Zachary Wilkins-Olson

IT LEADER | HEALTHTECH OPERATIONS | HIPAA SECURITY OFFICER

Eugene, OR 97405  ·  541-674-8565  ·  zach.w.olson@live.com
github.com/CodePapayas  ·  linkedin.com/in/wilkinza  ·  codepapayas.com

IT leader and HIPAA Security Officer. Built and operates the full technology function for a 100+ person behavioral health organization. Open source contributor.

Professional Experience

IT Manager & HIPAA Security Officer

Center for Family Development | Eugene, OR | July 2024 – Present

Department & Infrastructure Leadership

  • Established the organization's first internal IT department, transitioning from a fully outsourced to a co-managed model with internal leadership and a structured MSP partnership.
  • Manage $500K+ annual IT budget across EHR systems, security platforms, telehealth infrastructure, and MSP partnerships, maintaining cost stability through disciplined vendor management.
  • Assessed and restructured operations, eliminating $187K in redundant headcount.
  • Negotiated an optimized MSP model at a 10% per-staff discount with all-inclusive support terms.

EHR Evaluation, Vendor Negotiation & Integration

  • Led EHR platform evaluation to replace a 14-year CareLogic instance as project manager.
  • Sourced and negotiated a three-party EDI integration agreement with a no-fault termination clause across all parties to address an identified capability gap in the contracted EHR platform relating to mandatory state reporting.
  • Serve as primary liaison between state agencies and EHR vendor for EDI certification and mandatory reporting compliance.

Security & Technical Transformation

  • Replaced BYOD with a standardized Zero Trust device fleet across 130+ endpoints with MFA and always-on VPN, reducing HIPAA incidents 75% YoY.
  • Serve as HIPAA Security Officer, maintaining compliance through annual SRAs, policy development, and incident response.
  • Introduced AI tooling governance policies covering both clinical documentation and administrative workflows, ensuring compliance with HIPAA and 42 CFR Part 2.

Internal Engineering

  • Built and maintain a production facility scheduling and room reservation system (Flask, SQL Server, Azure App Service) serving 100+ daily active users across 4 buildings and ~50 rooms. Handles recurring staff schedules, real-time room conflict detection, event management, tiered access control, and childcare reservations.
  • Built a multi-stage client intake and screening pipeline with conditional routing and automated staff notifications. Processes 150+ monthly submissions; replaced a manual phone-based workflow.
  • Provisioned a HIPAA and 42 CFR Part 2-compliant REDCap instance on a custom air-gapped Linux VM in Azure, domain-configured and integrated with the organizational EHR via Snowflake.

System Administrator

Center for Family Development | Eugene, OR | May 2018 – July 2024

  • Led telehealth transformation during March 2020 lockdown, enabling 100% remote operations within two weeks for 100+ staff.
  • Managed technology infrastructure supporting transition from 100% in-person to 75% telehealth delivery.
  • Authored telehealth policies and procedures ensuring regulatory compliance.
  • Managed CareLogic EHR system, maintaining 99.9% uptime and data integrity.
  • Implemented Zendesk ticketing with KPI tracking, reducing maximum SLA response time from 48 to 24 hours.

Open Source

Pylint  ·  Contributor

Contributed fixes for false positive unreachable error with overload + NoReturn (#10785) and detection of unittest.fail() calls for assignment warnings (#10743).

hipaa-mcp  ·  Author and Maintainer

Local MCP server for HIPAA and 42 CFR Part 2 citation search. Hybrid vector + BM25 retrieval, no cloud dependencies. Published to PyPI; pip install hipaa-mcp.

Technical Proficiencies

Languages

Python, C++, Rust, SQL (T-SQL / SQLite)

Frameworks & Libraries

Flask, FastAPI, PyTorch, NumPy, spaCy, Jinja2, FastMCP

Data & Search

SQL Server, Turso, ChromaDB, BM25, Snowflake, REDCap, SSRS

Infrastructure

Azure (App Service / VM), Linux, GitHub Actions (CI/CD), VMware, Zero Trust, Docker

Security & Auth

HIPAA / 42 CFR Part 2, RBAC, HMAC, bcrypt, MFA, VPN, SSL/TLS, Zero Trust

Healthcare

EHR administration, EDI/HL7, telehealth platforms, HIPAA Security Officer

Other

Power Automate, SharePoint, Pydantic v2, Zendesk, gunicorn

Education & Certifications

Bachelor of Science, Computer Science; Minor in Business
Oregon State University
Certified Scrum Master (CSM)