Skip to main content
Insight Therapy Solutions

Remote WordPress Security & HIPAA Compliance Consultant

1w

Insight Therapy Solutions

Remote · Full-time · $120,000 – $200,000

About this role

Insight Therapy Solutions is seeking a freelance consultant to audit our WordPress website for HIPAA compliance, privacy, and security risks. The consultant will assess how sensitive data, including potential PHI, is collected, stored, processed, and shared. Actionable recommendations will strengthen compliance and security.

Audit WordPress setup, hosting, plugins, forms, integrations, tracking tools, and user access. Identify HIPAA, privacy, and security gaps related to PHI handling, encryption, access control, backups, logging, and third-party vendors. Assess risks involving CRMs, analytics tools, email platforms, payment tools, APIs, and form builders.

Review overall website security posture and identify vulnerabilities or misconfigurations. This remote position supports a healthcare-focused organization handling sensitive therapy solutions. Work independently to deliver high-impact security enhancements.

Provide a concise audit report with findings, risk levels, and prioritized remediation steps. Include HIPAA, privacy, and security audit report, risk and data flow summary, and prioritized remediation plan. Contribute to robust data protection in a regulated environment.

Requirements

  • Strong WordPress security and technical audit experience
  • Hands-on HIPAA compliance experience for healthcare or regulated websites
  • Knowledge of website privacy, consent management, data retention, and third-party risk
  • Familiarity with OWASP, SSL/TLS, firewalls, malware scanning, backups, and least-privilege access
  • Clear communication and documentation skills

Responsibilities

  • Audit WordPress setup, hosting, plugins, forms, integrations, tracking tools, and user access
  • Identify HIPAA, privacy, and security gaps related to PHI handling, encryption, access control, backups, logging, and third-party vendors
  • Assess risks involving CRMs, analytics tools, email platforms, payment tools, APIs, and form builders
  • Review overall website security posture and identify vulnerabilities or misconfigurations
  • Provide a concise audit report with findings, risk levels, and prioritized remediation steps

Benefits

  • Remote position
  • Flexible freelance schedule