About

A compliance career, deliberately pointed at security.

23 years protecting sensitive information, now pointed squarely at privacy, compliance, and GRC.

BJH Portrait of Bobbi Jo Halladay

For more than 23 years I worked in healthcare compliance, the kind of environment where a missed detail is not a typo but a regulated event. I handled protected health information and controlled substances under HIPAA, DEA, and FDA rules, from my father's independent pharmacy through retail, specialty, and clinical settings, and most recently as a Patient Care Coordinator.

Somewhere along the way I realized that the work I had been doing for two decades, managing risk, holding documentation to a standard, and protecting sensitive information, is the same work that sits at the center of privacy and governance. The vocabulary was different. The discipline was identical.

So I retrained on purpose. I produced a full portfolio of real GRC and AI governance work, from HIPAA risk assessments to privacy policy and audit readiness, rather than relying on a certificate alone, and I backed it with hands-on technical training so the governance is grounded in how the systems actually work. I also founded The Safe Click Project to teach everyday people how to protect themselves online, because most incidents trace back to human error and the people most at risk get the least approachable guidance.

I am now applying that foundation to roles in privacy and data protection, GRC and compliance, and program management, with the healthcare compliance background that runs underneath all of it. The through line is simple: I know how to keep sensitive information safe, document why, and explain it to people who are not technical.

Career timeline

1997

Started at Grantsville United Drug, my father's independent pharmacy. Where the compliance instinct was formed.

Early career

Target Pharmacy, then specialty and clinical pharmacy. Deepening work under HIPAA, DEA, and FDA requirements.

Through April 2026

Patient Care Coordinator at CarepathRx (CarepathRx / Cigna / Chartwell). Coordinating across patients, providers, and insurers.

2025–2026

The pivot into privacy and GRC: a full GRC and AI governance portfolio, the University of Utah bootcamp and a home lab for technical grounding, The Safe Click Project, and Security+ in progress.

What I bring

Regulatory fluency

HIPAA, DEA, and FDA in practice, not in theory. I read a requirement and know what it means operationally.

Risk & documentation discipline

The habit of assessing risk, writing it down, and building the control. The backbone of GRC.

Plain-language translation

Turning technical and regulatory concepts into something a non-technical person can actually use.

Program ownership

I took The Safe Click Project from idea to launch with no team and no budget, managing it end to end.

Self-direction

I built this entire pivot, the skills, the lab, the portfolio, on my own initiative.

Resilience

I kept momentum through a major career transition while supporting a large household and studying.

Credentials & education

  • CPhT (Certified Pharmacy Technician)
  • University of Utah Cybersecurity Bootcamp
  • BS in Marketing, Western Governors University (in progress)
  • CompTIA Security+ (exam July 10, 2026)