance, Information Security, and Internal Audit teams on security investigations. Assists with monitoring privileged and elevated access assignments. Generates reports and dashboards supporting ongoing access compliance.
- Collaborates with Information Technology and Information Security teams to support identity management initiatives. Assists with integration of Epic security processes and enterprise identity management systems. Participates in single sign-on (SSO), multifactor authentication (MFA), and authentication management initiatives. Supports security testing and validation activities for Epic upgrades and implementations. Coordinates security support during mergers, acquisitions, and organizational restructuring efforts.
- Supports Epic implementation, optimization, upgrade, and expansion projects. Participates in workflow analysis and security design sessions. Evaluates existing access models and recommends improvements. Implements security enhancements that improve user experience while maintaining compliance. Supports security remediation efforts resulting from audits or risk assessments.
- Serves as the primary point of contact for Epic security-related questions and requests. Educates leaders and users regarding Epic security policies and access standards. Develops reference materials, user guides, and security training resources. Communicates security changes, enhancements, and governance requirements to stakeholders. Provides regular reports regarding access activity, compliance trends, and audit findings.
- Assists in other duties as assigned to support the operational needs of the department and organization.
- May be required to remain on campus immediately before, during, and after severe weather and/or disasters.
As part of our selection process, candidates being considered for this position will be required to complete a Sphinx Assessment, which is used to evaluate job-related competencies and determine overall suitability for the role. Successful completion of the assessment is a required component of the hiring process.
This position also requires active participation in various phases of the Epic application lifecycle, including but not limited to implementation, go-live support, stabilization, optimization, and system upgrades. Candidates must be willing and able to accommodate the demands associated with these activities, which may include:
- This position operates in a hybrid work environment and may require a minimum of 25% onsite presence to support operational and business needs.
- Working additional hours outside of regularly scheduled business hours, including evenings and weekends, as project needs dictate.
- Participating in on-site go-live and support activities across multiple organizational locations.
Traveling occasionally for Epic training, certification, project meetings, or other work-related purposes, including travel outside of the state.
- Traveling between organizational facilities to provide operational, project, and end-user support.
Candidates should be prepared to maintain flexibility in their schedules to support critical project milestones and organizational operational needs.