McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you. Position Summary The Senior Healthcare Compliance Analyst is responsible for leading and supporting healthcare regulatory compliance initiatives across the organization, ensuring the protection of electronic Protected Health Information (ePHI) and adherence to healthcare industry regulations and certifications. This role serves as a subject matter expert for HIPAA Security Rule compliance, healthcare privacy requirements, HITRUST certification activities, and related healthcare regulatory obligations. The analyst will partner with Legal, Privacy, Technology, Business Units, and Cybersecurity teams to assess compliance, identify risks, validate control implementation, collect and evaluate evidence, coordinate remediation activities, and maintain ongoing audit readiness. The position plays a key role in supporting the organization's HIPAA Security Program, healthcare risk assessment activities, continuous monitoring efforts, regulatory audits, and compliance assurance initiatives. Key Responsibilities HIPAA Compliance & Risk Analysis Lead and support HIPAA Security Rule compliance activities across applications, systems, and business processes that create, receive, maintain, or transmit ePHI. Conduct and facilitate HIPAA Security Assessments and Attestations for in-scope applications. Support enterprise HIPAA Risk Analysis and Risk Management activities. Validate implementation and effectiveness of administrative, technical, and physical safeguards. Identify compliance gaps and coordinate remediation efforts with business and technology stakeholders. Provide guidance on HIPAA Security Rule requirements and compliance obligations. Support the maintenance of audit-ready evidence demonstrating compliance with HIPAA requirements. Healthcare Regulatory Compliance Support compliance activities across healthcare and privacy regulations including: HIPAA Security Rule HIPAA Privacy Rule HITECH HITRUST CSF PIPEDA GDPR CMMC Monitor evolving healthcare regulatory requirements and assess organizational impact. Support implementation of regulatory compliance initiatives. Maintain documentation demonstrating regulatory compliance and control effectiveness. HITRUST & Healthcare Certification Programs Support HITRUST certification and validated assessment activities. Perform control assessments, testing, and evidence reviews against HITRUST CSF requirements. Coordinate remediation activities for identified HITRUST control deficiencies. Maintain supporting documentation required for assessments, external reviews, and certification activities. Assist with continuous monitoring activities to sustain certification of readiness between assessment cycles. Compliance Assessments & Assurance Conduct healthcare-focused risk assessments and compliance reviews. Evaluate security and privacy controls against regulatory and industry requirements. Review evidence to validate control implementation and operating effectiveness. Track remediation plans and ensure timely closure of identified gaps. Support internal and external audits, regulatory reviews, and customer compliance requests. Develop compliance reports, metrics, dashboards, and executive-level status updates. Partner with Privacy & Data Protection Partner with Privacy teams to support identification and assessment of systems containing PHI or ePHI. Evaluate controls supporting the confidentiality, integrity, and availability of healthcare information. Assist with privacy and data protection compliance initiatives. HITRUST & Healthcare Certification Programs Support HITRUST certification and validated assessment activities. Perform control assessments, testing, and evidence reviews against HITRUST CSF requirements. Coordinate remediation activities for identified HITRUST control deficiencies. Maintain supporting documentation required for assessments, external reviews, and certification activities. Assist with continuous monitoring activities to sustain certification of readiness between assessment cycles. Stakeholder Engagement Collaborate with Privacy, Legal, Cybersecurity, Technology, Risk Management, Audit, and Business teams. Provide healthcare compliance expertise for projects, application implementations, and technology initiatives. Communicate compliance requirements, risks, and remediation expectations to stakeholders. Act as a trusted advisor on healthcare compliance and regulatory matters. Minimum Qualifications Experience 7 years of experience in Healthcare Compliance, Cybersecurity Compliance, IT Audit, Healthcare Privacy, Information Security, Risk Management, Governance, Risk & Compliance (GRC). Experience conducting HIPAA Security Rule assessments and risk analyses. Experience supporting healthcare regulatory audits and compliance programmes. Experience working with healthcare applications, systems, or services that process ePHI. Experience managing compliance evidence and remediation programmes. Experience successfully delivering programs and/or multiple projects on-time and within budget based on agreed upon scope and business goals. Strong ability to influence or negotiate with stakeholders dealing with competing priorities. Capable of anticipating needs and driving clarity on expectations. A solution-oriented mindset, with the ability to exercise good professional judgment. At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That’s why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves. As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. Our Base Pay Range for this position €72,800 - €121,300 McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind: McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application. McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates. McKesson job postings are posted on our career site: careers.mckesson.com.